One Plugin. Complete Security.

14 Security Modules. One Plugin.

Install the VistoShield plugin from wordpress.org and enable the modules your site needs. Manage everything from the cloud dashboard. GDPR compliant.

EU GDPR compliant. EU-hosted cloud dashboard.

✅ Available on wordpress.org 🔒 GPL-2.0 Open-Source Plugin 🌎 GDPR compliant 🛠 Built on 25+ years of server security expertise (est. 2002) 🚀 14 modules, 30+ releases

Security Modules

14 security modules included in the VistoShield plugin

Prevention, detection, access control, and incident response — each module handles a specific security domain.

🔍

Security Scanner

File integrity monitoring against official WordPress checksums. Malware detection with 62+ signatures. Vulnerability scanning. Quarantine management.

  • Core file integrity checks
  • Malware pattern scanning
  • File quarantine & restore
  • Scheduled automated scans
Learn More →
🛡

Firewall & WAF

WordPress Application Firewall with 7 rule categories. Security hardening checklist. HTTP security headers management.

  • SQL injection & XSS blocking
  • 14-point hardening checklist
  • 7 HTTP security headers
  • Learning mode for testing
Learn More →
🤖

Bot Detector

User-Agent signature matching with 143+ patterns. Behavioral scoring engine. Cloudflare-style inline controls.

  • Block / Challenge / Allow / Monitor
  • Behavioral scoring (0-100)
  • rDNS verification
  • AI crawler management
Learn More →
🔒

Login Guard

Brute force protection with progressive lockouts. Two-factor authentication (TOTP). Honeypot for bots. Login logging.

  • Progressive lockout (5m → 15m → 24h)
  • TOTP two-factor authentication
  • Hidden honeypot field
  • CSV export of login attempts
Learn More →
📋

Activity Log

Comprehensive security event monitoring. Alert rules with email, Slack, and webhook notifications. GDPR-compliant.

  • Login, content, plugin tracking
  • Email / Slack / Webhook alerts
  • Configurable alert rules
  • GDPR export & erasure
Learn More →
🔑

Password Policy

Role-based password enforcement with expiration, breach detection via Have I Been Pwned, and password history to prevent reuse.

  • Per-role complexity rules
  • Password expiration & forced reset
  • HIBP breach detection (k-anonymity)
  • Password reuse prevention
Learn More →
🔌

API Security

REST API lockdown with key management, per-key rate limiting, endpoint whitelist/blacklist, and XML-RPC protection.

  • API key create / revoke / rotate
  • Per-key rate limiting
  • Endpoint whitelist & blacklist
  • User enumeration prevention
Learn More →
🛡️

Vulnerability Patcher

Detect plugin/theme vulnerabilities, apply virtual patches via WAF rules, and manage smart auto-updates with rollback.

  • Wordfence vulnerability DB sync
  • Virtual patching (WAF rules)
  • Smart auto-updates by severity
  • Pre-update backup & rollback
Learn More →
🚨

Incident Response

Automated incident detection from all VistoShield modules, guided response playbooks, isolation tools, and Slack/email alerts.

  • Cross-plugin incident detection
  • 5 pre-built response playbooks
  • Plugin isolation & maintenance mode
  • Email + Slack notifications
Learn More →
🌐

CDN Connector

Multi-CDN integration: Cloudflare, Bunny CDN, Fastly, CloudFront, KeyCDN. Edge-level blocking, cache purge, real IP restoration.

  • 5 CDN providers supported
  • Auto-sync blocked IPs to edge
  • Cache purge on security events
  • Real visitor IP restoration
Learn More →
📡

DNS Monitor

DNS health monitoring with change detection. Validate NS, SOA, MX, SPF, DKIM, DMARC, DNSSEC, CAA records, and SSL certificates.

  • 9 DNS record categories validated
  • SSL certificate expiry monitoring
  • Change detection & alerts
  • DNS health score dashboard
Learn More →
💓

Uptime Monitor

Monitor website availability, port status, and database connectivity. Smart false-positive prevention with SMS notifications via your own provider.

  • HTTP/HTTPS & TCP monitoring
  • Smart false-positive prevention
  • Response time graphs
  • SMS notifications (BYOP)
Learn More →
🛡️

Reputation Monitor

Track your domain across 12+ blacklist providers with real DNS-based checks. Get instant alerts when your domain gets listed or delisted.

  • 12+ blacklist providers
  • Real DNS-based checks
  • Status change alerts
  • Reputation history
Learn More →
📡

Live Traffic

Real-time HTTP request monitoring. Watch every request hitting your server — filter by humans, bots, and blocked traffic.

  • Real-time request feed
  • Bot vs human classification
  • User agent analysis
  • Geographic origin data
Learn More →
💻

Cloud Dashboard

Centralized security management across all your sites. Security scores, automated reporting, team management, and multi-site operations.

  • Multi-site overview
  • Automated PDF reports
  • Team management
  • Centralized configuration
Learn More →

All modules are included free in the VistoShield plugin. Pro adds the cloud dashboard with reporting, premium intelligence, and multi-site management. Max adds white-label for client portfolios.

Ready for more?

Start with a 14-day Pro trial. No credit card required.

Free

$0/forever

Up to 3 sites. 5 active + 5 monitor-only modules. 3-day data history.

Start Free

Pro

$89/year

Per site. Hourly scans. Email + Slack + webhook alerts.

Start Free Trial

Max

$169/year

Per site. 30-day history. SMS alerts. Partner API.

Start Free Trial
See full feature comparison on the Pricing page →

14-day free trial. Annual billing. Cancel anytime.

Why Are They Free?

We believe security should be accessible to everyone. The free plan includes 5 active modules, 5 monitor-only, and 4 locked — no nag screens, no nag screens, no "upgrade to unlock" for core features. The Pro and Max plans add management features, premium signatures, and extended history for professionals who need more.

Ready to Secure Your Site?

All 14 security modules are included free. Install the VistoShield plugin from wordpress.org or go Pro for the complete suite.