Everything FrothIQ does for your site

A complete breakdown of the detection, blocking, and management features inside FrothIQ Defense.

Real-time threat detection

Every request to your site is scored as it arrives. Known bad-IP lists, credential-stuffing patterns, SQL-injection probes, path-traversal attempts, and abusive bot behavior are all flagged before they reach WordPress’s PHP layer.

  • Scores every incoming request against reputation and behavioral signals
  • Catches credential-stuffing attacks before they exhaust your login throttle
  • Detects common exploit patterns (SQLi, path traversal, XSS probes) at the edge
  • Flags suspicious User-Agents, unusual request rates, and geo-anomalies
  • Updates threat intelligence continuously — no manual signature updates

Three protection modes

FrothIQ is designed to match how you actually operate a site. Pick a mode that fits where you are, not where a vendor thinks you should be.

Monitor

Observe without blocking

FrothIQ logs every threat it sees but doesn’t interfere with any traffic. Ideal for a shake-out period on a new site, for seeing the attack surface before committing to policy, or for high-traffic sites that want visibility without risk of false positives.

Protect

Balanced, automatic defense

The everyday operating mode. FrothIQ blocks high-confidence threats (credential stuffing, known-bad IPs, active exploit attempts) while letting questionable-but-plausible traffic through. Recommended for most production sites.

Block

Zero-tolerance lockdown

For sites under active attack or with elevated compliance requirements. FrothIQ blocks anything scored as suspicious, not just confirmed-malicious. Expect aggressive defense and accept that you may block a small percentage of legitimate bots.

Modes can be switched in one click from the dashboard. No reinstall, no downtime.

Multi-layer IP blocking

When FrothIQ decides to block an attacker, it doesn’t just reject the request in WordPress. Blocked IPs get pushed down into layers outside the application, so the attacker’s next request never consumes any resources.

  • Application-layer block (WordPress) — instant, returns a standard deny response
  • Edge-layer block — the attacker is dropped before PHP even loads
  • Shared threat intelligence — a block seen on one site propagates to every other site on your account
  • Automatic expiration — blocks age out on a sliding window; no manual cleanup

Activity log & insights

Every decision FrothIQ makes is recorded with context. See what got through, what got blocked, and why — with privacy preserved.

  • Chronological view of every scored request
  • Threat score, reason, and the rule that fired
  • Request path, HTTP status, and outcome (allowed / blocked)
  • IP addresses partially masked in the activity log — full IPs stay in your own error log where you control them
  • Filter by score, outcome, or time window

Centralized management

If you run more than one site, FrothIQ is built for that world. All sites report to the same dashboard and share the same defense posture.

Unified inbox

See attacks across every site you own in one stream. Filter by severity, site, or time. Respond once — the change propagates.

Per-site policies

Same dashboard, different policies. Set one site to Block while others run Protect. Policies stay where you configure them.

Shared allow/deny lists

Whitelist your office IP once, applied everywhere. Ban a malicious network once, blocked everywhere. Lists are tenant-wide.

Privacy by default

FrothIQ is built for operators who take data minimization seriously:

  • IP addresses are partially masked (only the network portion is shown) in the activity log UI
  • Full IP addresses are written only to your server’s error log — your infrastructure, your retention policy
  • No user PII is collected by the plugin beyond what your site already logs
  • All FrothIQ traffic is encrypted in transit
  • License keys and tenant identifiers are stored only in your WordPress database

Low-impact integration

FrothIQ is designed to be boring infrastructure — you install it, forget it’s there, and only notice it when it catches something.

  • No shell or server access required — installs as a standard WordPress plugin
  • No configuration files or server-side tweaks needed for basic operation
  • Graceful failure — if FrothIQ can’t reach its intelligence layer, your site keeps running (policy falls back to local cache)
  • Minimal performance impact — sub-millisecond overhead on cached-blocklist hits
  • Compatible with standard caching plugins, page builders, and WooCommerce

Ready to try it?

Install FrothIQ Defense on your first WordPress site in about five minutes.