WordPress Application Firewall with security hardening and HTTP security headers. Block attacks at the application layer before they reach your site.
7 rule categories covering SQL injection, cross-site scripting (XSS), local file inclusion (LFI), remote file inclusion (RFI), remote code execution (RCE), scanner detection, and comment spam.
Enable learning mode to detect and log threats without blocking any requests. Review what the WAF would have blocked before switching to active protection.
14-point hardening checklist including disable XML-RPC, hide WordPress version, block author enumeration, disable file editing, and restrict REST API access.
Configure HSTS, X-Frame-Options, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and Cross-Origin headers from one interface.
Detailed WAF event log showing every blocked or flagged request with severity level, matched rule, request URI, IP address, and timestamp.
Syncs blocked IPs with the VistoShield Linux daemon for server-level firewall blocking. Attacks blocked at the WordPress layer get escalated to nftables/iptables.
The Web Application Firewall operates in three modes: Disabled, Learning, and Active. Learning mode is the recommended starting point — it logs every rule match without blocking traffic, letting you identify false positives before enabling enforcement.
/etc/passwd, wp-config.php, and similar filessystem(), exec(), passthru()wp-comments-post.php without proper referrer headers?author=N)wp-config.php access.htaccess, readme.html)Security headers are the first line of defense against browser-based attacks. The Firewall plugin lets you configure all major security headers from a single settings page, with sensible defaults and the ability to customize each directive.
Headers are applied at the PHP level, so they work on any hosting environment without requiring access to server configuration files. Each header includes a description of what it does and recommended values for WordPress sites.
Get more with VistoShield Pro Bundle
| Feature | Free | Pro Bundle |
|---|---|---|
| WAF Rules | Standard | Premium rules + priority updates |
| Reporting | Basic stats | Weekly email + PDF export |
| Event History | 7 days | Up to 10 years |
| Support | Community | Priority 24h |
| Updates | Standard | Priority + Early Access |
Download for your platform:
Install Firewall & WAF from the WordPress plugin directory and enable protection in minutes.
Get Started Free