Suggestions:
If Your Site Is HackedTuning Wordfence Resource UsageV3: Accessing and Consuming the Vulnerability Data FeedAPI CallbacksVulnerability Management: Webhook NotificationsBasic Plugin SettingsAudit LogV1: Accessing and Consuming the Vulnerability Data FeedV2: Accessing and Consuming the Vulnerability Data FeedWordfence IntelligenceCompatibilityWordfence Intelligence Webhook NotificationsWordfence ResponseWordfence CareWordfence FreePlugin / Theme ConflictsUsing Wordfence Central TeamsSub-Processors ListMySQLi storage engineAccount and Billing HistoryUsing Central’s Settings pageLogin Security PluginLogin Security OptionsLegacy Two-Factor AuthenticationUsing Wordfence plugin options TemplatesUsing the Configuration pageViewing scan FindingsUsing the Dashboard pageSetting up two-factor authenticationConnecting your sites to Wordfence CentralWordfence Central ToolImport/ExportWordfence and GDPR – General Data Protection RegulationTroubleshootingTechnical DetailsWordfence 7Blocking TroubleshootingWordfence and LiteSpeedDiagnosticsWHOIS LookupBrute Force ProtectionStatisticsGlobal OptionsWordfence APIAlertsDashboardToolsRate LimitingChangelogScan TroubleshootingFirewall Optimization TroubleshootingScan ResultsConstantsTroubleshootingLicense KeyRemove or ResetSystem requirementsScan SchedulingCountry BlockingScan OptionsFirewall OptionsFirewall Learning ModeAdvanced information and configurationIncident Response ServicesTwo-Factor AuthenticationReal-Time Live TrafficScanBlockingWordfence PremiumOptimizing The FirewallWordfence Web Application Firewall (WAF)

Compatibility

Some Cloudflare features may need adjustments for compatibility.

Cloudflare compatibility

If your site uses Cloudflare then some Cloudflare settings, including “Bot Fight Mode”, can prevent your site from reaching itself. This can affect WordPress cron jobs, Wordfence scans, and other features. On the “Diagnostics” tab of the Wordfence “Tools” page, the “Connecting back to this site” and “Connecting back to this site via IPv6” tests can show if the site is blocked from reaching itself.

To set up Cloudflare to allow connections from your site’s server back to itself, you can add your server IP address (or addresses) to Cloudflare’s IP address allowlist. If you are not sure how to do that then contact Cloudflare support or consult their documentation. Note that you may have to add your server IP address (or addresses) to more then one allowlist in your Cloudflare control panel.

If you don’t know the public IP address of your server, or if outbound requests from your host have a different public IP than the server itself, you may need to ask your hosting provider for help. Alternately, you may be able to find the IP address that is being blocked by looking at Cloudflare’s activity log to find recently blocked IP addresses. Be sure to only allow IP addresses that you know are legitimate, as this list can also show blocks of malicious traffic.