Server Agent

WordFort
Agent Beta

Server-side WAF-lite for PHP sites. Blocks scanners, SQL injection, XSS, path traversal and bad bots before they reach your app — no browser JavaScript required. Best for WordPress, Laravel and other PHP applications.

PHP sites only. WordFort runs inside PHP, so it protects PHP applications (WordPress covers ~40% of the web). For static HTML or Node sites, use the geo.js snippet instead — it runs in the browser and works everywhere.
1

Your WordFort key

WordFort uses your ACKgeo API key to link blocked requests to your account. You can reuse an existing key or generate a new one.

Loading…

2

Download the two files

Upload both to your site's web root (via FTP, SFTP, or your host's file manager — no SSH needed).

3

Open the installer in your browser

Visit this URL on your site (replace with your domain):

https://yoursite.com/install.php

The installer generates a one-time token, asks for the key from Step 1, verifies the agent is running, and deletes itself on success. That's it — WordFort is live.

4

Watch it work

Blocked probes and attacks appear in your traffic log within seconds of the first block. WordFort reports what it stopped — scanner probes, injection attempts, bad bots — tagged by reason.

Requires PHP-FPM (most modern hosts). Verified search crawlers (Google, Bing) are always allowed through, so your SEO is safe. Full setup notes and troubleshooting are in the WordFort docs.