Wontonee AI products are here — Blogibot & LayerShift now available. Check it out!

WordPress security plugin · WordPress.org

VaultShift

All-in-one WordPress security — malware scanning, WAF, login protection, hardening, activity log, spam defense, and backup. Runs on your server. Free on WordPress.org.

WordPress 5.8+ · PHP 7.4+ · Optional VaultShift Cloud for signature sync & IP reputation

8 security modulesWAF loads earlyLocal-firstFree key availableWP 5.8+

Purpose-built WordPress security

VaultShift replaces a stack of single-purpose security plugins with one integrated suite. Scan for malware, block attacks at the firewall, protect logins, harden your install, audit activity, stop spam, and restore from backup — all from a single dashboard on your own server.

8Security modules
3WAF modes
2FALogin layers
DB+wp-content backup
Modules

Everything your WordPress site needs

Malware & file integrity scanner

Scheduled and on-demand scans with quarantine and WordPress core checksum verification.

Web Application Firewall

Must-use plugin loads early — learning, active, and paranoid modes with geo-blocking and rate limiting.

Login protection

Brute-force lockout, custom login URL, reCAPTCHA v3, and TOTP two-factor authentication.

WordPress hardening

Guided checklist to tighten file permissions, disable risky endpoints, and reduce attack surface.

Tamper-evident activity log

Immutable-style audit trail of admin actions, file changes, and security events on your server.

Spam protection

Honeypot fields, local heuristics, and optional cloud scoring for comment and form spam.

Backup & restore

Database and wp-content snapshots — scheduled or manual — with one-click restore.

Security dashboard

Central hub for security score, module status, scan results, and quick actions.

Malware scanner

Catch threats before they spread

VaultShift scans your WordPress core, themes, and plugins for known malware signatures and unexpected file changes — on a schedule you control or on demand from the dashboard.

  • Scheduled and manual scans
  • Quarantine suspicious files safely
  • Verify core files against official checksums
WAF

Firewall that loads before WordPress

The VaultShift WAF runs as a must-use plugin so it intercepts malicious requests early — before your site boots. Progress from learning mode to active or paranoid protection as you tune rules.

  • Learning, active, and paranoid modes
  • Geo-blocking and IP rate limiting
  • Blocks common exploit patterns at the edge
Login protection

Lock down the front door

Stop brute-force attacks, hide your login URL from bots, and add reCAPTCHA v3 plus TOTP two-factor authentication — all configurable from one panel.

  • Brute-force lockout after failed attempts
  • Custom wp-login URL
  • reCAPTCHA v3 and TOTP 2FA support

More protection built in

Hardening, auditing, spam defense, and disaster recovery — included with every install.

Hardening checklist

Step-by-step recommendations to disable file editing, restrict REST endpoints, and apply security best practices.

Activity log

Tamper-evident record of logins, option changes, and file modifications — stored locally on your server.

Spam defense

Honeypot traps and heuristic scoring block comment spam without sending data off-site unless Cloud is enabled.

Backup & restore

Full database and wp-content backups with scheduled runs and quick restore when something goes wrong.

On your server vs VaultShift Cloud

Core security runs locally with a Free key. Enable Cloud in Settings when you want signature sync, IP reputation, and enhanced spam scoring.

CapabilityOn your server (Free key)+ VaultShift Cloud
Malware & integrity scanning
Web Application Firewall (WAF)
Login protection & 2FA
WordPress hardening checklist
Tamper-evident activity log
Local spam heuristics & honeypot
Database & wp-content backup
Malware signature sync
IP reputation feed
Cloud spam scoring

How to install

Five steps from download to your first security scan.

01

Install the plugin

Upload to /wp-content/plugins/vaultshift/ or use Plugins → Add New → Upload Plugin.

02

Activate VaultShift

Enable the plugin from the WordPress Plugins screen.

03

Enter your key

Add a Free or Cloud key from myapps.wontonee.com in VaultShift settings.

04

Run your first scan

Open the VaultShift Dashboard and launch an integrity scan to establish a baseline.

05

Enable Cloud (optional)

Opt in to signature sync, IP reputation, and cloud spam scoring in Settings.

Local-first architecture

Your data stays on your server

VaultShift is designed to run where your WordPress site lives. Scans, firewall rules, activity logs, and backups are stored locally. VaultShift Cloud is opt-in — enable it only when you want synced malware signatures, IP reputation feeds, or cloud spam scoring.

  • No cloud account required for core modules
  • Free key activates all on-server features
  • Cloud services toggled per site in Settings

Frequently asked questions

No. All core security modules — scanner, WAF, login protection, hardening, activity log, local spam heuristics, and backups — run entirely on your server with a Free key. Cloud is optional for signature sync, IP reputation, and enhanced spam scoring.
The Free key from myapps.wontonee.com activates VaultShift on your site and enables every on-server module. You do not need a paid tier to scan, firewall, harden, log, or back up your WordPress install.
Learning mode observes traffic and suggests rules without blocking. Active mode enforces configured rules. Paranoid mode applies stricter blocking for high-risk environments — use after tuning in learning mode.
VaultShift backs up your WordPress database and the wp-content directory (themes, plugins, uploads). Restore points are managed from the VaultShift Dashboard.
WordPress 5.8 or later, PHP 7.4 or later. VaultShift is tested with WordPress up to version 7.0.
Yes. Core scanning, WAF, login protection, and backups operate at the server or WordPress layer and are compatible with popular caching plugins and CDNs. Configure the WAF in learning mode first if you use aggressive page caching.

Secure your WordPress site today

Install VaultShift free from WordPress.org — activate with a Free key and run your first scan in minutes.