🔌 VistoShield
WordPress Edition
One plugin with 12 specialized security modules. Each module handles a specific security domain — enable what you need from the dashboard for comprehensive WordPress protection. Connect to the cloud dashboard for centralized management.
Free on wordpress.org. GPL-2.0 license. All 12 modules included.
12 Modules. Complete WordPress Security.
Each module focuses on a specific security domain. Enable what you need from the dashboard for layered protection.
Security Scanner
File integrity monitoring against official WordPress checksums. Malware detection with 62+ pattern signatures. Vulnerability scanning for known CVEs. Quarantine management with one-click restore.
- Core file integrity checks against wordpress.org checksums
- Malware pattern scanning with 62+ detection signatures
- File quarantine with safe restore and permanent delete
- Scheduled automated scans with email notifications
Firewall & WAF
WordPress Application Firewall with 7 rule categories covering SQL injection, XSS, RFI, directory traversal, and more. 14-point security hardening checklist. HTTP security headers management for HSTS, CSP, and X-Frame-Options.
- SQL injection, XSS, RFI, and directory traversal blocking
- 14-point security hardening checklist with one-click fixes
- 7 HTTP security headers (HSTS, CSP, X-Frame-Options, etc.)
- Learning mode for safe testing before enforcement
Bot Detector
User-Agent signature matching with 143+ patterns covering scrapers, spam bots, AI crawlers, and vulnerability scanners. Behavioral scoring engine rates each visitor 0–100. rDNS verification lets legitimate search engine bots through.
- Block / Challenge / Allow / Monitor per-bot actions
- Behavioral scoring engine (0–100 threat rating)
- rDNS verification for Google, Bing, and other good bots
- AI crawler management (GPTBot, CCBot, ClaudeBot, etc.)
Login Guard
Brute force protection with progressive lockouts that escalate from 5 minutes to 24 hours. TOTP two-factor authentication for all user roles. Hidden honeypot field catches automated bots. Full login attempt logging with CSV export.
- Progressive lockout intervals (5m → 15m → 1h → 24h)
- TOTP two-factor authentication with QR code setup
- Hidden honeypot field for automated bot detection
- Login attempt logging with search, filter, and CSV export
Activity Log
Comprehensive security event monitoring that tracks logins, content changes, plugin/theme activations, user role modifications, and settings changes. Alert rules with email, Slack, and webhook notifications. GDPR-compliant data export and erasure.
- Login, content, plugin, theme, and user tracking
- Alert rules with email, Slack, and webhook notifications
- Configurable retention and automatic log cleanup
- GDPR-compliant data export and personal data erasure
Password Policy
Role-based password enforcement with configurable complexity rules per user role. Password expiration with grace periods. Breach detection via Have I Been Pwned using privacy-safe k-anonymity API. Password history prevents reuse of recent passwords.
- Per-role minimum length and complexity
- Configurable password expiration
- HIBP breach detection (k-anonymity)
- Password reuse prevention
- Compliance dashboard
API Security
REST API lockdown with key management, per-key rate limiting, and endpoint control. Prevent user enumeration via author queries. Disable XML-RPC. Manage CORS origins. Full API request logging with analytics.
- API key create / revoke / rotate
- Per-key rate limiting with 429 responses
- Endpoint whitelist and blacklist
- User enumeration prevention
- CORS origin management
Vulnerability Patcher
Detect plugin and theme vulnerabilities by syncing against public vulnerability databases. Apply virtual patches via WAF rules before official fixes are released. Smart auto-updates with pre-update backups and one-click rollback.
- Vulnerability database sync
- Virtual patching via WAF rules
- Smart auto-updates by severity
- Pre-update backup and rollback
- Email notifications by severity
Incident Response
Automated incident detection from all VistoShield plugins with guided response playbooks. Isolate compromised plugins, enable maintenance mode, block IPs, and notify stakeholders via email or Slack. Generate post-incident reports.
- Cross-plugin incident detection
- 5 pre-built response playbooks
- Plugin isolation and maintenance mode
- Email and Slack notifications
- Incident timeline and reporting
DNS Monitor
DNS health monitoring with change detection. Validate NS, SOA, MX, SPF, DKIM, DMARC, DNSSEC, CAA records, and SSL certificates. Health score dashboard with automated scheduled checks and change alerts.
- 9 DNS record categories validated
- SSL certificate expiry monitoring
- Change detection and email alerts
- DNS health score dashboard
Unified Dashboard (Pro)
Pro unlocks the full cloud dashboard for managing all 12 modules across your sites.
Central Security Overview
One dashboard shows scanner results, firewall blocks, bot activity, login attempts, and security events across all 12 modules — everything is unified.
Multi-Site Management
Manage security across multiple WordPress sites from a single interface. Push configurations, view aggregated reports, and respond to threats across your entire network.
Advanced Reporting
Weekly and monthly security reports delivered to your inbox. Trend analysis, attack pattern detection, and actionable recommendations to strengthen your security posture.
How We Compare
See how VistoShield WordPress Edition stacks up against other WordPress security solutions.
| Feature | VistoShield | Wordfence | Sucuri | iThemes |
|---|---|---|---|---|
| Open source | ✅ GPL-2.0 | Partial | ❌ | ❌ |
| Cloud dashboard | ✅ EU-hosted dashboard for centralized management | Required | Required (CDN) | Required |
| Malware scanning | ✅ Local (62+ sigs) | ✅ Cloud | ✅ Cloud | ✅ Cloud |
| WAF / Firewall | ✅ Application-level | ✅ Application-level | ✅ CDN-level | ✅ Basic |
| Bot detection | ✅ 143+ signatures | Basic | Basic | ❌ |
| 2FA authentication | ✅ TOTP built-in | ✅ Premium | ❌ | ✅ Premium |
| Activity logging | ✅ Full (dedicated plugin) | ✅ Premium | ✅ Basic | ✅ Basic |
| Server-level firewall | ✅ Via Server Edition | ❌ | ❌ | ❌ |
| Modular architecture | ✅ 12 independent modules | ❌ Monolithic | ❌ Monolithic | ❌ Monolithic |
| GDPR compliant | ✅ All data local | ❌ Cloud required | ❌ Cloud required | ❌ Cloud required |
| Free tier | ✅ Full features | Limited | Limited | Limited |
WordPress Pricing
All modules are free with full functionality. Pro adds management and support.
Free
- All 12 modules with full functionality
- 7-day event history
- 143 bot signatures
- Community support (GitHub)
- Available on wordpress.org
Pro
- All 12 modules upgraded to Pro
- 10 sites included (€7.90/site)
- Cloud dashboard + centralized management
- 500+ premium bot signatures
- PDF export + weekly reports
- Priority 24h support
- 14-day free trial
Agency
- 25 sites included (€7.96/site)
- Everything in Pro
- White-label branding
- Centralized multi-site management
- Priority support
Annual billing. Cancel anytime. Your settings and data are never affected by license changes.
🇪🇺 GDPR Compliant — Cloud dashboard EU-hosted (Hetzner, Germany). Local data stays in your WordPress database.
Install from WordPress
Available on the official WordPress plugin directory.
From Plugin Directory
In your WordPress admin, go to:
Plugins → Add New → Search "VistoShield"
Search for "VistoShield" and install the plugin. All 12 security modules are included and can be enabled from the dashboard.
Manual Install
Download the ZIP from our modules page or from wordpress.org.
Upload via Plugins → Add New → Upload Plugin in your WordPress admin.