WordPress 6.4+ • PHP 8.2+ • GPLv2 Licensed

Your WordPress Site Is
Under Attack — Right Now

43% of the web runs on WordPress, making it the #1 target for hackers. MTS WP Security Shield detects threats, hardens your site, monitors activity, and responds to incidents — all from one plugin.

7

Security Scanners

5

Risk Levels

12

Admin Pages

8

REST API Endpoints

WordPress Is the #1 Target for Hackers

Without proper security, your site is vulnerable to attacks that can go undetected for months

Without Security Shield

  • Brute-force attacks go undetected
  • Modified files inject malware silently
  • Weak passwords compromise admin accounts
  • XML-RPC amplifies DDoS attacks
  • REST API exposes usernames to attackers
  • No security headers leave XSS gaps
  • Outdated plugins contain known CVEs
  • No incident response or logging

With Security Shield

  • Automatic brute-force detection & lockout
  • File integrity monitoring catches changes
  • 2FA and session management enforce auth
  • XML-RPC restricted to prevent abuse
  • REST API user enumeration blocked
  • Security headers applied automatically
  • Plugin/theme update alerts keep you patched
  • Complete activity log for forensics

Four-Layer Security Architecture

A comprehensive approach that covers the entire threat lifecycle

DETECT
HARDEN
MONITOR
RESPOND
Risk Engine
7 Scanners
IP Firewall
Alert System
Activity Log
IP Blocking
Session Control

7 Specialized Security Scanners

Each scanner targets a specific area of WordPress security to provide comprehensive coverage

File Integrity

SHA-256 hash comparison, modified file detection, unknown file detection, permission checks

Login Security

Default admin check, XML-RPC status, REST API enumeration, user enumeration protection

User Security

Admin count audit, password age tracking, inactive user detection

Configuration

DISALLOW_FILE_EDIT, table prefix, debug mode, auto-updates, file editing checks

Security Headers

X-Content-Type-Options, X-Frame-Options, CSP, HSTS, Referrer-Policy, Permissions-Policy audit

Plugins & Themes

Update availability, abandoned plugin detection, inactive plugin audit

Database

Admin account security, charset verification, table size monitoring

Complete Security Feature Set

Every feature you need to protect your WordPress site, organized by security domain

Login Protection

Brute-force detection with IP lockout, configurable max attempts & lockout duration, failed login tracking, rate limiting per IP address

Two-Factor Authentication

TOTP-based 2FA with QR code setup, Google Authenticator / Authy compatible, per-user enable/disable, RFC 6238 compliant

File Integrity Monitoring

SHA-256 hash comparison on every scan, detects modified PHP files, identifies unknown files, file permission verification

Security Hardening

XML-RPC restriction / disable, REST API access control, user enumeration protection, file editing disable (DISALLOW_FILE_EDIT)

Security Headers

X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, Strict-Transport-Security (HSTS), Content-Security-Policy support

IP Firewall

Manual IP blocking with reason, IP allowlist / denylist management, temporary blocks with auto-expire, brute-force auto-blocking

Activity Logging

Login success and failure logging, IP block/unblock events, settings change tracking, scan completion records

Alert System

Email alerts with HTML formatting, Slack / Discord webhook integration, critical finding immediate alerts, scan summary notifications

Developer Tools

REST API with 8 authenticated endpoints, WP-CLI with 5 commands, zero telemetry, zero external dependencies

How We Compare

See what sets MTS WP Security Shield apart from basic security plugins

Feature Basic Plugins MTS WP Security Shield
Login ProtectionBasicAdvanced with session management
Brute ForceSimple lockoutIP-based with rate limiting
Two-Factor AuthTOTP with QR code setup
File IntegritySHA-256 hash monitoring
Security Headers7+ headers auto-sent
REST API SecurityUser enum blocking
IP FirewallAllow/deny lists
Activity LogFull audit trail
Webhook AlertsSlack/Discord integration
WP-CLI Support5 commands
REST API8 endpoints
Risk Scoring5-level severity engine
Rollback SupportAutomated hardening rollback

Technical Specifications

Built with enterprise-grade architecture and zero external dependencies

8

PHP Namespaces

Modular architecture

12

Admin Pages

Dedicated screens

5

Custom DB Tables

Prepared queries

0

External Dependencies

Zero tracking

LanguagePHP 8.2+
WordPress6.4+ (tested up to 7.1)
PHP8.2+ (tested on 8.2.12)
MySQL5.7+ (tested on 8.0)
REST API8 authenticated endpoints (namespace: mts-ss/v1)
WP-CLI5 commands (wp mts-security)
Database5 custom tables (activity_log, sessions, file_hashes, blocked_ips, scans)
External DependenciesZero (no third-party libraries)
TelemetryNone (zero external API calls)
Memory Usage~40MB peak
LicenseGPL-2.0-or-later

One-Time Investment. No Recurring Fees.

Lifetime updates and support included. Single-site license.

One-Time Purchase

MTS WP Security Shield

Complete WordPress security for one site

₹9,999
One-Time Price • No Subscriptions • Lifetime Updates
Purchase Now
7 Security Scanners
Login Protection + 2FA
File Integrity Monitoring
Security Hardening
IP Firewall & Allow/Deny
Email & Webhook Alerts
REST API + WP-CLI
GPL-2.0 Licensed

Documentation

Comprehensive technical documentation and customer guides