Enterprise-Grade
WordPress Security
High-performance Web Application Firewall with real-time threat detection. Blocks SQL Injection, XSS, RCE attacks with zero latency impact.
UNION SELECT 1,2,3--
<script>alert(1)</script>
High-performance Web Application Firewall with real-time threat detection. Blocks SQL Injection, XSS, RCE attacks with zero latency impact.
UNION SELECT 1,2,3--
<script>alert(1)</script>
VietShield WAF intercepts requests early in the WordPress loading process, filtering threats before they reach your site's core functions.
Initializes before WordPress plugins to catch threats instantly. Checks IP headers against local threat databases.
Automatically skips analysis for images, CSS, and JS files to ensure strictly zero latency for static assets.
Scans GET, POST, and COOKIE data against comprehensive rule sets for SQLi, XSS, RCE, and other attack vectors.
Records traffic details and metadata asynchronously to prevent performance bottlenecks during request processing.
Defense-in-depth architecture covering every layer of your WordPress application. From network level to application logic.
Core protection engine that blocks malicious requests in real-time with comprehensive rule sets and heuristic analysis.
Blocks UNION SELECT, time-based blind injections, and error-based exploits with advanced pattern recognition.
Prevents Reflected and Stored Cross-Site Scripting attacks. Automatically sanitizes malicious script inputs.
Stops remote code execution, shell commands, and local file inclusion attempts before they can execute.
Automatically identifies and blocks automated tools like SQLMap, Nikto, Nuclei while whitelisting legitimate crawlers.
Syncs with VietShield Network for real-time threat data. 1-day, 7-day, and 30-day threat feeds available.
Comprehensive security tools designed to protect, monitor, and maintain your WordPress site's integrity.
Manage access control lists and automated blocking rules with precision.
Trusted IPs (admins, payment gateways) bypass WAF checks
Permanently block malicious IPs and attack sources
Auto-banned IPs from rate limiting (auto-released)
Block traffic from high-risk countries
Ensure your site's files haven't been tampered with or infected.
Verifies system files against official WordPress repository
Scans themes and plugins for backdoors, shells, eval functions
Configure daily/weekly automated security scans
Email notifications for detected threats and changes
Protect your dashboard from unauthorized access and brute force attacks.
Limits failed login attempts per IP address
Temporarily bans IPs after X failed attempts
Invisible fields to trap and identify bots
Blocks attempts to discover usernames
Monitor who is visiting your site with complete visibility and zero latency.
Watch requests hitting your site live with detailed metadata
Filter by IP, status code, URL, country, and attack type
Instantly block or unblock IPs from the traffic log
Export traffic data to CSV/JSON for analysis
Gain complete visibility into your site's traffic. Monitor IP addresses, geographic locations, user agents, and attack vectors in real-time.
| Status | Method | IP Address | Path | Action |
|---|---|---|---|---|
| 403 | GET | 192.168.1.5 | /?id=1 UNION SELECT... | |
| 200 | GET | 104.28.x.x | /wp-admin/ | |
| 403 | POST | 45.33.x.x | /contact-form [XSS] | |
| 200 | GET | 66.249.x.x | /blog/post-1 | |
| 200 | HEAD | 172.67.x.x | / |
Get protected in under 2 minutes.
Download vietshield-waf-v1.1.2.zip (v1.1.2) or browse all builds on the Releases page.
Go to Dashboard > Plugins > Add New > Upload Plugin. Select `vietshield-waf.zip`.
Click Install Now then Activate. Follow the Setup Wizard to configure prevention.
Go to VietShield WAF > Settings for advanced configuration and list management.
Everything you need to know about VietShield WAF
Absolutely. VietShield is 100% open-source and transparent. You can inspect every line of code on our GitHub Repository to verify it's clean and secure. No hidden code, no backdoors.
No. VietShield is optimized for zero latency. It uses intelligent bypass for static files (images, CSS, JS) and executes heavy logging tasks asynchronously in the background. Your visitors experience no delay.
Don't panic. You have two options: 1) Manually remove your IP from the vietshield_ip_lists database table, or 2) Rename the vietshield-waf plugin folder via FTP/File Manager to temporarily disable the firewall.
Learning Mode logs threats without blocking them - perfect for testing and fine-tuning rules. Protecting Mode actively blocks detected threats. Start with Learning Mode to avoid false positives, then switch to Protecting Mode once configured.
Yes, but we recommend using VietShield as your primary WAF. It works alongside backup plugins, but avoid running multiple WAFs simultaneously as they may conflict. VietShield provides comprehensive protection that typically replaces the need for other security plugins.
VietShield syncs with our community threat network to receive real-time IP blacklists. You can choose 1-day, 7-day, or 30-day feeds. We also auto-whitelist legitimate crawlers like Googlebot and Cloudflare IPs to prevent false positives.
You can get support through our GitHub Issues page or email us at [email protected]. Our community and team are active in helping users configure and optimize their security.