Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Cybexsoft Shield

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Cybexsoft Shield

By CybexSoft
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Cybexsoft Shield protects the login form, watches your files and settings, and shows you what it found in one dashboard.

Login protection

  • Limit login attempts, with per-account lockout for distributed attacks
  • CAPTCHA — Google reCAPTCHA v2/v3, Cloudflare Turnstile or a built-in challenge — on login, registration, lost password, comments, WooCommerce and Contact Form 7, plus a [cybex_shield_captcha] shortcode
  • An invisible honeypot field that stops bots with no puzzle for people
  • IP block and allow lists, temporary and permanent bans, and rules that ban 404 scanners, known attack tools and XML-RPC abuse
  • A blocked page with a reference code, and a way for real people to unblock themselves by email
  • Custom login URL, with an emergency recovery link

Sessions & passwords

  • Password rules, including a Have I Been Pwned check that never sends the password and blocking the last five passwords
  • See and end every signed-in session; limit sessions per user; idle timeout and maximum session length
  • Email alert when an account signs in from a new device
  • A Security section on each user’s profile with their sessions and devices

Site scanning

  • File integrity: WordPress core and WordPress.org plugins against official checksums, themes against their first scan, and code hidden in uploads
  • Restore the official copy, quarantine, or view a line-by-line diff
  • Plugin and theme health: updates, auto-update policy, and plugins closed or abandoned on WordPress.org
  • Optional Google Safe Browsing check

Hardening, server & SSL

  • Hardening switches: file editor, PHP in uploads, directory listing, wp-config.php permissions, XML-RPC, pingbacks, user enumeration, REST API for visitors, version number, the “admin” username, application passwords. Nothing is switched on until you choose, and one button turns on the safe set.
  • One-time actions: rotate security keys, change the table prefix, force a password reset. Shield’s settings are snapshotted first, and wp-config.php is backed up before it is edited.
  • Server audit of PHP settings, file permissions and ownership, with the exact line or command to fix each problem
  • SSL certificate check with expiry emails, force HTTPS once HTTPS works, security headers, and a mixed-content check

Activity log & overview

  • An activity log of sign-ins, account and role changes, application passwords, plugin, theme and WordPress installs and updates, changes to key site settings and to Shield’s own settings, and everything Shield refused
  • Filter by type, user, severity and period, search by name or IP address, and export exactly what is shown as CSV
  • A security score built from checks you can see — each recommendation says what it is worth and links to the fix
  • Fourteen days of threat activity, figures for blocked addresses, altered core files, waiting updates and failed sign-ins, and one-click switches for each protection
  • A Dashboard widget, and a Shield item in the admin bar with your security score and a count when something needs your attention
  • Country for every logged address, from Cloudflare or a free MaxMind GeoLite2 database on your own server

Privacy

  • Shield’s records are included in WordPress’s Export Personal Data and Erase Personal Data tools
  • Suggested wording for your privacy policy, reflecting your own retention settings
  • Optionally shorten IP addresses (203.0.113.0) and drop browser strings once events are older than a few days
  • No address is sent to any outside service to find its country

Recovery

If a protection ever locks you out:

  • Add define( 'CYBEX_SHIELD_SAFE_MODE', true ); to wp-config.php. Every protection that can stand between you and your site is suspended; logging and the settings screens keep working so you can fix the cause.
  • Or, with shell access, use WP-CLI: wp shield disable <module>, wp shield unblock <ip>, wp shield allow <ip>.

WP-CLI

  • wp shield status — version, licence, safe mode and every module’s state
  • wp shield modules, wp shield enable <module>, wp shield disable <module>
  • wp shield unblock <ip>, wp shield allow <ip> [--label=<label>]
  • wp shield logout <user>, wp shield logout --all
  • wp shield scan
  • wp shield settings get|set|reset|export|import
  • wp shield license status|activate|deactivate|refresh
  • wp shield login-url show|reset|recovery

Pro (sold separately, delivered as an add-on plugin)

Two-factor authentication with passkeys, a firewall that can start before WordPress loads, rate limiting and crawler control, geo-blocking, server rules for Apache and nginx, a malware scanner, and governance tools: a tamper-evident audit trail of Shield’s settings, access levels and two-administrator approval, alerts to Slack, Teams, PagerDuty, syslog and webhooks, PDF reports, configuration profiles and a compliance map. The free plugin never needs Pro, and nothing in it is disabled or time-limited. See https://cybexsoft.com/products/cybexsoft-shield for plans.

External services

Cybexsoft Shield contacts the services below only for the features that need them. Every one is optional; the default CAPTCHA is Shield’s own built-in challenge, which contacts nobody, and country lookups use a database on your own server. No visitor data is sent anywhere unless you switch on one of these features.

Google reCAPTCHA

Used only if you choose “Google reCAPTCHA” as the CAPTCHA provider under Shield → CAPTCHA and enter your own keys.

The forms you protect then load a script from google.com, and Google receives each visitor’s IP address, browser and device information, and their interaction with the challenge — including visitors who never submit the form. When a form is submitted, Shield sends the challenge token, your secret key and the visitor’s IP address to Google to check the answer.

Service provided by Google: terms of service, privacy policy.

Cloudflare Turnstile

Used only if you choose “Cloudflare Turnstile” as the CAPTCHA provider under Shield → CAPTCHA and enter your own keys.

The forms you protect then load a script from challenges.cloudflare.com, and Cloudflare receives each visitor’s IP address, browser and device information, and their interaction with the challenge. When a form is submitted, Shield sends the challenge token, your secret key and the visitor’s IP address to Cloudflare to check the answer.

Service provided by Cloudflare: terms of service, privacy policy.

Have I Been Pwned (Pwned Passwords)

Used only if password rules are switched on under Shield → Sessions & passwords with “Not found in known data breaches” selected.

When a password is set or changed, and at most once a month when someone signs in, Shield hashes the password with SHA-1 on your server and sends only the first five characters of that hash to https://api.pwnedpasswords.com. The password itself never leaves your server, and the answer is compared locally. If the service cannot be reached, the check is skipped.

Service provided by Have I Been Pwned: acceptable use, privacy policy.

Google Safe Browsing

Used only if you enter a Google Safe Browsing API key under Shield → Settings.

Once a day, Shield sends your site’s home address and your API key to https://safebrowsing.googleapis.com to ask whether Google is warning visitors away from the site. No visitor data is sent.

Service provided by Google: terms of service, privacy policy.

WordPress.org

Used by the file integrity scan and Plugin & theme health, which are on by default.

Shield asks api.wordpress.org and downloads.wordpress.org for the official checksums of your WordPress version and of plugins hosted on WordPress.org, and for public information about those plugins (whether they are still listed, when they were last updated). When you choose to restore a file, its official copy is downloaded from core.svn.wordpress.org or plugins.svn.wordpress.org. Each request names only the WordPress version, locale, plugin slug and version concerned.

Service provided by WordPress.org: privacy policy.

Cybexsoft licence server

Used only if you have bought the Pro add-on and enter a licence key under Shield → Licence.

Your licence key and your site’s home address are sent to https://cybexsoft.com/api/licenses when you activate or deactivate the key, and once a day afterwards to confirm it is still valid. Nothing is sent while no licence key is stored, which is the case on every free install.

Service provided by Cybexsoft: terms of service, privacy policy.

Third-party code

The plugin is distributed under the GNU General Public License, version 3 or later. Version 3 rather than 2, because it includes code under the Apache License 2.0, which is compatible with GPLv3 but not with GPLv2.

  • MaxMind-DB-Reader-php — Copyright (c) MaxMind, Inc., Apache License 2.0. Portions of the .mmdb reader in includes/class-cybex-shield-mmdb-reader.php are derived from it, in modified form. No MaxMind database is bundled; you supply your own, and it stays subject to MaxMind’s terms. MaxMind and GeoLite are trademarks of MaxMind, Inc.; this plugin is not affiliated with or endorsed by them.
  • Public Sans and Space Grotesk — SIL Open Font License 1.1, served from this plugin rather than a font CDN, so no administrator’s IP address is handed to a third party when the dashboard loads.

Full notices are in the NOTICE file, and the licence itself in LICENSE.txt.

Screenshots

Security overview: a score built from checks you can see, what to fix next and what each fix is worth, fourteen days of threat activity, and a switch for every protection.
Security overview: a score built from checks you can see, what to fix next and what each fix is worth, fourteen days of threat activity, and a switch for every protection.
Activity log: sign-ins, account, plugin and settings changes and everything Shield refused, with filters, search and CSV export.
Activity log: sign-ins, account, plugin and settings changes and everything Shield refused, with filters, search and CSV export.
Login attempts: brute-force limits, with failed sign-ins, lockouts and the account names being tried.
Login attempts: brute-force limits, with failed sign-ins, lockouts and the account names being tried.
IP blocking: block and allow lists, temporary and permanent bans, and where attacks come from.
IP blocking: block and allow lists, temporary and permanent bans, and where attacks come from.
Sessions & passwords: password rules with a breached-password check, and every signed-in device.
Sessions & passwords: password rules with a breached-password check, and every signed-in device.

Installation

  1. Upload the plugin to /wp-content/plugins/cybexsoft-shield, or install it from the Plugins screen.
  2. Activate it.

Shield works out where visitor IP addresses come from the first time you open its dashboard: straight from visitors, through Cloudflare, or through your host’s own proxy. It only trusts a proxy it can verify from the connection itself. If it cannot tell (another CDN, for example), the setup wizard asks, and you can always change it under Settings.

FAQ

Does it work on multisite?

Yes. Each site keeps its own settings, logs and block lists, and is configured by its own administrator.

How do I see which country an address is from?

Behind Cloudflare, Shield reads it from Cloudflare’s header. Anywhere else, download the free GeoLite2 City or Country database from MaxMind, put the .mmdb file somewhere on the server outside the web root, and enter its path under Settings → Visitor location. Lookups happen on your server.

What personal data does Shield store?

For each security event: the time, IP address, country (when known), browser user-agent and — for sign-ins — the account or username involved. It is kept for the number of days set under Settings (30 by default). Shield’s records are included in WordPress’s personal-data export and erasure tools.

What happens to my data if I delete the plugin?

It is kept, unless you switch on “Delete all data when the plugin is deleted” under Settings. Deactivating never removes anything.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Cybexsoft Shield” is open source software. The following people have contributed to this plugin.

Contributors
  • CybexSoft

Translate “Cybexsoft Shield” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.0.0

  • Initial release.
  • Login protection: login attempt limits with per-account lockout, CAPTCHA (built-in, reCAPTCHA or Turnstile) on WordPress, WooCommerce and Contact Form 7 forms, a honeypot field, IP block and allow lists with automatic bans, a blocked page with self-unblock, and a custom login URL with a recovery link.
  • Sessions & passwords: password rules with a breached-password check, a list of every session with sign-out, session limits and timeouts, new-device alerts, and a Security section on each profile.
  • Site scanning: file integrity against official checksums with restore, quarantine and a diff view; plugin and theme health; an optional Safe Browsing check.
  • Hardening switches, one-time actions with settings snapshots, a server audit that says how to fix each problem, and SSL and security-header checks.
  • An activity log with filters, search and CSV export; a security score with recommendations; a Dashboard widget and an admin-bar item with the score and open notifications; country lookups from Cloudflare or your own GeoLite2 database.
  • Privacy: personal-data export and erasure, suggested privacy-policy text, and optional IP shortening.
  • Safe mode and WP-CLI commands for getting back in if a protection locks you out.
  • Six colour themes for Shield’s screens on their own Appearance page (Harbor Navy, Deep Ocean, Evergreen, Merlot, Ivory & Ink, Mist), the same as Cybexsoft AI’s, or your own primary and accent colours; the accent also lines the top of the band.

Meta

  • Version 1.0.0
  • Last updated 12 hours ago
  • Active installations Fewer than 10
  • WordPress version 5.8 or higher
  • Tested up to 7.1.2
  • PHP version 7.4 or higher
  • Tags
    Activity LogBrute Forcehardeninglogin securitysecurity
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • CybexSoft

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org
  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry
The WordPress® trademark is the intellectual property of the WordPress Foundation.