Server Agent
Server-side WAF-lite for PHP sites. Blocks scanners, SQL injection, XSS, path traversal and bad bots before they reach your app — no browser JavaScript required. Best for WordPress, Laravel and other PHP applications.
WordFort uses your ACKgeo API key to link blocked requests to your account. You can reuse an existing key or generate a new one.
Loading…Upload both to your site's web root (via FTP, SFTP, or your host's file manager — no SSH needed).
Visit this URL on your site (replace with your domain):
https://yoursite.com/install.php
The installer generates a one-time token, asks for the key from Step 1, verifies the agent is running, and deletes itself on success. That's it — WordFort is live.
Blocked probes and attacks appear in your traffic log within seconds of the first block. WordFort reports what it stopped — scanner probes, injection attempts, bad bots — tagged by reason.