VaultShift hardens your WordPress site with a unified security dashboard, real-time threat monitoring, and tools that run locally on your server. Every core module is included and works out of the box after you activate your Free or Cloud key from myapps.wontonee.com.
Optional VaultShift Cloud services (signature sync, IP reputation, cloud spam scoring) stay off by default until you enable them under Settings.
wp-login.phpwp-contentEnable Cloud services under Settings when you want enhanced protection backed by VaultShift servers:
Remote calls are opt-in only — nothing is sent until you turn Cloud on.
VaultShift requires a cloud key to activate (Free or Cloud tier). Keys tie your site to myapps for plan validation. All local security features remain on your server; Cloud keys unlock optional remote services when you choose to enable them.
This plugin may connect to external services when configured or when you opt in.
Optional malware signature updates, IP reputation checks, VPN/proxy detection, and cloud-based spam scoring when Cloud services is enabled under Settings.
Sends visitor IP addresses, comment metadata/content (when cloud spam check is enabled), and site identification data when those features run.
Service: VaultShift Cloud API at https://myapps.wontonee.com/v1
Terms of use: https://wontonee.com/terms/
Privacy policy: https://wontonee.com/privacy/
Used when you activate a Free or Cloud key during setup or under Settings.
Sends your cloud key and site domain to register and validate your plan.
Service: https://myapps.wontonee.com/api/vaultshift
Terms of use: https://wontonee.com/terms/
Privacy policy: https://wontonee.com/privacy/
Used when you enter reCAPTCHA v3 site and secret keys under Login Protection.
Sends the visitor IP address and reCAPTCHA token to Google for verification when someone logs in or registers.
Terms of use: https://policies.google.com/terms
Privacy policy: https://policies.google.com/privacy
Used for country-based geo-blocking when you configure blocked country codes under Firewall.
Sends the visitor IP address when determining country code.
Terms of use: https://ipapi.co/terms/
Privacy policy: https://ipapi.co/privacy/
Used during malware scans to verify WordPress core file checksums against the official release.
Sends WordPress version and locale.
Terms of use: https://wordpress.org/about/gpl/
Privacy policy: https://wordpress.org/about/privacy/