Simple, Transparent Pricing
Start with a 14-day Pro trial. No credit card required. Downgrade to Free anytime.
Save 25% with annual billing — $7.42/mo vs $9.90/mo
Compare annual pricing per site
Free
For personal sites and testing
free forever
No credit card required
- 5 modules active, 5 monitor-only
- 3-day data history
- On-demand scans
- Email security alerts
- 143 bot signatures (weekly)
- Weekly security report
- Up to 3 sites
- Owner only
- Community support
No credit card required
Pro
Best for freelancers and growing portfolios
per site / year
$7.42/mo per site · or $9.90/mo monthly
- All 14 modules unlocked
- 14-day data history
- Hourly scheduled scans
- Email + Slack + webhook alerts
- 500+ bot signatures (daily)
- PDF reports + weekly emails
- Up to 100 sites
- Team members (up to 5)
- Priority support
No credit card required
Max
For agencies & hosting providers
per site / year
$14.08/mo per site · or $18.90/mo monthly
- Everything in Pro, plus:
- 30-day data history
- White-label branding
- Email + Slack + webhook + SMS
- Branded PDF reports
- Partner API + reseller tools
- Up to 250 sites
- Team members (up to 20)
- Dedicated support
No credit card required
Backed by 25+ years of hosting security expertise • Vistoweb, est. 2002 • EU-hosted • GDPR compliant
Start with 1 site. Add more anytime. Volume discounts apply automatically for 5, 10, and 25-site bundles.
EU-hosted cloud dashboard. Data encrypted in transit and at rest. GDPR compliant.
Annual and monthly billing available. All prices exclude VAT where applicable.
David Morales
Security Consultant
“I've audited over 50 WordPress security setups. VistoShield is the only modular solution that lets me recommend exactly what each client needs.”
Pro • Security consulting
Elena Kowalski
Operations Director, FitnessPro Online
“We have 4,200 active members. The Activity Log tracks every login, every role change, every content modification. The accountability alone is worth the Pro upgrade.”
Pro • Membership site
Full Feature Comparison
Every feature across all three plans — no hidden limits, no surprises.
| Feature | Free | Pro | Max |
|---|---|---|---|
| General | |||
| Security modules | 5 active / 5 monitor-only / 4 locked | ✓ All 14 | ✓ All 14 |
| WordPress.org availability | ✓ | ✓ | ✓ |
| Open source (GPLv2) | ✓ | ✓ | ✓ |
| Setup wizard | ✓ | ✓ | ✓ |
| Cloud Dashboard | Basic (3 days) | Full (14 days) | Full + White-label (30 days) |
| Live Traffic View | Last 500 requests | Last 10,000 requests | Last 50,000 requests |
| Sites covered | Up to 3 sites | Up to 100 sites | Up to 250 sites |
| Team members | ✗ | Up to 5 | Up to 20 |
| Security Scanner | |||
| File integrity monitoring | ✓ | ✓ | ✓ |
| Malware detection (62+ patterns) | ✓ | ✓ | ✓ |
| Vulnerability scanning | ✓ | ✓ | ✓ |
| Quarantine management | ✓ | ✓ | ✓ |
| Scan scheduling | Manual only | Hourly | Hourly |
| Scan history | 3 days | 14 days | 30 days |
| Scheduled PDF scan reports | ✗ | ✓ Weekly | ✓ Branded |
| Firewall & WAF | |||
| WAF rules | 5 core categories | All 7 + custom rules | All 7 + custom rules |
| Security hardening (14-point) | ✓ | ✓ | ✓ |
| HTTP security headers | ✓ | ✓ | ✓ |
| Learning mode | ✓ | ✓ | ✓ |
| WAF event history | 3 days | 14 days | 30 days |
| PDF security reports | ✗ | ✓ | ✓ Branded |
| Rate limiting | Standard (300 req/min) | Unlimited + custom rules | Unlimited + custom rules |
| Bot Detector | |||
| Bot signatures | 143 (weekly) | 500+ (daily updates) | 500+ (daily updates) |
| Behavioral scoring (0–100) | ✓ | ✓ | ✓ |
| rDNS verification | ✓ | ✓ | ✓ |
| Challenge pages | ✓ | ✓ | ✓ |
| Bot analytics history | 3 days | 14 days | 30 days |
| PDF bot reports | ✗ | ✓ | ✓ Branded |
| Robots.txt editor | ✓ | ✓ | ✓ |
| Access Control (Login Guard + Password Policy) | |||
| Progressive lockouts | ✓ | ✓ | ✓ |
| TOTP two-factor auth | ✓ | ✓ | ✓ |
| Honeypot CAPTCHA | ✓ | ✓ | ✓ |
| Password roles | Admin & Editor | All roles + custom | All roles + custom |
| Password expiration | ✓ | ✓ | ✓ |
| HIBP breach detection | ✓ | ✓ | ✓ |
| Password history | ✓ | ✓ | ✓ |
| Login/password history | 3 days | 14 days | 30 days |
| PDF compliance reports | ✗ | ✓ | ✓ Branded |
| Activity Log | |||
| Event tracking (all types) | ✓ | ✓ | ✓ |
| Alerts | Email only | Email + Slack + webhook | Email + Slack + webhook + SMS |
| GDPR export & erasure | ✓ | ✓ | ✓ |
| Event history | 3 days | 14 days | 30 days |
| PDF audit reports | ✗ | ✓ | ✓ Branded |
| API Security | |||
| API keys | ✗ PRO | Unlimited + rotation | Unlimited + rotation |
| Rate limiting | ✗ PRO | ✓ Advanced | ✓ Advanced |
| Endpoint control | ✗ PRO | ✓ | ✓ |
| XML-RPC protection | ✗ PRO | ✓ | ✓ |
| CORS management | ✗ PRO | ✓ | ✓ |
| API request history | ✗ PRO | 14 days | 30 days |
| PDF API reports | ✗ | ✓ | ✓ Branded |
| Vulnerability Patcher | |||
| Vulnerability scanning | ✓ | ✓ | ✓ |
| Virtual patching (WAF rules) | ✓ | ✓ | ✓ |
| Auto-updates | Weekly | Daily + smart scheduling | Hourly + smart scheduling |
| Vulnerability DB sync | Weekly | Daily | Hourly |
| Pre-update backup & rollback | ✓ | ✓ | ✓ |
| Vulnerability history | 3 days | 14 days | 30 days |
| PDF vulnerability reports | ✗ | ✓ | ✓ Branded |
| Incident Response | |||
| Incident detection | ✓ | ✓ | ✓ |
| Pre-built playbooks | 3 built-in | 5 + custom playbooks | 5 + custom playbooks |
| Plugin isolation | ✓ | ✓ | ✓ |
| Maintenance mode | ✓ | ✓ | ✓ |
| Notifications | Email only | Email + Slack + webhook | Email + Slack + webhook + SMS |
| Incident history | 3 days | 14 days | 30 days |
| PDF incident reports | ✗ | ✓ | ✓ Branded |
| Dashboard & Reporting | |||
| Plugin cards overview | ✓ | ✓ | ✓ |
| Security score | ✓ | ✓ | ✓ |
| Security timeline (30-day) | ✗ | ✓ | ✓ |
| Critical events feed | ✗ | ✓ | ✓ |
| Weekly email summary | ✗ | ✓ | ✓ |
| PDF export | ✗ | ✓ | ✓ Branded |
| Integrations | |||
| CDN providers | 1 (Cloudflare) | All 5 providers | All 5 providers |
| Under Attack mode control | ✓ | ✓ | ✓ |
| Real IP restoration | ✓ | ✓ | ✓ |
| DNS Monitor | |||
| DNS health checks (9 categories) | ✓ | ✓ | ✓ |
| SSL certificate monitoring | ✓ | ✓ | ✓ |
| Check history | 3 days | 14 days | 30 days |
| Automated scheduled checks | ✗ | ✓ Daily | ✓ Hourly |
| Change detection & alerts | ✗ | ✓ | ✓ |
| PDF DNS health reports | ✗ | ✓ | ✓ Branded |
| Uptime Monitor | |||
| HTTP/HTTPS monitoring | 1 check (view only) | ✓ 10 checks | ✓ 50 checks |
| TCP / Port monitoring | ✗ | ✓ | ✓ |
| Check interval | 5 min | 2 min | 1 min |
| Smart false-positive prevention | ✓ | ✓ | ✓ |
| Incident history | 3 days | 14 days | 30 days |
| SMS notifications (BYOP) | ✗ | ✓ | ✓ |
| Response time graphs | ✗ | ✓ | ✓ |
| Reputation Monitor | |||
| Blacklist providers monitored | View only | ✓ 12+ providers | ✓ 12+ providers |
| Real DNS-based checks | ✗ | ✓ 5 providers | ✓ 5 providers |
| Check frequency | Daily | Every 6 hours | Every 6 hours |
| Status change alerts | Email only | Email + Slack | Email + Slack + SMS |
| Reputation history | 3 days | 14 days | 30 days |
| Max Features | |||
| White-label branding | ✗ | ✗ | ✓ |
| Custom brand name / logo / color | ✗ | ✗ | ✓ |
| Multi-site management | ✓ Up to 3 | ✓ Up to 100 | ✓ Up to 250 |
| Client-facing branded reports | ✗ | ✗ | ✓ |
| Centralized configuration | ✗ | ✗ | ✓ |
| Support | |||
| Community support (GitHub) | ✓ | ✓ | ✓ |
| Email support | ✗ | ✓ 48h response | ✓ 24h response |
| Priority support | ✗ | ✓ | ✓ |
| Dedicated support | ✗ | ✗ | ✓ |
| Configuration assistance | ✗ | ✓ | ✓ |
| Partner & Reseller | |||
| Partner API access | ✗ | ✗ | ✓ |
| White-label branding | ✗ | ✗ | ✓ |
| Bulk license management | ✗ | ✗ | ✓ Learn more |
Frequently Asked Questions
What happens after the 14-day trial?
Your account downgrades to Free. All settings preserved. Upgrade anytime.
Do I need a credit card to start the trial?
No. The 14-day Pro trial starts instantly when you register. No credit card or payment information is required. If you decide to upgrade after the trial, you can add payment details then.
Can I start free and upgrade later?
Absolutely. The Free plan gives you up to 3 sites with 5 fully active modules, 5 monitor-only modules, and basic cloud dashboard access (3-day data). When you are ready for more sites, all 14 modules unlocked, extended history, PDF reports, and premium bot signatures, upgrading to Pro takes one click and your existing data is preserved.
How many sites does each plan support?
Free covers up to 3 sites with 5 active modules. Pro supports up to 100 sites at $89/site/year ($7.42/mo per site) with all 14 modules unlocked. Max supports up to 250 sites at $169/site/year ($14.08/mo per site) and adds white-label branding and centralized management. Volume discounts apply automatically for 5, 10, and 25-site bundles.
Is billing annual?
Both annual and monthly billing are available. Annual: Pro $89/site/year, Max $169/site/year. Monthly: Pro $9.90/mo, Max $18.90/mo. Your license key activates instantly after purchase.
Is there a money-back guarantee?
Yes. Pro and Max plans come with a 30-day money-back guarantee. If the product does not meet your expectations, contact us within 30 days of purchase for a full refund.
How do the free trial and money-back guarantee work together?
Start with a 14-day free trial of Pro — no credit card required. After the trial, your account moves to the Free plan if you don't upgrade. If you do upgrade and change your mind, you're covered by a 30-day money-back guarantee from the date of purchase. So you get up to 44 days of risk-free evaluation.
Do I need all 14 modules?
No. Each module works independently, so you can enable only the ones you need. However, they are designed to complement each other and the cloud dashboard gives you a single view of all active protections.
Where is my security data stored?
Your data is stored in our EU-hosted cloud dashboard infrastructure. All data is encrypted in transit and at rest. Our architecture is fully GDPR compliant.
What happens when my license expires?
Your modules keep working with all free-tier features. You retain access to your data, but premium features like PDF reports, extended history, and daily signature updates pause until you renew.
Do you offer discounts for non-profits?
Yes. Registered non-profit organizations and educational institutions can apply for a 50% discount on Pro and Max plans. Contact us at [email protected] with proof of status.
Ready to Secure Your WordPress Site?
Start your 14-day Pro trial today. No credit card required.
Start Free — 3 Sites, 5 Modules Start Pro Trial — $89/site/year