9.1 Billion Blocked Requests, One Message: Assume You’re Targeted
Wordfence blocked 9.1 billion web-application-firewall requests in Q4 2025. Read that again: in just one quarter, automated traffic tried billions of times to hit WordPress sites with payloads that a WAF considered malicious.
The takeaway is not “install a firewall.” The takeaway is that WordPress WAF attacks occur at an industrial scale and are indiscriminate. If you run a marketing site, a customer portal, or a SaaS knowledge base, you sit on the same internet as everyone else. Attackers do not hand-pick targets before they scan, probe, and exploit. They let automation do it, then they follow the openings.
That volume matters because configuration becomes a business decision. Too loose, and the WAF misses real abuse that leads to account takeovers, data exposure, or a compliance headache. Too strict, and you block legitimate users, break checkout flows, or flood your team with false positives. Either way, the cost shows up as lost revenue, higher support load, and leaders asking why “the website” keeps becoming an incident.
A resilient approach treats the WAF like part of operations. Rules need to match how your site actually behaves. Caching and rate limits need to protect origin resources without punishing real visitors. Alerts need to be actionable, not a noisy inbox.
If you have been telling yourself, “we’re too small to be a target,” Q4 2025 is the rebuttal. WordPress WAF attacks are mostly not personal, but the impact is. The teams that stay calm during spikes are the ones who validate their CDN and WAF posture and back it with hosting that can absorb load and recover quickly when something slips through.
Attack volume isn’t theoretical. Check your CDN and WAF rules and get a configuration that can handle real-world noise.
Source: Wordfence Quarterly WordPress Threat Intelligence Report (Q4 2025)