WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: wp-simple-firewall (Used by 8,578 domains)

Shield: Blocks Bots, Protects Users, and Prevents Security Breaches

πŸ‘€ Paul πŸ“¦ v21.2.6 πŸ”— Plugin Homepage

Shield stops bot attacks before they hack your site. Bots CAN be stopped. Shield stops them.

Key Security Features At A Glance

[PRO-Only] Zero-Configuration, Fast & Reliable WordPress Backups Included

We’ve made WordPress backups faster than ever with our integrated WordPress Disaster Recovery Backups solution – ShieldBACKUPS.

No more risky Cloud Storage/OAuth credentials exposed on your sites; Backups that work without relying on a temperamental WordPress cron.

ShieldBACKUPS keeps your data off-site, encrypted, and far away from hackers.

silentCAPTCHA Bad Bot Protection

Bad bots are your #1 security threat. They account for nearly all WordPress security probes, attacks, injections, malware, and vulnerability exploitation.

Google reCAPTCHA and CloudFlare Turnstile are considered the best way to detect bots, but these along with all other CAPTCHAs interrupt the user experience.

Shield’s exclusive silentCAPTCHA detects bad bots and blocks them from taking any abusive actions on your site, such as brute-force user login attacks and WP Comments SPAM.

Furthermore, privacy directives from legislation such as Europe’s GDPR restrict what data you may share of your visitors. All silentCAPTCHA data is kept on your WordPress site and ensures full compliance with GDPR regulations.

Comprehensive Activity Log

Shield’s has best-in-class logging that documents every WP action on your site.

Unlike existing logging solutions, Shield detects changes to your WordPress sites that happen directly on your database. e.g. by hackers that have infiltrated your defenses via an exposed vulnerability.

No other WordPress security plugin does this.

Limit Login Attempts and Block User Registration SPAM

silentCAPTCHA technology is invisible to your visitors and protects your WordPress login, registration and lost password forms from brute force attacks, and eliminates user registration SPAM from bots.

User Session Theft Protection

Shield can lock user session to browsers, or IP addresses. Combine with 2FA (below), you can protect your users from session theft and account theft.

Two-Factor Authentication (2FA) for all users

Two-Factor Authentication is a crucial part of WordPress user security. It protects against account theft, takeover, and sharing. Shield supports email-based login code, Google/Microsoft/Lastpass Authenticator, Yubikey One-Time Passwords and Passkeys (pro).

Exclusive Security Admin Protection

Not only does Shield Security protect your WordPress site, it also provides security against tampering of key WordPress options and the Shield Security plugin itself. With Shield’s exclusive Security Admin feature, you can lockdown the security plugin from other admins to prevent accidental or malicious changes that will impact your security.

CrowdSec Partnership

Shield is the only WordPress security plugin with strategic partnerships that bring powerful protection to your WordPress sites. With our CrowdSec integration, your WordPress sites benefit from crowd-sourced IP Block Lists so your site can block malicious bots before they can do any damage whatsoever.

All The Features You’ll Absolutely Love

  • [ShieldPRO] ShieldBACKUPS – Disaster-proof your WordPress site with fast, reliable, easy WordPress backups!
  • Exclusive silentCAPTCHA Security – WordPress-specific bot-detection alternative to Google reCAPTCHA and CloudFlare Turnstile.
  • Automatic Bot & IP Blocking – reputation-based security intelligence to block repeat offenders automatically.
  • Instant Bad Bot Blocking with our exclusive CrowdSec Security integration
  • Easy To Understand Security Dashboard that highlights quick wins and areas to rapidly improve site security
  • [ShieldPRO] Artificial Intelligence based PHP Malware Detection
  • Security for your important user forms, by blocking Block Bots:
    • Login Forms
    • User Registration Forms
    • Lost Password Reset Forms
    • [ShieldPRO] WooCommerce & Easy Digital Downloads
    • [ShieldPRO] Contact Form SPAM Protection: Contact Form 7, NinjaForms, Elementor, WP Forms, and more!
    • [ShieldPRO] Memberpress, LearnPress, BuddyPress, WP Members, ProfileBuilder
  • Brute Force Security Protection, Limit Login Attempts + Login Cooldown
  • Powerful Firewall Rules
  • Restricted Security Admin Access
  • (MFA) Two-Factor / Multi-Factor Login Authentication:
    • Email
    • Google Authenticator
    • Yubikey
    • [ShieldPRO] Passkeys
    • [ShieldPRO] Backup Login Codes
    • [ShieldPRO] Multiple Yubikey per User
    • [ShieldPRO] Remember Me (reduces 2FA requests for users)
  • Block XML-RPC (including Pingbacks and Trackbacks)
  • Security firewall for the REST API – block anonymous requests
  • Powerful IP Addresses-based Security:
  • Comprehensive WordPress File Scanner for Intrusions and Hacks
    • Detect File Changes – Scan & Repair WordPress Core Files
    • Detect Unknown/Suspicious PHP Files
    • Detect Abandoned Plugins.
    • [ShieldPRO] Malware Scanner – detects known and unknown malware.
    • [ShieldPRO] Plugin and Theme Scanning – identify file changes in your plugins/themes.
    • [ShieldPRO] Detect Plugins/Themes With Known Security Vulnerabilities.
  • Create a Private Secure Login URL by hiding wp-login.php
  • Comment SPAM Blocking – Block Comment SPAM from Bots and Humans.
  • Never Block Google: Smart Security Automatically Detects Known Good Bots: GoogleBot, Bing and other Official Search Engines including:
    • Google
    • Bing,
    • DuckDuckGo
    • Yahoo!
    • Baidu
    • Apple
    • Yandex
  • Automatically Detects 3rd Party Services and Prevents Blocking Of:
    • ManageWP / iControlWP / MainWP
    • Pingdom, NodePing, Statuscake, UptimeRobot, GTMetrix
    • Stripe, PayPal IPN
    • CloudFlare, SEMRush
  • Full Security Activity Log – Monitor All Site Activity, including:
    • Activity log for all user login & registration attempts
    • Plugin and Theme installation activity logs, including activation & deactivation etc.
    • User creation activity log, including detection of administrator promotions
    • Activity log for Page/Post create, update, delete
  • Advanced User Sessions Control
    • Restrict Multiple User Login
    • Restrict Users Session To IP
    • Password Security – Block Pwned Passwords
    • User Enumeration Blocking – Firewall blocks requests to ?author=x
    • [ShieldPRO] Security for old and idle user account with manual and automatic User Suspend.
  • Full/Automatic Support for All IP Address Sources including Proxy Support
  • HTTP Request/Traffic Logging – Full Traffic Logging and Request Monitoring
  • [ShieldPRO] Traffic Rate Limiting Security – prevent server overload from DoS Attacks
  • HTTP Security Headers & Content Security Policies (CSP)

Full Shield Security Features List

Shield is the only security plugin for WordPress that prioritises protection and intrusion prevention before repair. With Shield Security, your site will immediately to block visitors as they probe your site looking for vulnerabilities, and before they can do damage.

No other standalone WordPress security plugin (including Wordfence, WP Cerber, Ninja Firewall, All-In-One Security) approaches security in this way. The 1st step in any good security system is Intrusion Detection/Prevention, the 2nd step is repair. Shield Security does both.

Get the highest rated 5* Security Plugin for WordPress

Per download, Shield Security has the highest 5* rating in the WordPress plugin repository.

Leave Behind the Security Marketing Hype and Scare Mongering

Our solution isn’t designed to scare you and make you feel unsafe.

2 Key WordPress Security Strategies

Shield Security uses 2 simple key strategies to protect your WordPress sites:

  1. Intrusion Prevention System – Detect Bots/Malicious IPs that will try to hack and invade your WordPress sites.
  2. Block & Recover – Block Bad Bots and Repair Hacks

Key Security Strategy #1: Hacking Prevention

Bad Bots are the primary cause for nearly all our security troubles – they’re relentless, automatic and powerful.

Shield Security is highly focused on their detection and eradication from your WordPress sites.

Blocking malicious bots before they do damage through malware and exploitation of vulnerabilities is the #1 security strategy to protect and enhance security on a WordPress site.

Shield detects these malicious visitors, then blocks their access to your site completely. This involves analysing different security bot-signals and combining them to identify a visitor as malicious.

These security signals include:

  • site probes that generate 404 errors
  • failed logins
  • logins with invalid usernames
  • xml-rpc access
  • fake search engine web crawlers
  • invalid user agents
  • excessive website requests and resource abuse
  • and many more signals our security team have identified.

Early identification and blocking of malicious bots reduces your WordPress site’s vulnerability to any sort of attack.

Key Strategy #2: Hacking Recovery

Even with the best security efforts, a site can get hacked. This usually involves file modification: either a hack file is added, or a file is changed.

There are 3 key WordPress assets whose files can be hacked:

  1. WordPress Core
  2. WordPress Plugins
  3. WordPress Themes

Almost every security plugin can now do #1 – it’s easy because WordPress.org provides checksums for core files.

But, there are no hashes available for plugins and themes, particularly premium plugins, so they can’t do it.

Shield is the only WordPress security plugin that offers accurate detection of file modifications for all plugins and themes because we build our own file fingerprints.

Shield can compare the file contents of every plugin & theme in the WordPress.org repository, looking for changed or new files

And, if you’re a ShieldPRO client, you can protect premium plugins/themes too, including Yoast SEO and Advanced Custom Fields Pro.

Where possible, Shield will repair any unrecognised/modified files it detects.

Non-stop Security Notifications Are Not Okay.

Your security plugin must be smarter, and take responsibility for decisions, so you don’t have to.

Shield handles many problems for you, making intelligent decisions without noisy email notifications.

Dedicated Premium Support When You Go PRO

The Shield Security team prioritises email technical support over the WordPress.org forums.
Individual, dedicated technical support is only available to customers who have purchased Shield Pro.

Discover all the advantages of switching your WordPress security Pro at our Shield Security store.

Partnerships & Integrations

We believe that silentCAPTCHA is one of the simplest and most powerful solutions available today for all WordPress site owners to block and eliminate automated bot spam.

That’s why we’ve started a collaboration campaign with other WordPress plugin developers to adapt their plugins to natively support Shield’s silentCAPTCHA solution, alongside Google reCAPTCHA & Cloudflare Turnstile.

When you use one of the products from any of our partners, you will be able to activate Shield’s silentCAPTCHA bot spam protection so that your forms are protected from automated spam. You won’t need any site/API keys, custom integrations, or JavaScript that can breaks your forms. It all works automatically for you when you enable the feature.

As of this release, we have partnered with the following WordPress form providers:

DomainExposuresHeadersLast Checked
b*b*m*s*.pl (WP 7.0) βœ… A 2026-06-16 19:04:49
s*m*a*e.pt (WP 6.5.8) πŸ‘€ D 2026-06-16 18:01:29
a*n*b*r*.c*m.ua (WP 6.9.4) βœ… D 2026-06-16 17:38:16
a*n*b*r*.uk (WP 6.9.4) βœ… D 2026-06-16 17:38:16
i*s*l*g*t.com πŸ“‚ F 2026-06-16 16:55:19
k*r*g*r*i*s*h*i*.at βœ… D 2026-06-16 16:29:39
p*e*s.p*l*j*.a*.id βœ… A 2026-06-16 15:56:07
p*s*a.p*l*j*.a*.id βœ… A 2026-06-16 15:56:07
a*a*o*t*o*s*a.pl πŸ‘€ D 2026-06-16 15:55:44
h*t*l*u*d*.org βœ… D 2026-06-16 15:54:12
v*r*e*i*k*l*e*i*1*a*k*t*e*.nl (WP 6.6.5) βœ… D 2026-06-16 14:21:15
b*t*.p*p*.pl πŸ‘€ D 2026-06-16 14:04:08
z*r*v*l*i*g*l*l*n*n.nl (WP 6.6.5) βœ… F 2026-06-16 14:03:17
l*v*d*r*e*o*a.c*m.br πŸ‘€ D 2026-06-16 13:14:58
2*b.games (WP 6.9.4) πŸ‘€ C 2026-06-16 12:45:05
s*g*w*w*o*c*b*d*i*g*l*s*a*i*g.k*n*t*.cloud (WP 6.8.3) βœ… D 2026-06-16 12:13:20
j*m.c*m.pl πŸ‘€ D 2026-06-16 10:41:12
l*c*i*o*a.de βœ… D 2026-06-16 09:49:55
s*r*n*a*d*i*.net (WP 6.9.4) βœ… F 2026-06-16 08:37:25
v*w*d*r.nl (WP 7.0) βœ… D 2026-06-16 08:18:32
m*s*e*o.es (WP 6.0.12) ⚠️ D 2026-06-16 07:51:39
c*o*b*o*s.a*d*e*s*c*e*l.com βœ… D 2026-06-16 07:27:51
t*i*b*e*e*.c*.at (WP 7.0) βœ… D 2026-06-16 06:45:03
r*m*r*e*.at (WP 7.0) βœ… D 2026-06-16 06:45:03
c*n.c*d*i*-*o*x*p*o*o*r*p*e.fr (WP 7.0) βœ… F 2026-06-16 06:25:56
s*p*n*s*a*d*c*p*.gr (WP 6.9.4) πŸ‘€ F 2026-06-16 06:12:24
n*a*h*a*o*n*t*a*.vn (WP 6.0.12) ⚠️ πŸ”“ πŸ‘€ D 2026-06-16 06:11:15
t*m*-*u*.pl (WP 4.9.29) ⚠️ F 2026-06-16 05:36:46
k*l*c.org (WP 7.0) βœ… D 2026-06-16 05:06:17
m*c*o*y*i*.de (WP 6.9.4) βœ… D 2026-06-16 04:46:20
e*d*r*c*e*b*u*r.at πŸ‘€ D 2026-06-16 04:42:55
h*r*y*r*i*c*m*n*.de (WP 4.9.26) ⚠️ F 2026-06-16 04:31:37
l*r*v*n*a*n*l.com βœ… F 2026-06-16 04:31:37
m*s*-*o*o*a*a.ch πŸ‘€ F 2026-06-16 04:31:37
p*n*m*.m*i*a*p*.com (WP 6.1.10) ⚠️ πŸ‘€ D 2026-06-16 03:39:30
a*r*a*b*o*s.n*w*a*t*.edu (WP 7.0) βœ… C 2026-06-16 03:25:47
b*o*n*.com βœ… D 2026-06-16 02:13:48
e*p*o*o*r*p*y*3*5.l*v*-*e*s*t*.com (WP 6.9.4) πŸ‘€ D 2026-06-16 01:53:17
f*e*-*i*-*r*e*e*-*a*b*r*.de (WP 7.0) πŸ‘€ F 2026-06-16 01:40:08
r*s*e*t*w*r*t.de (WP 7.0) βœ… F 2026-06-15 22:40:30
m*t*d*o.pl (WP 6.0.12) ⚠️ D 2026-06-15 22:32:40
c*l*p*.u*v.br (WP 7.0) βœ… D 2026-06-15 22:25:08
r*j*y.m*z*w*z*.pl (WP 6.0.9) ⚠️ F 2026-06-15 21:48:39
t*r*o*r*f*a.u*v.br (WP 7.0) βœ… D 2026-06-15 20:29:25
e*e*t*y*t*m.p*d*l*u*.o*g.uk (WP 7.0) πŸ‘€ C 2026-06-15 19:48:03
s*k*z*z*p*o*k.org (WP 7.0) βœ… F 2026-06-15 18:57:30
t*s*.s*h*o*s*f*l*e*h*u*.de βœ… D 2026-06-15 17:54:36
b*a*k*r*s*.app (WP 6.8.5) βœ… C 2026-06-15 17:36:55
m*n*l*n*n*a*n*i*d*r*.eu (WP 6.9.4) βœ… F 2026-06-15 17:31:46
m*n*e*r*n*n*a*u*i*.es (WP 6.3.5) ⚠️ F 2026-06-15 17:17:00
m*b*e*o*i*m*e*.pl (WP 6.9.4) βœ… D 2026-06-15 17:08:45
l*g*s*y*a.e*r*c*m*e*c*.pl (WP 7.0) βœ… D 2026-06-15 17:08:45
p*w*a*.w*o*a*a.pl (WP 7.0) βœ… A 2026-06-15 16:41:36
d*s*a*k.c*m.br βœ… C 2026-06-15 15:43:43
s*u*e*t*u*u*e.pl (WP 7.0) βœ… D 2026-06-15 15:37:32
b*a*m*k*m*r*s.dk (WP 7.0) βœ… D 2026-06-15 14:01:02
h*a*t*c*r*o*t*e*u*u*e.ch (WP 6.9.4) πŸ‘€ C 2026-06-15 13:58:07
w*w*.d*i.u*v.br (WP 7.0) βœ… D 2026-06-15 13:51:39
m*a.2*e.m*f*p*p*o*d.com βœ… D 2026-06-15 12:56:05
b*a*t*m.ru (WP 6.6.4) πŸ”“ D 2026-06-15 11:52:58
b*a*r*k.c*.uk (WP 7.0) βœ… C 2026-06-15 11:05:32
e*c*l*e*c*i*t*a*h*n*a*a*d*.org βœ… B 2026-06-15 09:34:17
l*g*c*e*-*e*p*a*n*n*.fr (WP 7.0) βœ… D 2026-06-15 09:31:52
i*t*r*r*m*x.it (WP 7.0) βœ… D 2026-06-15 09:30:10
w*l*e*m*b*a*.com (WP 7.0) πŸ‘€ C 2026-06-15 07:51:59
c*p*n*a*d*.net βœ… D 2026-06-15 07:31:32
p*p*k*s*a*i*.pl (WP 7.0) βœ… D 2026-06-15 07:30:15
d*i*p*a.org (WP 7.0) βœ… F 2026-06-15 07:15:10
s*i*b*d*i*e*z*s.pl (WP 7.0) βœ… D 2026-06-15 07:14:31
f*c*m*n*-*h*b.pl (WP 7.0) βœ… D 2026-06-15 06:55:53
d*s.u*v.br (WP 7.0) βœ… D 2026-06-15 06:18:55
l*u*y*.info (WP 7.0) βœ… C 2026-06-15 04:46:32
t*u*a*g*s*r*e*a*t*e*t*v*l.nz βœ… F 2026-06-15 01:02:16
h*g*e*l*n*e*-*i*d*r*i*d*c*.de (WP 7.0) βœ… D 2026-06-14 23:19:20
d*g*a*f*n*e*k*n.nl (WP 7.0) βœ… D 2026-06-14 23:04:19
v*e*a*m*i*h*.org (WP 6.9.4) βœ… D 2026-06-14 21:57:26
f*r*m.a*r*n*a.de (WP 6.8.5) πŸ‘€ C 2026-06-14 19:45:58
o*v*d*r*a.u*v.br (WP 7.0) βœ… D 2026-06-14 19:39:47
s*r*i*k*y*i*t*e*a*i*.nl (WP 7.0) βœ… C 2026-06-14 19:12:10
h*l*e*a*-*b.de βœ… D 2026-06-14 18:48:22
q*w*r*-*u*.de (WP 7.0) βœ… C 2026-06-14 18:03:55
p*o.u*v.br (WP 7.0) βœ… D 2026-06-14 17:22:10
s*c.u*v.br (WP 7.0) βœ… D 2026-06-14 17:22:10
n*n*f*l*p*t*.org πŸ‘€ C 2026-06-14 16:12:59
9*e*t*.org βœ… D 2026-06-14 16:12:59
z*a*z*n.pl (WP 6.9.4) βœ… A 2026-06-14 15:45:14
i*f*a*t.com βœ… C 2026-06-14 15:43:50
t*e*t*e*b*u*g.com βœ… F 2026-06-14 14:53:19
p*-*r*b*s.g*.id (WP 7.0) βœ… C 2026-06-14 14:18:24
w*r*s*.au βœ… D 2026-06-14 14:08:40
m*c*r*p.events βœ… F 2026-06-14 14:08:40
c*r*o*a*e*u*e*.co βœ… F 2026-06-14 14:08:40
s*k*c*i.pl (WP 6.9.1) πŸ‘€ F 2026-06-14 14:07:15
l*z*r*w*w*b*z*z*.pl (WP 6.7.5) πŸ‘€ F 2026-06-14 14:07:15
a*l*r*u*p.de βœ… F 2026-06-14 13:23:11
r*s*h*f*r*n*u*a*e*.art (WP 7.0) πŸ‘€ D 2026-06-14 12:51:17
b*o*.r*t*e*g*r.com (WP 7.0) βœ… D 2026-06-14 12:46:44
s*o*r*o*g*a.t*c*o*a*p*s.cat βœ… D 2026-06-14 12:41:28
j*w*i*.net (WP 6.9.4) βœ… D 2026-06-14 12:34:21
e*i*o*a*s*u*a.c*m.br (WP 6.9.4) βœ… D 2026-06-14 12:15:37

Top 50 Plugins

Plugin Count
elementor 1,880,658
contact-form-7 1,852,966
elementor-pro 1,093,255
woocommerce 847,767
revslider 642,261
jetpack 480,894
js_composer 450,441
wp-rocket 350,306
gravityforms 321,186
essential-addons-for-elementor-lite 311,386
complianz-gdpr 271,300
cookie-law-info 243,772
instagram-feed 237,083
google-site-kit 230,694
sitepress-multilingual-cms 230,335
google-analytics-for-wordpress 221,574
elementskit-lite 220,384
header-footer-elementor 218,275
bluehost-wordpress-plugin 192,570
gutenberg 167,030
gutenberg-core 166,368
cookie-notice 161,977
litespeed-cache 142,610
the-events-calendar 139,091
wpforms-lite 133,812
gtranslate 133,474
astra-sites 122,839
popup-maker 120,636
tablepress 116,946
woocommerce-payments 115,949
coblocks 103,733
honeypot 102,316
astra-addon 98,832
duracelltomi-google-tag-manager 97,902
wp-smushit 97,300
all-in-one-seo-pack 96,802
layerslider 95,240
bb-plugin 93,233
megamenu 91,154
premium-addons-for-elementor 90,359
akismet 88,509
mailchimp-for-wp 86,901
cleantalk-spam-protect 86,210
woocommerce-gateway-stripe 85,840
ml-slider 85,220
borlabs-cookie 84,217
wp-pagenavi 83,516
fusion-builder 82,907
ewww-image-optimizer 82,068
smart-slider-3 81,436

Top 50 Themes

Theme Count
hello-elementor 643,040
Divi 532,735
astra 439,616
flatsome 150,016
generatepress 136,012
Avada 129,289
pub 114,620
twentytwentyfour 108,458
sydney 105,451
oceanwp 86,953
kadence 82,683
enfold 75,042
salient 69,072
twentyseventeen 59,028
h4 58,701
bb-theme 56,679
betheme 54,333
blocksy 53,460
cocoon-master 52,877
dt-the7 48,049
twentytwentyfive 46,497
neve 41,357
Avada-Child-Theme 39,053
woodmart 34,618
gox 34,505
bridge 34,095
twentytwentyone 33,437
lightning 32,541
twentytwenty 31,491
voxel 29,229
swell 29,197
Impreza 27,790
bricks 27,088
sinatra 25,996
twentytwentythree 25,058
Newspaper 25,015
kubio 22,372
twentytwentytwo 20,596
uncode 20,034
twentysixteen 19,388
epik-redesign 19,298
storefront 18,619
pro 18,260
Total 15,378
extendable 15,133
yith-wonder 14,146
hello-theme-child-master 14,022
yootheme 13,597
themify-ultra 13,558
hestia 13,535