Cybexsoft Shield protects the login form, watches your files and settings, and shows you what it found in one dashboard.
Login protection
[cybex_shield_captcha] shortcodeSessions & passwords
Site scanning
Hardening, server & SSL
Activity log & overview
Privacy
Recovery
If a protection ever locks you out:
define( 'CYBEX_SHIELD_SAFE_MODE', true ); to wp-config.php. Every protection that can stand between you and your site is suspended; logging and the settings screens keep working so you can fix the cause.wp shield disable <module>, wp shield unblock <ip>, wp shield allow <ip>.WP-CLI
wp shield status — version, licence, safe mode and every module’s statewp shield modules, wp shield enable <module>, wp shield disable <module>wp shield unblock <ip>, wp shield allow <ip> [--label=<label>]wp shield logout <user>, wp shield logout --allwp shield scanwp shield settings get|set|reset|export|importwp shield license status|activate|deactivate|refreshwp shield login-url show|reset|recoveryPro (sold separately, delivered as an add-on plugin)
Two-factor authentication with passkeys, a firewall that can start before WordPress loads, rate limiting and crawler control, geo-blocking, server rules for Apache and nginx, a malware scanner, and governance tools: a tamper-evident audit trail of Shield’s settings, access levels and two-administrator approval, alerts to Slack, Teams, PagerDuty, syslog and webhooks, PDF reports, configuration profiles and a compliance map. The free plugin never needs Pro, and nothing in it is disabled or time-limited. See https://cybexsoft.com/products/cybexsoft-shield for plans.
Cybexsoft Shield contacts the services below only for the features that need them. Every one is optional; the default CAPTCHA is Shield’s own built-in challenge, which contacts nobody, and country lookups use a database on your own server. No visitor data is sent anywhere unless you switch on one of these features.
Used only if you choose “Google reCAPTCHA” as the CAPTCHA provider under Shield CAPTCHA and enter your own keys.
The forms you protect then load a script from google.com, and Google receives each visitor’s IP address, browser and device information, and their interaction with the challenge — including visitors who never submit the form. When a form is submitted, Shield sends the challenge token, your secret key and the visitor’s IP address to Google to check the answer.
Service provided by Google: terms of service, privacy policy.
Used only if you choose “Cloudflare Turnstile” as the CAPTCHA provider under Shield CAPTCHA and enter your own keys.
The forms you protect then load a script from challenges.cloudflare.com, and Cloudflare receives each visitor’s IP address, browser and device information, and their interaction with the challenge. When a form is submitted, Shield sends the challenge token, your secret key and the visitor’s IP address to Cloudflare to check the answer.
Service provided by Cloudflare: terms of service, privacy policy.
Used only if password rules are switched on under Shield Sessions & passwords with “Not found in known data breaches” selected.
When a password is set or changed, and at most once a month when someone signs in, Shield hashes the password with SHA-1 on your server and sends only the first five characters of that hash to https://api.pwnedpasswords.com. The password itself never leaves your server, and the answer is compared locally. If the service cannot be reached, the check is skipped.
Service provided by Have I Been Pwned: acceptable use, privacy policy.
Used only if you enter a Google Safe Browsing API key under Shield Settings.
Once a day, Shield sends your site’s home address and your API key to https://safebrowsing.googleapis.com to ask whether Google is warning visitors away from the site. No visitor data is sent.
Service provided by Google: terms of service, privacy policy.
Used by the file integrity scan and Plugin & theme health, which are on by default.
Shield asks api.wordpress.org and downloads.wordpress.org for the official checksums of your WordPress version and of plugins hosted on WordPress.org, and for public information about those plugins (whether they are still listed, when they were last updated). When you choose to restore a file, its official copy is downloaded from core.svn.wordpress.org or plugins.svn.wordpress.org. Each request names only the WordPress version, locale, plugin slug and version concerned.
Service provided by WordPress.org: privacy policy.
Used only if you have bought the Pro add-on and enter a licence key under Shield Licence.
Your licence key and your site’s home address are sent to https://cybexsoft.com/api/licenses when you activate or deactivate the key, and once a day afterwards to confirm it is still valid. Nothing is sent while no licence key is stored, which is the case on every free install.
Service provided by Cybexsoft: terms of service, privacy policy.
The plugin is distributed under the GNU General Public License, version 3 or later. Version 3 rather than 2, because it includes code under the Apache License 2.0, which is compatible with GPLv3 but not with GPLv2.
includes/class-cybex-shield-mmdb-reader.php are derived from it, in modified form. No MaxMind database is bundled; you supply your own, and it stays subject to MaxMind’s terms. MaxMind and GeoLite are trademarks of MaxMind, Inc.; this plugin is not affiliated with or endorsed by them.Full notices are in the NOTICE file, and the licence itself in LICENSE.txt.