შიგთავსზე გადასვლა
  • შესვლა
  • რეგისტრაცია
WordPress.org

საქართველო

  • თემები
  • ჩადგმები
  • News
  • მხარდაჭერა
  • WordPress-ის შესახებ
  • ჩვენს შესახებ
  • Get WordPress
Get WordPress

ჩადგმები

  • ჩემი რჩეულები
  • ბეტა-ტესტირება
  • დეველოპერები
ჩამოტვირთვა

Shield Security – Smart Bot Blocking & Intrusion Prevention

ავტორი: Shield Security
  • დეტალები
  • მიმოხილვა
  • დაყენება
  • დეველოპმენტი
მხარდაჭერა

აღწერა

Features You’ll Absolutely Love

  • Exclusive AntiBot Detection Engine – a powerful alternative for Google reCAPTCHA and CloudFlare Turnstile.
  • Automatic Bot & IP Blocking – score-based security intelligence to block bad bots.
  • Instant Bad Bot Blocking with our exclusive CrowdSec integration
  • Easy To Understand Dashboard points you to quick wins and areas you can quickly improve
  • Block Bots On Important Forms:
    • Login Forms
    • User Registration Forms
    • Lost Password Reset Forms
    • [ShieldPRO] WooCommerce & Easy Digital Downloads Security
    • [ShieldPRO] Memberpress, LearnPress, BuddyPress, WP Members, ProfileBuilder Security
  • Brute Force Security Protection, Limit Login Attempts + Login Cooldown Security
  • Powerful Firewall Security Rules
  • Restricted Security Admin Access
    • Prevents Unauthorized Changes By Compromised Admins.
  • (MFA) Two-Factor / Multi-Factor Login Security Authentication:
    • Email
    • Google Authenticator
    • Yubikey
    • [ShieldPRO] U2F Security Keys
    • [ShieldPRO] Backup Login Security Codes
    • [ShieldPRO] Multiple Yubikey per User
    • [ShieldPRO] Remember Me (reduces 2FA requests for users)
  • Block XML-RPC (including Pingbacks and Trackbacks)
  • Block Anonymous Rest API
  • Block, Bypass and Analyse IP Addresses
    • Automatic IP Address Blocking Using Points-Based Security System
    • Block or Bypass individual IPs
    • Block or Bypass IP Subnets
    • Full IP Security Analysis in 1 place to review activity on your sites
  • Comprehensive WordPress File Security Scanner for Intrusions and Hacks
    • Detect File Changes – Scan & Repair WordPress Core Files
    • Detect Unknown/Suspicious PHP Files
    • Detect Abandoned Plugins.
    • [ShieldPRO] Malware Security Scanner – detects known and unknown malware.
    • [ShieldPRO] Plugin and Theme Security Scanning – identify file changes in your plugins/themes.
    • [ShieldPRO] Detect Plugins/Themes With Known Security Vulnerabilities.
  • Create a Private Secure Login URL by hiding wp-login.php
  • Detect (and Block) Comment SPAM from Bots and Humans.
  • reCAPTCHA & hCAPTCHA support
  • Never Block Google: Automatic Detection and Bypass for GoogleBot, Bing and other Official Search Engines including:
    • Google
    • Bing,
    • DuckDuckGo
    • Yahoo!
    • Baidu
    • Apple
    • Yandex
  • Automatically Detect 3rd Party Services and Prevent Blocking Of:
    • ManageWP / iControlWP / MainWP
    • Pingdom, NodePing, Statuscake, UptimeRobot, GTMetrix
    • Stripe, PayPal IPN
    • CloudFlare, SEMRush
  • Full Security Audit Trail – Monitor All Site Activity, including:
    • All login/registration attempts
    • Plugin and Theme installation, activation, deactivation etc.
    • User creation and promotion
    • Page/Post create, update, delete
  • Advanced User Sessions Security Control
    • Restrict Multiple User Login
    • Restrict Users Session To IP
    • Block Use Of Pwned Passwords
    • Block User Enumeration (?author=x)
    • [ShieldPRO] User Suspend – manual and automatic.
  • Full/Automatic Support for All IP Address Sources including Proxy Support
  • Full Traffic Log and Request Monitoring
  • HTTP Security Headers & Content Security Policies (CSP)

Full Shield Security Features List

Shield is the only security plugin for WordPress that fully prioritises protection and intrusion prevention before repair. With Shield, your site will start to block visitors as they probe your site looking for vulnerabilities, and before they can begin to do any damage.

No other standalone WordPress security plugin (including Wordfence, WP Cerber, Ninja Firewall, All-In-One Security) approaches security in this way. The 1st step in any good security system is Intrusion Detection/Prevention, the 2nd step is repair. Shield does both.

Our mission is to block bad IPs and requests before they can do any damage. Shield will block all automated Comment SPAM, brute force logins, plugin-vulnerability exploitation, malware injection, vulnerability scanning, password stuffing, contact form spam, and so much more. If you’re disappointed with the performance of your current solution, give Shield a try – we promise that you won’t be disappointed.

Use the power of the network. ShieldNET is our new and exclusive network-based intelligence platform that draws-in information from all around the globe to help Shield Security plugins be smarter when assessing security threats and taking appropriate action. And with our new Crowdsec partnership you’ve got even more data to make smarter decision.

Get the highest rated 5* Security Plugin for WordPress

Per download, Shield Security has the highest 5* rating in the WordPress plugin repository.

Leave Behind the Security Marketing Hype and Scare Mongering

Our Security solution isn’t designed to scare you and make you feel unsafe. We’ll never try to scare you.

2 Key WordPress Security Strategies

Shield Security uses 2 simple key strategies to protect your WordPress sites:

  1. Intrusion Prevention System – Detect Bots/Malicious IPs that will try to hack and invade your WordPress sites.
  2. Cure – Block Bad Bots and Repair Hacks

Key Security Strategy #1: Hacking Prevention

Bad Bots are the primary cause for nearly all our security troubles – they’re relentless, automatic and powerful.

Shield Security is highly focused on their detection and eradication from your WordPress sites.

Blocking malicious bots before they do damage through malware and exploitation of vulnerabilities is the #1 security strategy to protect and enhance security on a WordPress site.

Shield detects these malicious visitors, then blocks their access to your site completely. This involves analysing different security bot-signals and combining them to identify a visitor as malicious.

These security signals include:

  • site probes that generate 404 errors
  • failed logins
  • logins with invalid usernames
  • xml-rpc access
  • fake search engine web crawlers
  • invalid user agents
  • excessive website requests and resource abuse
  • and many more signals our security team have identified.

Early identification and blocking of malicious bots reduces your WordPress site’s vulnerability to any sort of attack.

Key Strategy #2: Hacking Cure

Even with the best security efforts, a site can get hacked. This usually involves file modification: either a hack file is added, or a file is changed.

There are 3 key WordPress assets whose files can be hacked:

  1. WordPress Core
  2. WordPress Plugins
  3. WordPress Themes

Almost every security plugin can now do #1 – it’s easy because WordPress.org provides file fingerprints for core files.

But, there are no hashes available for plugins and themes, so they can’t do it.

Shield is the only WordPress security plugin that offers full and accurate detection of file modifications for plugins and themes because we build our own file fingerprints.

Shield Security can compare the file contents of every plugin & theme in the WordPress.org repository, looking for changed or new files

And, if you’re a ShieldPRO client, you can protect premium plugins/themes too, including Yoast SEO and Advanced Custom Fields Pro.

Where possible, Shield Security will repair any unrecognised/modified files it detects.

Shield makes Security easy

There’s no reason for your WordPress security to be so complicated.

Shield Security is the easiest security plugin to setup – you simply activate it and off you go! As you learn more, you can tweak the settings to suit your needs.

Non-stop Security Notifications Are Not Okay.

Your security plugin must be smarter, and take responsibility for decisions so you don’t have to.

Shield Security handles many problems for you, making intelligent security decisions without noisy email notifications.

Dedicated Premium Security Support When You Go PRO

The Shield Security team prioritises email technical support over the WordPress.org forums.
Individual, dedicated technical support is only available to customers who have purchased Shield Pro.

Discover all the advantages of switching your WordPress security Pro at our Shield Security store.

ეკრანული სურათები

  • A top-level dashboard that shows all the important things you need to know at-a-glance.
  • IP Whitelist and Blacklists lets you manage access and blocks on your site with ease.
  • A full audit log lets you see everything that happens on your site and why, and by whom.
  • Track user sessions and monitor who is logged-into your site and what they're doing.
  • Simple, clean options pages that let you configure Shield Security and all its options easily.

დაყენება

Note: When you enable the plugin, the firewall is not automatically turned on. This security plugin contains various different sections of security protection for your site and you should choose which you need based on your own requirements.

Why do we do this? It’s simple: performance and optimization – there is no reason to automatically turn on features for people that don’t
need it as each site and set of requirements is different.

This plugin should install as any other WordPress.org repository plugin.

  1. Browse to Plugins -> Add Plugin
  2. Search: Shield
  3. Click Install
  4. Click to Activate.

A new menu item will appear on the left-hand side called ‘Shield’.

ხდკ

Please see the dedicated security help centre for details on features and some FAQs.

How does the Shield Security compare with other WordPress Security Plugins?

Easy – we’re just better! 😉

Firstly, we don’t modify any core WordPress or web hosting file. This is important and explains why randomly you upgrade your security plugin and your site dies.

Ideally you shouldn’t use this along side other Anti-SPAM plugins or security plugins. If there is a feature you need, please feel free to suggest it in the support forums.

My server has a securiy firewall, why do I need this plugin?

This plugin is an application layer firewall, not a server/network security firewall. It is designed to interpret web calls to your site to look for attempts to circumvent it and gain unauthorized access.

Your network security firewall is designed to restrict access to your server based on certain types of network traffic. The Shield Security plugin is designed to restrict access to your site, based on certain types of web calls.

How does the IP Security Bypass List work?

Any IP address that is on the whitelist will not be subject to any of the firewall security processing. This setting takes priority over all other settings.

Does the IP Bypass support IP ranges?

Yes. To specify a range you use CIDR notation. E.g. ABC.DEF.GHJ.KMP/16

I want to review and manage IP addresses, where can I do that?

You can use IP Lists section. This is an essential tool you can use to analyse IP address, review information concerning blocked and bypassed IP addresses.

It shows you geo-location information and all the request made to your site by that IP, including offenses and any logged-in users.

I’ve locked myself out from my own site!

This happens when any the following 3 conditions are met:

  • you have added your IP address to the firewall blacklist,
  • you have enabled 2 factor authentication and email doesn’t work on your site (and you haven’t chosen the override option)

You can completely turn OFF (and ON) the Shield Security by creating a special file in the plugin folder.

Here’s how:

  1. Open up an FTP connection to your site, browse to the plugin folder /wp-content/plugins/wp-simple-firewall/
  2. Create a new file in here called: “forceOff”.
  3. Load any page on your WordPress site.
  4. After this, you’ll find your Shield has been switched off.

Remember: If you leave one of these files on the server, it will override your on/off settings, so you should delete it when you no longer need it.

Which takes precedence… bypass list or block list?

Bypass List: so if you have the same address in both lists, it’ll be bypassed and never be blocked.

Can I assist with development?

Yes! We actively develop our plugin on Github and the best thing you can do is submit pull request and bug reports which we’ll review.

How does the pages/parameters whitelist work?

It is a comma-separated list of pages and parameters. A NEW LINE should be taken for each new page name and its associated parameters.

The first entry on each line (before the first comma) is the page name. The rest of the items on the line are the parameters.

The following are some simple security examples to illustrate:

edit.php, featured

On the edit.php page, the parameter with the name ‘featured’ will be ignored.

admin.php, url, param01, password

Any parameters that are passed to the page ending in ‘admin.php’ with the names ‘url’, ‘param01’ and ‘password’ will
be excluded from the firewall processing.

*, url, param, password

Putting a star first means that these exclusions apply to all pages. So for every page that is accessed, all the parameters
that are url, param and password will be ignored by the firewall.

How does the login cooldown security feature work?

Login Cooldown Security prevents more than 1 login attempt to your site every “so-many” seconds. So if you enable a login cooldown of 60 seconds, only 1 login attempt will be processed every 60 seconds. If you login incorrectly, you wont be able to attempt another login for a further 60 seconds.

This security system completely blocks any level of brute-force login attacks and a cooldown of just 1 second goes a long way to adding security to your WordPress login.

More Info

How does the GASP Login Guard work?

This is best described on the blog

How does the 2-factor authentication security work?

2-Factor Authentication is best described here.

I’m not receiving the email with 2FA verification code.?

Email delivery is a huge problem with WordPress sites and is very common.

Your WordPress is not designed to send emails. The best solution is to use a service that is dedicated to the purpose of sending emails.

This is what we recommend.

I’m getting an update message although I have auto update enabled?

The Automatic (Background) WordPress updates happens on a WordPress schedule – it doesn’t happen immediately when an update is detected.
You can either manually upgrade, or WordPress will handle it in due course.

I’m getting large volumes of comment SPAM. How can I stop this?

You can use Shield Security to block 100% of automated spam bots and also block and analyse human spam. This is best described here.

Do you offer White Label?

Yes, we do. You can essentially rename the Shield Security plugin to whatever you would like it to be.

It ensures a more consistent brand offering and presents your business offering as a more holistic, integrated solution.

We go into further detail here.

I’d like to customise 2FA emails sent to my site users. How can I do that?

You can use our custom templates for this purpose.

How can I change the text/html in the Plugin Security Badge?

Use the following filter and return the HTML/Text you wish to display:

add_filter( 'icwp_shield_plugin_badge_text', 'your_function_to_return_text' );

How can I change the roles for login notification security emails?

Use the following filter and return the role in the function:

add_filter( 'icwp-wpsf-login-notification-email-role', 'your_function_to_return_role' );

Possible options are: network_admin, administrator, editor, author, contributor, subscriber

What changes go into each Shield Security release?

The changelog outlines the main changes for each release. We group changes by minor release “Series”. Changes in smaller “point” releases are highlighted
using (.1) notation. So for example, version 10.1.1 will have changelog items appended with (.1)

You can view the entire Shield changelog here.

მიმოხილვები

Fast becoming a terrible plugin

yarbou 20.03.2023 1 reply
Ive been using Sheild Security for years. It was 5 stars. Not anymore. Lucky to be 2 stars. I have both pro and free sites. Sheild Security FREE site analysis constantly and increasingly rates sites as DDDDCBDACCDD. Sites that were rated ABCCCDBDCA have slowly become DDCDDACBDA (just an example) - guilting free users (and their clients) to upgrade (and think of you as an idiot). Stop playing games! Seriously! Not to mention the pain your plugin causes locking out sites constantly - ok - adjust the settings I hear you say - yep - to the point of making the features of your plugin pretty pointless. Disappointed.

Resolving a Caching Issue

gerhardjvr 16.02.2023
The Shield Security Team absolutely Rocks!I had a dreadful occasion to troubleshoot a serious performance degradation issue on one of my websites, and through the process I uncovered that Shield Security sets a SET-COOKIE state through headers on my website, which renders dynamic caching caching not functional.I reported this anomaly on the Shield Security Facebook page, and within a surprisingly short period of time, Paul Goodchild replied back to me, and he worked with me with my test cases all along, until a beta release, and subsequently, v17.0.1 release addressed the issue.Thank you so much to Paul and your Team for your perseverance and persistence in uncovering the root cause of this issue, which had a positive effect on frontend page load speeds.Kudos! Gerhard

Well thought out, must have plug-in

jacksonbatnerd 16.02.2023
Well coded, good protection. The only thing I hope the dev adds in the future update, ability to 'White List' your IPs from your country and/or 'Block Countries'.

Do not download!

Nico Visagie 16.02.2023 6 replies
[UPDATED] This plugin is not compatible with PHP 8.2. I found that out only after activating the plugin and then getting a "critical error" message from WordPress which took my e-commerce website offline for an hour! I had to manually remove the plugin to get control of my website back. Apparently, the plugin does work with PHP 8.0 and 8.1, but I have not tested it as such. According to the author PHP 8.2 is very new (released in December 2022) and they did not have the time to adjust the plugin for it. Fair enough, but a warning to this fact in the plugin description would have been nice. The rating I have given this plugin is for their support service which I must say is really good! In today's age of buck passing good support is always welcome! ------------------------ [ORIGINAL] This thing messed up my wordpress site with a critical error after activation. DO NOT DOWNLOAD!

The best Security Plugin

kryoz507 30.12.2022
The best security plugin if you think about sucuri, wordfence, malcare, Itheme and others. I recommend 100% Shield Pro more features and easy to use.Only have to mix cloudflare (Free Account) and shieldpro and your website will be secure.

Excellent support, should you need it

funkysam 14.12.2022
My experience with this plugin has been nothing short of amazing. I am running a small website, quite low traffic but with a woocommerce shop selling electronic devices we produce in house. I started getting security issues a few years ago and installed Shield Pro after a quick rundown of all security plugins offered at the time. I've spent a couple days setting the plugin up and I've had zero issues with security since this day. It's now transparent for me, I do not even think it is installed. It's doing its job. I recently had an issue where the license couldn't be activated anymore. After quick investigation by their great team, it was a problem with my host and the outdated openssl library version they were using on the server. This was solved by my host by migrating the website to a new up to date server. In a nutshell: Support is great, should you need it. Plugin is great, and you know you need it 🙂
1,003 რევიუს წაკითხვა

მონაწილეები & დეველოპერები

“Shield Security – Smart Bot Blocking & Intrusion Prevention” ღია პროგრამული უზრუნველყოფაა. შემდეგმა ადამიანებმა წვილი შეიტანეს მის განვითარებაში.

მონაწილეები
  • Paul
  • Shield Security

“Shield Security – Smart Bot Blocking & Intrusion Prevention” ითარგმნა 7 ენაზე. გმადლობთ თარჯიმნებო თქვენი წვლილისათვის.

გადათარგმნეთ Shield Security – Smart Bot Blocking & Intrusion Prevention თქვენს ენაზე.

დაინტერესებული ხართ დეველოპმენტით?

დაათვალიერეთ კოდი, შეამოწმეთ SVN რეპო, ან გამოიწერეთ შექმნის ჟურნალი : RSS.

ცვლილებები

View Shield Security Changelog

ShieldPRO delivers exclusive, enhanced security features for the serious site administrator
looking to maximise their WordPress security for themselves and their clients.

You’ll of course have direct access to our technical support team and the option to reach out to us for any security questions or concerns.

Go Pro or grab the free ShieldPRO Trial.

მეტა

  • ვერსია: 17.0.18
  • ბოლო განახლება: 3 დღის წინ
  • აქტიური ინსტალაციები: 50,000+
  • WordPress-ის ვერსია: 4.7, ან უფრო მაღალი
  • გატესტილია ვერსიამდე: 6.2
  • PHP ვერსია: 7.2.5, ან უფრო მაღალი
  • ენები:

    Dutch, English (Canada), English (UK), English (US), German, Italian, Japanese და Romanian.

    თარგმნეთ თქვენს ენაზე

  • ჭდე:
    firewalllimit loginmalware scantwo factor authentication
  • დამატებითი ხედი

რეიტინგები

ყველას ნახვა
  • 5 ვარსკვლავი 941
  • 4 ვარსკვლავი 24
  • 3 ვარსკვლავი 11
  • 2 ვარსკვლავი 9
  • 1 ვარსკვლავი 18
Log in to submit a review.

მონაწილეები

  • Paul
  • Shield Security

მხარდაჭერა

პრობლემა, რომლებიც გადაწყდა ბოლო ორი თვის განმავლობაში:

გადაწყვეტილია: 6, სულ: 7

მხარდაჭერის ფორუმის ნახვა

შემოწირულობა

გსურთ ამ ჩადგმის განვითარების მხარდაჭერა?

შეწირეთ თანხა ამ ჩადგმას

  • About
  • News
  • Hosting
  • Donate
  • Swag
  • Documentation
  • Developers
  • Get Involved
  • Learn
  • Showcase
  • Plugins
  • Themes
  • Patterns
  • WordCamp
  • WordPress.TV
  • BuddyPress
  • bbPress
  • WordPress.com
  • Matt
  • Privacy
  • Public Code
WordPress.org
WordPress.org

საქართველო

  • Visit our Facebook page
  • Visit our Twitter account
  • Visit our Instagram account
  • Visit our LinkedIn account
კოდი პოეზიაა.