🛡

Download VistoShield

One lightweight agent. One EU-hosted cloud dashboard. Choose your platform — or install over SSH with a single command.

⬇ WordPress Plugin ⬇ Joomla 3/4/5 Package

Free — ZIP files — WordPress plugin 2.1.3, Joomla agent 2.2.0

Requirements

WordPress 4.7 or higher
Joomla 3.9, 4.x or 5.x
PHP 7.1 or higher
Hosting Any standard shared, VPS, or managed hosting
Browser Any modern browser for the cloud dashboard

Install on WordPress

  1. Download the ZIP file
    Click the WordPress Plugin button above to get the latest vistoshield.zip file.
  2. Upload to WordPress
    In your WordPress admin, go to Plugins → Add New → Upload Plugin. Choose the downloaded ZIP file and click Install Now.
  3. Activate the plugin
    After installation completes, click Activate Plugin. VistoShield will appear in your admin sidebar.
  4. Run the setup wizard
    On first activation, the setup wizard connects you to the cloud dashboard — paste your Site Key (from the dashboard, Sites → Add Site), or sign in with your account.

Install on Joomla 3, 4 or 5

  1. Download the Joomla package
    Click the Joomla 3/4/5 Package button above to get vistoshield-joomla.zip.
  2. Install the extension
    In the Joomla administrator, go to System → Install → Extensions and upload the ZIP.
  3. Enable and connect
    Go to System → Manage → Plugins, open System - VistoShield, paste your Site Key into the field, set the plugin to Enabled, and save. The agent connects on the next page load.
Joomla protection: the agent adds a WAF that virtual-patches the recurring unauthenticated file-upload exploits in EOL Joomla and paid frameworks (JCE, SP Page Builder, Astroid, Helix3), plus self-healing PHP-execution hardening, rogue super-admin detection, and file-integrity monitoring. Logged-in administrators are never blocked.

Install over SSH — no admin login needed

The universal CLI installer works for both WordPress and Joomla. It auto-detects the platform, installs and activates the agent, and connects it with your Site Key — ideal for bulk installs or sites you manage over SSH. Run it from the site's document root:

curl -s https://api.vistoshield.com/api/plugin/installer -o vistoshield-install.php
php vistoshield-install.php --key=YOUR_SITE_KEY
rm vistoshield-install.php

If the document root isn't the current directory, add --path=/full/path/to/site. The installer validates your Site Key against the cloud before touching any files.

Tip: Don't have a VistoShield account yet? Create a free account first — no credit card required — then add your site to get its Site Key.

Cloud Dashboard

Once installed, manage all your WordPress and Joomla sites from a single cloud dashboard. Monitor security events, configure modules, and receive real-time alerts — all from one place.

Open Cloud Dashboard →

  • Multi-site management — monitor all connected sites from one dashboard
  • Real-time security event sync
  • Centralized module configuration
  • Email and Slack alert notifications
  • EU-hosted on ISO 27001 certified datacenters in Germany

What's Included (WordPress)

On WordPress, VistoShield bundles 14 security modules into a single lightweight plugin:

✓ Firewall & WAF
✓ Security Scanner
✓ Login Guard
✓ Bot Detector
✓ Live Traffic
✓ Activity Log
✓ Password Policy
✓ API Security
✓ Vulnerability Patcher
✓ Incident Response
✓ CDN Connector
✓ DNS Monitor
✓ Uptime Monitor
✓ Reputation Monitor

Each module works independently — enable only what you need. On Joomla, the agent focuses on the platform's highest-risk surface: WAF virtual patching, self-healing folder hardening, rogue-admin detection, file-integrity monitoring, and configuration audits. The free plan covers up to 3 sites with core features. Compare plans →

Install Directly from WordPress

Alternative method: You can also install VistoShield without downloading a ZIP file.
  1. In your WordPress admin, go to Plugins → Add New
  2. Search for "VistoShield"
  3. Click Install Now and then Activate
  4. Follow the setup wizard to connect to the cloud dashboard

Next Steps