Changelog

Release history for VistoShield — Linux daemon, WordPress plugins, and control panel modules.

v1.0.0 — 2026-03-28

Initial public release.

Linux Daemon

  • Dual firewall backend support (nftables and iptables) with automatic detection
  • Full IPv4 and IPv6 dual-stack protection
  • Per-IP rate limiting with configurable thresholds and burst allowance
  • Login Failure Detection (LFD) for SSH, FTP, IMAP, POP3, SMTP, DirectAdmin, cPanel, Webmin, and ModSecurity
  • Bot detection with User-Agent signature matching (143+ patterns) and rDNS verification
  • Connection tracking with per-IP limits
  • SYN flood and per-port flood (PORTFLOOD) protection
  • Country-based blocking via GeoIP
  • Allow and deny list management with CIDR support
  • Testing mode with automatic block clearing for safe deployment
  • CLI management tool with full command set
  • Email alert notifications
  • Automatic log rotation

WordPress Plugins

  • Security Scanner — Core integrity checks, malware scanning, vulnerability detection, quarantine, and baseline snapshots
  • Firewall & WAF — 7 rule categories (SQLi, XSS, LFI, RFI, RCE, scanner detection, comment spam), security hardening checklist, HTTP security headers, learning and active modes
  • Bot Detector — 143+ signatures, behavioral scoring engine (0–100), rDNS verification, inline action switching (block/challenge/monitor/allow)
  • Login Guard — Brute force protection with progressive lockouts, TOTP two-factor authentication, hidden honeypot, login attempt logging with CSV export
  • Activity Log — Authentication, content, plugin/theme, settings, and system event tracking. Alert rules with email, Slack, and webhook channels. GDPR-compliant with configurable retention.

Control Panel Plugins

  • DirectAdmin — Admin and user-level plugin with dashboard, configuration editor, blocked IP management, allow/deny lists, bot signatures, log viewer, exec wrapper, and DirectAdmin hooks
  • Webmin — Full module with config editor (comment-preserving), daemon control, blocked IP management, allow/deny lists, bot signature management, and color-coded log viewer

Installation

  • One-line installer with OS and panel auto-detection
  • Support for Ubuntu 22.04/24.04, Debian 12, AlmaLinux 8/9, CentOS Stream 9
  • Automatic web server configuration (Nginx and Apache)
  • Dry-run mode for previewing changes before installation