WordPress websites are the target of thousands of attacks every day. The platform is popular – but that's precisely what makes it a target. Without targeted security measures, a website can quickly become a security vulnerability. Therefore, using security plugins is no longer optional, but essential.
What is a firewall plugin?
A firewall plugin protects your website from unauthorized access – even before it reaches your server. It monitors incoming traffic and automatically blocks suspicious requests, for example, through geoblocking rules or IP address blocking. This is particularly effective against brute-force attacks, which aim to automatically guess passwords.
What is a malware plugin?
A malware scanner continuously checks all WordPress code and files on your site. Its goal is to detect and remove malicious software (malware), suspicious files, or modified code before it can cause damage. Good plugins can even detect hidden malicious code within themes or plugins.
Furthermore, many malware plugins also offer protection against spam, especially in comments and forms. This effectively blocks automated spam comments and mass contact form submissions by bots – an often underestimated but very important aspect of website security.
When do I need which plugin?
Both types of plugins complement each other – and should ideally be used together:
| Safety measure | Protection from… |
|---|---|
| Firewall-Plugin | External attacks, login attempts, bot access |
| Malware-Scanner | Infected files, hidden malicious code, spam protection for comments & forms |
How often our client websites are attacked – a look at reality
The following security overview shows, as an example, the attack statistics of three customer websites in just 7 days.

- 10,833 attacks blocked by the firewall
- 5,950 brute-force attacks (e.g., password cracking attempts) were registered.
- No malware found – thanks to active protection
- and 27 successful logins performed correctly
This shows that it is constantly under attack. But with the right protection, the damage remains at zero.
What to do if the site has been hacked?
If your site is already affected, act quickly.
We will professionally help you clean up and secure your website.
How can you tell if your website has been hacked?
Typical signs include, for example:
- Your site is suddenly marked as "unsafe" (e.g., in Google or browsers).
- Unknown content, pop-ups, or redirects appear on your page.
- You can no longer log in to the WordPress backend.
- Your hosting provider is reporting unusual traffic or outgoing spam.
- There are tons of spam comments and form submissions.
- Google displays warnings in search results such as "This page may have been hacked".
In Switzerland, most hosting providers actively inform their customers if there is a suspicion of malicious code or abuse – for example, by sending an email notification or even by temporarily blocking the affected site.
If you notice such abnormalities, don't hesitate – every hour counts.
➡ Click here to go to our help and support section
Maintenance with us? Safety included!
If you have a maintenance contract with us, the protection is already included:
Firewall, malware scanner, security updates and monitoring – everything runs automatically in the background.


