pluginwordfence

Wordfence Abilities

Security integration. Firewall, scanning, and hardening controls.

5Total Abilities
0Destructive
1Capability Gates
Functional Domains:
Security
WordPress capabilities required:
manage_options 5

Available Tools (5)

wf_get_security_statusmanage_options

Get a Wordfence security overview: whether the firewall (WAF) is enabled and its mode, whether live traffic/login security features are on, when the last scan ran, and whether a scan is currently running. Read-only.

Ability IDmore-mcp/wf-get-security-statusRequiresmanage_options
Parameter Schema0 parameters
{
  "type": "object",
  "properties": {}
}
wf_get_scan_resultsmanage_options

Get the results of the most recent Wordfence scan: counts of new issues, plus issues the admin has previously ignored (per-issue and per-category), and when the scan last ran. Returns finding titles and severities, never raw file contents or attacker payloads.

Ability IDmore-mcp/wf-get-scan-resultsRequiresmanage_options
Parameter Schema1 parameter
{
  "type": "object",
  "properties": {
    "limit": {
      "type": "integer",
      "description": "Maximum number of new issues to detail (default 25, max 100). Counts are always returned regardless of this limit."
    }
  }
}
wf_get_blocked_ipsmanage_options

List IP addresses currently blocked by Wordfence, with the block reason, type (manual, brute-force, rate-limit, etc.), and when the block expires. Read-only.

Ability IDmore-mcp/wf-get-blocked-ipsRequiresmanage_options
Parameter Schema1 parameter
{
  "type": "object",
  "properties": {
    "limit": {
      "type": "integer",
      "description": "Maximum number of blocked IPs to return (default 50, max 200)."
    }
  }
}
wf_get_failed_loginsmanage_options

Get Wordfence's recent failed-login summary: the top usernames by failed-attempt count over the plugin's reporting window, and whether each username maps to a real account (a repeated failure against a valid admin username is a stronger signal than one against a random string). Read-only.

Ability IDmore-mcp/wf-get-failed-loginsRequiresmanage_options
Parameter Schema1 parameter
{
  "type": "object",
  "properties": {
    "limit": {
      "type": "integer",
      "description": "Maximum number of usernames to return (default 10, max 50)."
    }
  }
}
wf_start_scanmanage_options

Start a Wordfence scan now. A scan is CPU- and IO-intensive, so this is a two-part confirmation: call without confirm to receive a preview and start nothing; call with confirm=true AND confirm_scan=true to actually begin. Uses the scan type configured in Wordfence. Refuses if a scan is already running.

Ability IDmore-mcp/wf-start-scanRequiresmanage_options
Parameter Schema2 parameters
{
  "type": "object",
  "properties": {
    "confirm": {
      "type": "boolean",
      "description": "Must be true to start the scan. Omit or false to receive a preview instead. That preview is the intended first call."
    },
    "confirm_scan": {
      "type": "boolean",
      "description": "Must also be true, alongside confirm=true, to start the scan. A deliberate second flag so a scan cannot begin on a single unconsidered call."
    }
  }
}