43% of the web runs on WordPress, making it the #1 target for hackers. MTS WP Security Shield detects threats, hardens your site, monitors activity, and responds to incidents — all from one plugin.
Security Scanners
Risk Levels
Admin Pages
REST API Endpoints
Without proper security, your site is vulnerable to attacks that can go undetected for months
A comprehensive approach that covers the entire threat lifecycle
Each scanner targets a specific area of WordPress security to provide comprehensive coverage
SHA-256 hash comparison, modified file detection, unknown file detection, permission checks
Default admin check, XML-RPC status, REST API enumeration, user enumeration protection
Admin count audit, password age tracking, inactive user detection
DISALLOW_FILE_EDIT, table prefix, debug mode, auto-updates, file editing checks
X-Content-Type-Options, X-Frame-Options, CSP, HSTS, Referrer-Policy, Permissions-Policy audit
Update availability, abandoned plugin detection, inactive plugin audit
Admin account security, charset verification, table size monitoring
Every feature you need to protect your WordPress site, organized by security domain
Brute-force detection with IP lockout, configurable max attempts & lockout duration, failed login tracking, rate limiting per IP address
TOTP-based 2FA with QR code setup, Google Authenticator / Authy compatible, per-user enable/disable, RFC 6238 compliant
SHA-256 hash comparison on every scan, detects modified PHP files, identifies unknown files, file permission verification
XML-RPC restriction / disable, REST API access control, user enumeration protection, file editing disable (DISALLOW_FILE_EDIT)
X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, Strict-Transport-Security (HSTS), Content-Security-Policy support
Manual IP blocking with reason, IP allowlist / denylist management, temporary blocks with auto-expire, brute-force auto-blocking
Login success and failure logging, IP block/unblock events, settings change tracking, scan completion records
Email alerts with HTML formatting, Slack / Discord webhook integration, critical finding immediate alerts, scan summary notifications
REST API with 8 authenticated endpoints, WP-CLI with 5 commands, zero telemetry, zero external dependencies
See what sets MTS WP Security Shield apart from basic security plugins
| Feature | Basic Plugins | MTS WP Security Shield |
|---|---|---|
| Login Protection | Basic | Advanced with session management |
| Brute Force | Simple lockout | IP-based with rate limiting |
| Two-Factor Auth | ✗ | TOTP with QR code setup |
| File Integrity | ✗ | SHA-256 hash monitoring |
| Security Headers | ✗ | 7+ headers auto-sent |
| REST API Security | ✗ | User enum blocking |
| IP Firewall | ✗ | Allow/deny lists |
| Activity Log | ✗ | Full audit trail |
| Webhook Alerts | ✗ | Slack/Discord integration |
| WP-CLI Support | ✗ | 5 commands |
| REST API | ✗ | 8 endpoints |
| Risk Scoring | ✗ | 5-level severity engine |
| Rollback Support | ✗ | Automated hardening rollback |
Built with enterprise-grade architecture and zero external dependencies
PHP Namespaces
Modular architecture
Admin Pages
Dedicated screens
Custom DB Tables
Prepared queries
External Dependencies
Zero tracking
| Language | PHP 8.2+ |
| WordPress | 6.4+ (tested up to 7.1) |
| PHP | 8.2+ (tested on 8.2.12) |
| MySQL | 5.7+ (tested on 8.0) |
| REST API | 8 authenticated endpoints (namespace: mts-ss/v1) |
| WP-CLI | 5 commands (wp mts-security) |
| Database | 5 custom tables (activity_log, sessions, file_hashes, blocked_ips, scans) |
| External Dependencies | Zero (no third-party libraries) |
| Telemetry | None (zero external API calls) |
| Memory Usage | ~40MB peak |
| License | GPL-2.0-or-later |
Lifetime updates and support included. Single-site license.
Complete WordPress security for one site
Comprehensive technical documentation and customer guides