Title: Cybexsoft Shield
Author: CybexSoft
Published: <strong>October 5, 2026</strong>
Last modified: October 5, 2026

---

Search plugins

![](https://ps.w.org/cybexsoft-shield/assets/banner-772x250.png?rev=3727988)

![](https://ps.w.org/cybexsoft-shield/assets/icon-256x256.png?rev=3728058)

# Cybexsoft Shield

 By [CybexSoft](https://profiles.wordpress.org/rahul1099/)

[Download](https://downloads.wordpress.org/plugin/cybexsoft-shield.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/cybexsoft-shield/#description)
 * [Reviews](https://wordpress.org/plugins/cybexsoft-shield/#reviews)
 *  [Installation](https://wordpress.org/plugins/cybexsoft-shield/#installation)
 * [Development](https://wordpress.org/plugins/cybexsoft-shield/#developers)

 [Support](https://wordpress.org/support/plugin/cybexsoft-shield/)

## Description

Cybexsoft Shield protects the login form, watches your files and settings, and shows
you what it found in one dashboard.

**Login protection**

 * Limit login attempts, with per-account lockout for distributed attacks
 * CAPTCHA — Google reCAPTCHA v2/v3, Cloudflare Turnstile or a built-in challenge—
   on login, registration, lost password, comments, WooCommerce and Contact Form
   7, plus a `[cybex_shield_captcha]` shortcode
 * An invisible honeypot field that stops bots with no puzzle for people
 * IP block and allow lists, temporary and permanent bans, and rules that ban 404
   scanners, known attack tools and XML-RPC abuse
 * A blocked page with a reference code, and a way for real people to unblock themselves
   by email
 * Custom login URL, with an emergency recovery link

**Sessions & passwords**

 * Password rules, including a Have I Been Pwned check that never sends the password
   and blocking the last five passwords
 * See and end every signed-in session; limit sessions per user; idle timeout and
   maximum session length
 * Email alert when an account signs in from a new device
 * A Security section on each user’s profile with their sessions and devices

**Site scanning**

 * File integrity: WordPress core and WordPress.org plugins against official checksums,
   themes against their first scan, and code hidden in uploads
 * Restore the official copy, quarantine, or view a line-by-line diff
 * Plugin and theme health: updates, auto-update policy, and plugins closed or abandoned
   on WordPress.org
 * Optional Google Safe Browsing check

**Hardening, server & SSL**

 * Hardening switches: file editor, PHP in uploads, directory listing, wp-config.
   php permissions, XML-RPC, pingbacks, user enumeration, REST API for visitors,
   version number, the “admin” username, application passwords. Nothing is switched
   on until you choose, and one button turns on the safe set.
 * One-time actions: rotate security keys, change the table prefix, force a password
   reset. Shield’s settings are snapshotted first, and wp-config.php is backed up
   before it is edited.
 * Server audit of PHP settings, file permissions and ownership, with the exact 
   line or command to fix each problem
 * SSL certificate check with expiry emails, force HTTPS once HTTPS works, security
   headers, and a mixed-content check

**Activity log & overview**

 * An activity log of sign-ins, account and role changes, application passwords,
   plugin, theme and WordPress installs and updates, changes to key site settings
   and to Shield’s own settings, and everything Shield refused
 * Filter by type, user, severity and period, search by name or IP address, and 
   export exactly what is shown as CSV
 * A security score built from checks you can see — each recommendation says what
   it is worth and links to the fix
 * Fourteen days of threat activity, figures for blocked addresses, altered core
   files, waiting updates and failed sign-ins, and one-click switches for each protection
 * A Dashboard widget, and a Shield item in the admin bar with your security score
   and a count when something needs your attention
 * Country for every logged address, from Cloudflare or a free MaxMind GeoLite2 
   database on your own server

**Privacy**

 * Shield’s records are included in WordPress’s Export Personal Data and Erase Personal
   Data tools
 * Suggested wording for your privacy policy, reflecting your own retention settings
 * Optionally shorten IP addresses (203.0.113.0) and drop browser strings once events
   are older than a few days
 * No address is sent to any outside service to find its country

**Recovery**

If a protection ever locks you out:

 * Add `define( 'CYBEX_SHIELD_SAFE_MODE', true );` to wp-config.php. Every protection
   that can stand between you and your site is suspended; logging and the settings
   screens keep working so you can fix the cause.
 * Or, with shell access, use WP-CLI: `wp shield disable <module>`, `wp shield unblock
   <ip>`, `wp shield allow <ip>`.

**WP-CLI**

 * `wp shield status` — version, licence, safe mode and every module’s state
 * `wp shield modules`, `wp shield enable <module>`, `wp shield disable <module>`
 * `wp shield unblock <ip>`, `wp shield allow <ip> [--label=<label>]`
 * `wp shield logout <user>`, `wp shield logout --all`
 * `wp shield scan`
 * `wp shield settings get|set|reset|export|import`
 * `wp shield license status|activate|deactivate|refresh`
 * `wp shield login-url show|reset|recovery`

**Pro** (sold separately, delivered as an add-on plugin)

Two-factor authentication with passkeys, a firewall that can start before WordPress
loads, rate limiting and crawler control, geo-blocking, server rules for Apache 
and nginx, a malware scanner, and governance tools: a tamper-evident audit trail
of Shield’s settings, access levels and two-administrator approval, alerts to Slack,
Teams, PagerDuty, syslog and webhooks, PDF reports, configuration profiles and a
compliance map. The free plugin never needs Pro, and nothing in it is disabled or
time-limited. See https://cybexsoft.com/products/cybexsoft-shield for plans.

### External services

Cybexsoft Shield contacts the services below only for the features that need them.
Every one is optional; the default CAPTCHA is Shield’s own built-in challenge, which
contacts nobody, and country lookups use a database on your own server. No visitor
data is sent anywhere unless you switch on one of these features.

#### Google reCAPTCHA

Used only if you choose “Google reCAPTCHA” as the CAPTCHA provider under Shield  
CAPTCHA and enter your own keys.

The forms you protect then load a script from google.com, and Google receives each
visitor’s IP address, browser and device information, and their interaction with
the challenge — including visitors who never submit the form. When a form is submitted,
Shield sends the challenge token, your secret key and the visitor’s IP address to
Google to check the answer.

Service provided by Google: [terms of service](https://policies.google.com/terms),
[privacy policy](https://policies.google.com/privacy).

#### Cloudflare Turnstile

Used only if you choose “Cloudflare Turnstile” as the CAPTCHA provider under Shield
CAPTCHA and enter your own keys.

The forms you protect then load a script from challenges.cloudflare.com, and Cloudflare
receives each visitor’s IP address, browser and device information, and their interaction
with the challenge. When a form is submitted, Shield sends the challenge token, 
your secret key and the visitor’s IP address to Cloudflare to check the answer.

Service provided by Cloudflare: [terms of service](https://www.cloudflare.com/website-terms/),
[privacy policy](https://www.cloudflare.com/privacypolicy/).

#### Have I Been Pwned (Pwned Passwords)

Used only if password rules are switched on under Shield  Sessions & passwords with“
Not found in known data breaches” selected.

When a password is set or changed, and at most once a month when someone signs in,
Shield hashes the password with SHA-1 on your server and sends only the first five
characters of that hash to `https://api.pwnedpasswords.com`. The password itself
never leaves your server, and the answer is compared locally. If the service cannot
be reached, the check is skipped.

Service provided by Have I Been Pwned: [acceptable use](https://haveibeenpwned.com/API/v3#AcceptableUse),
[privacy policy](https://haveibeenpwned.com/Privacy).

#### Google Safe Browsing

Used only if you enter a Google Safe Browsing API key under Shield  Settings.

Once a day, Shield sends your site’s home address and your API key to `https://safebrowsing.
googleapis.com` to ask whether Google is warning visitors away from the site. No
visitor data is sent.

Service provided by Google: [terms of service](https://developers.google.com/terms),
[privacy policy](https://policies.google.com/privacy).

#### WordPress.org

Used by the file integrity scan and Plugin & theme health, which are on by default.

Shield asks api.wordpress.org and downloads.wordpress.org for the official checksums
of your WordPress version and of plugins hosted on WordPress.org, and for public
information about those plugins (whether they are still listed, when they were last
updated). When you choose to restore a file, its official copy is downloaded from
core.svn.wordpress.org or plugins.svn.wordpress.org. Each request names only the
WordPress version, locale, plugin slug and version concerned.

Service provided by WordPress.org: [privacy policy](https://wordpress.org/about/privacy/).

#### Cybexsoft licence server

Used only if you have bought the Pro add-on and enter a licence key under Shield
Licence.

Your licence key and your site’s home address are sent to `https://cybexsoft.com/
api/licenses` when you activate or deactivate the key, and once a day afterwards
to confirm it is still valid. Nothing is sent while no licence key is stored, which
is the case on every free install.

Service provided by Cybexsoft: [terms of service](https://cybexsoft.com/terms-of-service),
[privacy policy](https://cybexsoft.com/privacy-policy).

### Third-party code

The plugin is distributed under the GNU General Public License, version 3 or later.
Version 3 rather than 2, because it includes code under the Apache License 2.0, 
which is compatible with GPLv3 but not with GPLv2.

 * **MaxMind-DB-Reader-php** — Copyright (c) MaxMind, Inc., Apache License 2.0. 
   Portions of the .mmdb reader in `includes/class-cybex-shield-mmdb-reader.php`
   are derived from it, in modified form. No MaxMind database is bundled; you supply
   your own, and it stays subject to MaxMind’s terms. MaxMind and GeoLite are trademarks
   of MaxMind, Inc.; this plugin is not affiliated with or endorsed by them.
 * **Public Sans** and **Space Grotesk** — SIL Open Font License 1.1, served from
   this plugin rather than a font CDN, so no administrator’s IP address is handed
   to a third party when the dashboard loads.

Full notices are in the `NOTICE` file, and the licence itself in `LICENSE.txt`.

## Screenshots

[⌊Security overview: a score built from checks you can see, what to fix next and
what each fix is worth, fourteen days of threat activity, and a switch for every
protection.⌉⌊Security overview: a score built from checks you can see, what to fix
next and what each fix is worth, fourteen days of threat activity, and a switch 
for every protection.⌉[

Security overview: a score built from checks you can see, what to fix next and what
each fix is worth, fourteen days of threat activity, and a switch for every protection.

[⌊Activity log: sign-ins, account, plugin and settings changes and everything Shield
refused, with filters, search and CSV export.⌉⌊Activity log: sign-ins, account, 
plugin and settings changes and everything Shield refused, with filters, search 
and CSV export.⌉[

Activity log: sign-ins, account, plugin and settings changes and everything Shield
refused, with filters, search and CSV export.

[⌊Login attempts: brute-force limits, with failed sign-ins, lockouts and the account
names being tried.⌉⌊Login attempts: brute-force limits, with failed sign-ins, lockouts
and the account names being tried.⌉[

Login attempts: brute-force limits, with failed sign-ins, lockouts and the account
names being tried.

[⌊IP blocking: block and allow lists, temporary and permanent bans, and where attacks
come from.⌉⌊IP blocking: block and allow lists, temporary and permanent bans, and
where attacks come from.⌉[

IP blocking: block and allow lists, temporary and permanent bans, and where attacks
come from.

[⌊Sessions & passwords: password rules with a breached-password check, and every
signed-in device.⌉⌊Sessions & passwords: password rules with a breached-password
check, and every signed-in device.⌉[

Sessions & passwords: password rules with a breached-password check, and every signed-
in device.

## Installation

 1. Upload the plugin to `/wp-content/plugins/cybexsoft-shield`, or install it from
    the Plugins screen.
 2. Activate it.

Shield works out where visitor IP addresses come from the first time you open its
dashboard: straight from visitors, through Cloudflare, or through your host’s own
proxy. It only trusts a proxy it can verify from the connection itself. If it cannot
tell (another CDN, for example), the setup wizard asks, and you can always change
it under Settings.

## FAQ

### Does it work on multisite?

Yes. Each site keeps its own settings, logs and block lists, and is configured by
its own administrator.

### How do I see which country an address is from?

Behind Cloudflare, Shield reads it from Cloudflare’s header. Anywhere else, download
the free GeoLite2 City or Country database from MaxMind, put the .mmdb file somewhere
on the server outside the web root, and enter its path under Settings  Visitor location.
Lookups happen on your server.

### What personal data does Shield store?

For each security event: the time, IP address, country (when known), browser user-
agent and — for sign-ins — the account or username involved. It is kept for the 
number of days set under Settings (30 by default). Shield’s records are included
in WordPress’s personal-data export and erasure tools.

### What happens to my data if I delete the plugin?

It is kept, unless you switch on “Delete all data when the plugin is deleted” under
Settings. Deactivating never removes anything.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Cybexsoft Shield” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ CybexSoft ](https://profiles.wordpress.org/rahul1099/)

[Translate “Cybexsoft Shield” into your language.](https://translate.wordpress.org/projects/wp-plugins/cybexsoft-shield)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/cybexsoft-shield/),
check out the [SVN repository](https://plugins.svn.wordpress.org/cybexsoft-shield/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/cybexsoft-shield/)
by [RSS](https://plugins.trac.wordpress.org/log/cybexsoft-shield/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial release.
 * Login protection: login attempt limits with per-account lockout, CAPTCHA (built-
   in, reCAPTCHA or Turnstile) on WordPress, WooCommerce and Contact Form 7 forms,
   a honeypot field, IP block and allow lists with automatic bans, a blocked page
   with self-unblock, and a custom login URL with a recovery link.
 * Sessions & passwords: password rules with a breached-password check, a list of
   every session with sign-out, session limits and timeouts, new-device alerts, 
   and a Security section on each profile.
 * Site scanning: file integrity against official checksums with restore, quarantine
   and a diff view; plugin and theme health; an optional Safe Browsing check.
 * Hardening switches, one-time actions with settings snapshots, a server audit 
   that says how to fix each problem, and SSL and security-header checks.
 * An activity log with filters, search and CSV export; a security score with recommendations;
   a Dashboard widget and an admin-bar item with the score and open notifications;
   country lookups from Cloudflare or your own GeoLite2 database.
 * Privacy: personal-data export and erasure, suggested privacy-policy text, and
   optional IP shortening.
 * Safe mode and WP-CLI commands for getting back in if a protection locks you out.
 * Six colour themes for Shield’s screens on their own Appearance page (Harbor Navy,
   Deep Ocean, Evergreen, Merlot, Ivory & Ink, Mist), the same as Cybexsoft AI’s,
   or your own primary and accent colours; the accent also lines the top of the 
   band.

## Meta

 *  Version **1.0.0**
 *  Last updated **20 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.8 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [Activity Log](https://wordpress.org/plugins/tags/activity-log/)[Brute Force](https://wordpress.org/plugins/tags/brute-force/)
   [hardening](https://wordpress.org/plugins/tags/hardening/)[login security](https://wordpress.org/plugins/tags/login-security/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/cybexsoft-shield/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/cybexsoft-shield/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/cybexsoft-shield/reviews/)

## Contributors

 *   [ CybexSoft ](https://profiles.wordpress.org/rahul1099/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/cybexsoft-shield/)