Description
Cybexsoft Shield protects the login form, watches your files and settings, and shows you what it found in one dashboard.
Login protection
- Limit login attempts, with per-account lockout for distributed attacks
- CAPTCHA — Google reCAPTCHA v2/v3, Cloudflare Turnstile or a built-in challenge — on login, registration, lost password, comments, WooCommerce and Contact Form 7, plus a
[cybex_shield_captcha]shortcode - An invisible honeypot field that stops bots with no puzzle for people
- IP block and allow lists, temporary and permanent bans, and rules that ban 404 scanners, known attack tools and XML-RPC abuse
- A blocked page with a reference code, and a way for real people to unblock themselves by email
- Custom login URL, with an emergency recovery link
Sessions & passwords
- Password rules, including a Have I Been Pwned check that never sends the password and blocking the last five passwords
- See and end every signed-in session; limit sessions per user; idle timeout and maximum session length
- Email alert when an account signs in from a new device
- A Security section on each user’s profile with their sessions and devices
Site scanning
- File integrity: WordPress core and WordPress.org plugins against official checksums, themes against their first scan, and code hidden in uploads
- Restore the official copy, quarantine, or view a line-by-line diff
- Plugin and theme health: updates, auto-update policy, and plugins closed or abandoned on WordPress.org
- Optional Google Safe Browsing check
Hardening, server & SSL
- Hardening switches: file editor, PHP in uploads, directory listing, wp-config.php permissions, XML-RPC, pingbacks, user enumeration, REST API for visitors, version number, the “admin” username, application passwords. Nothing is switched on until you choose, and one button turns on the safe set.
- One-time actions: rotate security keys, change the table prefix, force a password reset. Shield’s settings are snapshotted first, and wp-config.php is backed up before it is edited.
- Server audit of PHP settings, file permissions and ownership, with the exact line or command to fix each problem
- SSL certificate check with expiry emails, force HTTPS once HTTPS works, security headers, and a mixed-content check
Activity log & overview
- An activity log of sign-ins, account and role changes, application passwords, plugin, theme and WordPress installs and updates, changes to key site settings and to Shield’s own settings, and everything Shield refused
- Filter by type, user, severity and period, search by name or IP address, and export exactly what is shown as CSV
- A security score built from checks you can see — each recommendation says what it is worth and links to the fix
- Fourteen days of threat activity, figures for blocked addresses, altered core files, waiting updates and failed sign-ins, and one-click switches for each protection
- A Dashboard widget, and a Shield item in the admin bar with your security score and a count when something needs your attention
- Country for every logged address, from Cloudflare or a free MaxMind GeoLite2 database on your own server
Privacy
- Shield’s records are included in WordPress’s Export Personal Data and Erase Personal Data tools
- Suggested wording for your privacy policy, reflecting your own retention settings
- Optionally shorten IP addresses (203.0.113.0) and drop browser strings once events are older than a few days
- No address is sent to any outside service to find its country
Recovery
If a protection ever locks you out:
- Add
define( 'CYBEX_SHIELD_SAFE_MODE', true );to wp-config.php. Every protection that can stand between you and your site is suspended; logging and the settings screens keep working so you can fix the cause. - Or, with shell access, use WP-CLI:
wp shield disable <module>,wp shield unblock <ip>,wp shield allow <ip>.
WP-CLI
wp shield status— version, licence, safe mode and every module’s statewp shield modules,wp shield enable <module>,wp shield disable <module>wp shield unblock <ip>,wp shield allow <ip> [--label=<label>]wp shield logout <user>,wp shield logout --allwp shield scanwp shield settings get|set|reset|export|importwp shield license status|activate|deactivate|refreshwp shield login-url show|reset|recovery
Pro (sold separately, delivered as an add-on plugin)
Two-factor authentication with passkeys, a firewall that can start before WordPress loads, rate limiting and crawler control, geo-blocking, server rules for Apache and nginx, a malware scanner, and governance tools: a tamper-evident audit trail of Shield’s settings, access levels and two-administrator approval, alerts to Slack, Teams, PagerDuty, syslog and webhooks, PDF reports, configuration profiles and a compliance map. The free plugin never needs Pro, and nothing in it is disabled or time-limited. See https://cybexsoft.com/products/cybexsoft-shield for plans.
External services
Cybexsoft Shield contacts the services below only for the features that need them. Every one is optional; the default CAPTCHA is Shield’s own built-in challenge, which contacts nobody, and country lookups use a database on your own server. No visitor data is sent anywhere unless you switch on one of these features.
Google reCAPTCHA
Used only if you choose “Google reCAPTCHA” as the CAPTCHA provider under Shield CAPTCHA and enter your own keys.
The forms you protect then load a script from google.com, and Google receives each visitor’s IP address, browser and device information, and their interaction with the challenge — including visitors who never submit the form. When a form is submitted, Shield sends the challenge token, your secret key and the visitor’s IP address to Google to check the answer.
Service provided by Google: terms of service, privacy policy.
Cloudflare Turnstile
Used only if you choose “Cloudflare Turnstile” as the CAPTCHA provider under Shield CAPTCHA and enter your own keys.
The forms you protect then load a script from challenges.cloudflare.com, and Cloudflare receives each visitor’s IP address, browser and device information, and their interaction with the challenge. When a form is submitted, Shield sends the challenge token, your secret key and the visitor’s IP address to Cloudflare to check the answer.
Service provided by Cloudflare: terms of service, privacy policy.
Have I Been Pwned (Pwned Passwords)
Used only if password rules are switched on under Shield Sessions & passwords with “Not found in known data breaches” selected.
When a password is set or changed, and at most once a month when someone signs in, Shield hashes the password with SHA-1 on your server and sends only the first five characters of that hash to https://api.pwnedpasswords.com. The password itself never leaves your server, and the answer is compared locally. If the service cannot be reached, the check is skipped.
Service provided by Have I Been Pwned: acceptable use, privacy policy.
Google Safe Browsing
Used only if you enter a Google Safe Browsing API key under Shield Settings.
Once a day, Shield sends your site’s home address and your API key to https://safebrowsing.googleapis.com to ask whether Google is warning visitors away from the site. No visitor data is sent.
Service provided by Google: terms of service, privacy policy.
WordPress.org
Used by the file integrity scan and Plugin & theme health, which are on by default.
Shield asks api.wordpress.org and downloads.wordpress.org for the official checksums of your WordPress version and of plugins hosted on WordPress.org, and for public information about those plugins (whether they are still listed, when they were last updated). When you choose to restore a file, its official copy is downloaded from core.svn.wordpress.org or plugins.svn.wordpress.org. Each request names only the WordPress version, locale, plugin slug and version concerned.
Service provided by WordPress.org: privacy policy.
Cybexsoft licence server
Used only if you have bought the Pro add-on and enter a licence key under Shield Licence.
Your licence key and your site’s home address are sent to https://cybexsoft.com/api/licenses when you activate or deactivate the key, and once a day afterwards to confirm it is still valid. Nothing is sent while no licence key is stored, which is the case on every free install.
Service provided by Cybexsoft: terms of service, privacy policy.
Third-party code
The plugin is distributed under the GNU General Public License, version 3 or later. Version 3 rather than 2, because it includes code under the Apache License 2.0, which is compatible with GPLv3 but not with GPLv2.
- MaxMind-DB-Reader-php — Copyright (c) MaxMind, Inc., Apache License 2.0. Portions of the .mmdb reader in
includes/class-cybex-shield-mmdb-reader.phpare derived from it, in modified form. No MaxMind database is bundled; you supply your own, and it stays subject to MaxMind’s terms. MaxMind and GeoLite are trademarks of MaxMind, Inc.; this plugin is not affiliated with or endorsed by them. - Public Sans and Space Grotesk — SIL Open Font License 1.1, served from this plugin rather than a font CDN, so no administrator’s IP address is handed to a third party when the dashboard loads.
Full notices are in the NOTICE file, and the licence itself in LICENSE.txt.
Screenshots





Installation
- Upload the plugin to
/wp-content/plugins/cybexsoft-shield, or install it from the Plugins screen. - Activate it.
Shield works out where visitor IP addresses come from the first time you open its dashboard: straight from visitors, through Cloudflare, or through your host’s own proxy. It only trusts a proxy it can verify from the connection itself. If it cannot tell (another CDN, for example), the setup wizard asks, and you can always change it under Settings.
FAQ
-
Does it work on multisite?
-
Yes. Each site keeps its own settings, logs and block lists, and is configured by its own administrator.
-
How do I see which country an address is from?
-
Behind Cloudflare, Shield reads it from Cloudflare’s header. Anywhere else, download the free GeoLite2 City or Country database from MaxMind, put the .mmdb file somewhere on the server outside the web root, and enter its path under Settings Visitor location. Lookups happen on your server.
-
What personal data does Shield store?
-
For each security event: the time, IP address, country (when known), browser user-agent and — for sign-ins — the account or username involved. It is kept for the number of days set under Settings (30 by default). Shield’s records are included in WordPress’s personal-data export and erasure tools.
-
What happens to my data if I delete the plugin?
-
It is kept, unless you switch on “Delete all data when the plugin is deleted” under Settings. Deactivating never removes anything.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Cybexsoft Shield” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Cybexsoft Shield” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.0
- Initial release.
- Login protection: login attempt limits with per-account lockout, CAPTCHA (built-in, reCAPTCHA or Turnstile) on WordPress, WooCommerce and Contact Form 7 forms, a honeypot field, IP block and allow lists with automatic bans, a blocked page with self-unblock, and a custom login URL with a recovery link.
- Sessions & passwords: password rules with a breached-password check, a list of every session with sign-out, session limits and timeouts, new-device alerts, and a Security section on each profile.
- Site scanning: file integrity against official checksums with restore, quarantine and a diff view; plugin and theme health; an optional Safe Browsing check.
- Hardening switches, one-time actions with settings snapshots, a server audit that says how to fix each problem, and SSL and security-header checks.
- An activity log with filters, search and CSV export; a security score with recommendations; a Dashboard widget and an admin-bar item with the score and open notifications; country lookups from Cloudflare or your own GeoLite2 database.
- Privacy: personal-data export and erasure, suggested privacy-policy text, and optional IP shortening.
- Safe mode and WP-CLI commands for getting back in if a protection locks you out.
- Six colour themes for Shield’s screens on their own Appearance page (Harbor Navy, Deep Ocean, Evergreen, Merlot, Ivory & Ink, Mist), the same as Cybexsoft AI’s, or your own primary and accent colours; the accent also lines the top of the band.
