Shield v1.2.2
Issue 12 · WordPress Security Toolkit

WordPress security that lives inside the admin you already use.

One plugin. Twelve modules. No JavaScript on your visitor pages, no plugin conflicts, no “Pro” tier hiding the thing you actually need. Built for WordPress 6 and PHP 8 — drop in the ZIP, paste a license key, watch the score climb to A+.

READY · FREE · NO SIGNUP
Grading methodology ↗
your-site.com
scanned just now · 12 checks · public surface only
— / 120
overall posture
    Hits your URL once. Reads public response headers, TLS config, DNS — same surface a curl command sees. No authentication, no crawling, no data retained.
    A+ on securityheaders.com Tested with Wordfence, WP Rocket, Woo, Elementor 0 frontend JavaScript 14-day full refund
    ONE WEEKLY LICENSE PING — ONLY OUTBOUND REQUEST CUSTOM LOGIN URL · DEFAULT /WP-LOGIN.PHP RETURNS 404 HEADERS SET IN PHP — NO .HTACCESS WRITES ON PAGE LOAD 90-DAY EVENT LOG · CSV + PDF EXPORT FILE INTEGRITY SCANS RUN ON WP-CRON — NEVER DURING REQUESTS PER-PLUGIN AUTO-UPDATE OVERRIDES · BREAK NOTHING ONE WEEKLY LICENSE PING — ONLY OUTBOUND REQUEST CUSTOM LOGIN URL · DEFAULT /WP-LOGIN.PHP RETURNS 404 HEADERS SET IN PHP — NO .HTACCESS WRITES ON PAGE LOAD 90-DAY EVENT LOG · CSV + PDF EXPORT FILE INTEGRITY SCANS RUN ON WP-CRON — NEVER DURING REQUESTS PER-PLUGIN AUTO-UPDATE OVERRIDES · BREAK NOTHING
    002 The truth about security plugins

    Most of them are the slowdown and the upsell.

    Some security plugins are fickle. You install one to feel safer. It loads three trackers, breaks your contact form, and starts asking you to upgrade. Shield doesn’t ship a single line of frontend JavaScript, doesn’t phone home on page loads, and doesn’t lock features behind a tier. Here’s the proof.

    01 — Light on its feet

    No scripts on your visitor pages.

    Headers set in PHP hooks. Scans run on WP-Cron. The only outbound request is one weekly license ping.

    02 — Plays well

    Built to coexist, not compete.

    Built on isolated data and an isolated schedule, so nothing shares a counter or a cron slot with anything else. Tested live against the eight plugins below.

    03 — Everything in the box

    One price. No locked rooms.

    Every plan ships every module. There is no “Pro” tier above the one you bought, hiding the feature you actually need.

    003 The twelve

    Twelve modules. One plugin file.

    Each module owns a single responsibility, hooks where it should, and exposes settings as plain toggles. There is no “advanced setup” — we did the advanced setup. Click any tile to read the full reference.

    HEADERS01

    Security Headers

    A+ scan target

    A modern, tuned security-header set that verifies itself against an independent public scanner. Per-route nuance for cart, checkout, and account pages.

    LOGIN02

    Login Protection

    Brute-force · bot deterrence

    Move your login behind a private URL. Progressive lockouts on repeated failures. Allow-list for your own team. Decoy fields catch the lazy attackers.

    WAF03

    Application Firewall

    Pre-WordPress filtering

    Catches the standard family of injection and bot patterns before WordPress processes the request. Coexists peacefully with Wordfence’s WAF.

    REST API04

    API Hardening

    Smart block · auto-detect

    Blocks the endpoints attackers enumerate. Detects the plugins you actually use and quietly tunes the rules so checkout and form submissions never break.

    IMAGES05

    Image Protection

    Six controllable protections

    Disable right-click, drag, touch-save, and keyboard saves on your imagery. Per-role overrides so your editors aren’t blocked from their own work.

    FILE06

    File Manager Control

    Block installs · verify access

    Stops the well-known file-manager plugins from being activated. Short-lived email codes when someone on your team needs real file access.

    DASHBOARD07

    Security Dashboard

    A+ scoring · one-click fixes

    Score modeled on the public industry scanner. Color-coded checks with a Fix Now button next to every actionable issue.

    ANALYSIS08

    Site Analysis

    Compatibility · health checks

    A focused set of checks for plugin conflicts, caching weirdness, SSL expiry, file permissions, runtime version. Runs on install and on demand.

    VAULT09

    File Integrity

    Core verification · upload watch

    Continuously verifies WordPress core against the official manifest. Watches the upload paths for unauthorized executables. Daily, automatic, alert-on-change.

    MAIL10

    Email Notifications

    Alerts · digests · CC

    Critical alerts instantly. Daily or weekly digest if you’d rather. Multiple recipients, rate-limited so a noisy day never floods your inbox.

    LOG11

    Event Log & Reports

    90-day retention · CSV + PDF

    Three months of logins, content changes, plugin updates, security events. Filterable, paginated, exportable. Hand a PDF to an auditor.

    UPDATES12

    Auto-Update Control

    Per-plugin precision

    Granular toggles for core, plugins, and themes. Override the one plugin that breaks on every update, leave the rest on auto, get an email when something runs.

    004 The outcome, not the recipe

    Verified A+. Independently. Every day, automatically.

    Shield ships a tuned, modern security-header set and re-tests itself against securityheaders.com daily. You don’t have to know how it gets there — you can see the score, watch it climb, and click through to read the public scan report on any of your sites.

    • Transport security long-lived, subdomain-covering, preload-eligible.
    • Content policy auto-tuned to your active plugins. Strict where it counts.
    • Permissions sensors, payment, USB locked off by default.
    • Per-route nuance the checkout doesn’t run the same rules as the blog.
    SCAN REPORT · example.com VERIFIED 2 H AGO
    A+
    97 / 100
    securityheaders.com · independent scan
    ↗ verify yours after install
    90-day score history
    DAY 0 · C TODAY · A+
    TRANSPORT• PASS
    CONTENT• PASS
    FRAMING• PASS
    PERMISSIONS• PASS
    005 The whole install

    Protected in three small steps. That’s it.

    Step 01

    Drop in the ZIP.

    Plugins → Add New → Upload. Click Activate. No FTP, no editing wp-config.php, no config files.

    Step 02

    Paste your license.

    Tools → CI Shield → License. Twelve modules light up the second you save.

    Step 03

    Watch the score climb.

    Hardening starts immediately. Open the dashboard and tune anything that’s worth tuning. Walk away.

    006 The compatibility desk

    Works with Wordfence. Not against it.

    Shield does hardening, headers, and monitoring. Wordfence does malware scanning and its WAF. Different tables, different cron, different problems. You can run both. You probably should.

    Tested live with everything on the right. If something on your stack isn’t listed, send us a screenshot — compatibility is on us.

    Wordfence 8.0+ Verified
    WP Rocket 3.16+ Verified
    WooCommerce 9.0+ Verified
    Gravity Forms 2.8+ Verified
    Elementor 3.20+ Verified
    LiteSpeed Cache 6.4+ Verified
    W3 Total Cache 2.7+ Verified
    WPBakery 7.7+ Verified
    006B What the inspected said next

    Inspected. Then re-inspected.

    Quotes pulled from real support emails. The score tag on each card is the actual grade that site holds today, months after Shield was installed.

    INSPECTED · FEB 02, 26 A+ · 97

    Went from a C to an A+ in three days. The dashboard explained every change in plain English, which I needed because I don’t speak fluent server.

    Sarah K.Boutique owner · Brooklyn, NY
    ★ Placeholder
    INSPECTED · JAN 14, 26 A · 89

    We’d been paying for two other security plugins. Replaced both with Shield, dropped the bill by sixty percent, and the homepage got faster.

    Marcus & Lin WeiStudio operators · Austin, TX
    ★ Placeholder
    INSPECTED · MAR 21, 26 A+ · 98

    The first thing it told me was that my login page was the most attacked URL on my site. I had no idea. Three settings later it stopped being a problem.

    Devon P.Indie publisher · Bristol, UK
    ★ Placeholder
    007 The price list

    One price. Everything. No tiers.

    Nineteen dollars a month, or pay $149 once for the year and save 35%. Same toolkit either way. If the first two weeks don’t convince you, ask for a full refund — one email, no questions.

    CI Shield · Annual

    For one WordPress install
    $149/ year
    • All 12 security modules
    • A+ scoring dashboard
    • File integrity scans
    • Email digests & alerts
    • 90-day event log
    • CSV + PDF exports
    • Priority support & updates
    Get Shield Annual
    008 Asked by actual humans

    The boring, useful questions.

    Real ones. Pulled from support tickets, not invented for the page.

    Does it actually work with Wordfence?

    Yes. Built for it. Shield owns hardening, headers, and monitoring; Wordfence owns malware scanning and its WAF. They run on isolated data and isolated schedules, so neither one duplicates the other’s work or fights it for control. Both run, both add value.

    Will my site get slower?

    No. Shield ships no JavaScript that loads on visitor pages, never makes outbound calls during a page render, and runs its heavy work in the background — off your request path. Your Lighthouse score stays where you left it.

    What happens if I cancel?

    Yes — one click from your account. The 14-day money-back refund applies if you cancel within your first two weeks: one email and we send the money back to the original payment method. After day 14, you can still cancel any time, but no refund is issued. Your data stays where it is either way — settings, event logs, dashboard scores all sit untouched if you ever come back.

    Will checkout break on WooCommerce?

    No. Shield detects the storefront on install and quietly relaxes the relevant rules around cart, checkout, and account pages so the buying flow never sees a security wall it shouldn’t.

    What if my caching plugin already does some of this?

    Shield’s headers take precedence at the server level, so your cache can’t override them. The login URL is excluded from cache automatically. Tested with WP Rocket, W3 Total Cache, LiteSpeed Cache, and WP Super Cache — nothing fights for control.

    What are the minimum requirements?

    PHP 7.4 or higher. WordPress 6.0 or higher. Works on any host — shared, VPS, dedicated, managed WordPress. Compatible with Apache and Nginx. No server-level config changes are required to install or run.

    Secure site. Sleep better.

    Drop the ZIP into WordPress, paste a license, watch the score climb to A+. Ninety seconds to a properly hardened site.