{"id":307449,"date":"2026-05-26T08:46:53","date_gmt":"2026-05-26T08:46:53","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/dawsonyweb-security-shield\/"},"modified":"2026-09-13T22:50:34","modified_gmt":"2026-09-13T22:50:34","slug":"dawsonyweb-security-shield","status":"publish","type":"plugin","link":"https:\/\/cl.wordpress.org\/plugins\/dawsonyweb-security-shield\/","author":23454405,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.0.5","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"DawsonyWeb \u2013 Security Shield","header_author":"DawsonyWeb","header_description":"Spam comment protection, complete comment disabling, XML-RPC hardening, REST API lockdown, user enumeration blocking, IP blocklisting, and rate limiting.","assets_banners_color":"707c7e","last_updated":"2026-09-13 22:50:34","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/dawsony.com\/plugins\/security-shield","header_author_uri":"https:\/\/dawsony.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":244,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"dawsonyweb","date":"2026-05-26 08:45:35","revision":3548776},"1.1.0":{"tag":"1.1.0","author":"dawsonyweb","date":"2026-09-13 22:50:34","revision":3694262}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3694262,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3694262,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3694262,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3694262,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3694262,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1","1.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3694262,"resolution":"1","location":"assets","locale":"","width":1280,"height":680},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3694262,"resolution":"2","location":"assets","locale":"","width":1280,"height":880}},"screenshots":{"1":"Overview of configured comment and API controls.","2":"API settings with explanations of compatibility impacts."}},"plugin_section":[],"plugin_tags":[107,23853,600,599,14731],"plugin_category":[44,54],"plugin_contributors":[256015],"plugin_business_model":[],"class_list":["post-307449","plugin","type-plugin","status-publish","hentry","plugin_tags-comments","plugin_tags-rest-api","plugin_tags-security","plugin_tags-spam","plugin_tags-xmlrpc","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-dawsonyweb","plugin_committers-dawsonyweb"],"banners":{"banner":"https:\/\/ps.w.org\/dawsonyweb-security-shield\/assets\/banner-772x250.png?rev=3694262","banner_2x":"https:\/\/ps.w.org\/dawsonyweb-security-shield\/assets\/banner-1544x500.png?rev=3694262","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/dawsonyweb-security-shield\/assets\/icon.svg?rev=3694262","icon":"https:\/\/ps.w.org\/dawsonyweb-security-shield\/assets\/icon.svg?rev=3694262","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/dawsonyweb-security-shield\/assets\/screenshot-1.png?rev=3694262","caption":"Overview of configured comment and API controls."},{"src":"https:\/\/ps.w.org\/dawsonyweb-security-shield\/assets\/screenshot-2.png?rev=3694262","caption":"API settings with explanations of compatibility impacts."}],"raw_content":"<!--section=description-->\n<p>DawsonyWeb \u2013 Security Shield provides focused controls for comment spam, XML-RPC and REST API access. Choose the settings that suit your site. It is not a malware scanner, firewall service or a substitute for updates and backups.<\/p>\n\n<p><strong>Comment Protection<\/strong><\/p>\n\n<ul>\n<li>Master switch to completely disable all comments (form, REST API, XML-RPC, feeds)<\/li>\n<li>Invisible honeypot field to trap bots<\/li>\n<li>Minimum comment length enforcement<\/li>\n<li>Block all links or cap links per comment<\/li>\n<li>Require login to comment<\/li>\n<li>Keyword\/phrase blocklist<\/li>\n<\/ul>\n\n<p><strong>API &amp; REST Hardening<\/strong><\/p>\n\n<ul>\n<li>Disable XML-RPC entirely (removes X-Pingback header too)<\/li>\n<li>Hide <code>\/wp\/v2\/users<\/code> endpoints from guests while keeping them available to signed-in users<\/li>\n<li>Require authentication for all REST API requests<\/li>\n<li>Optionally disable the REST API completely<\/li>\n<li>Block author enumeration via <code>\/?author=N<\/code><\/li>\n<\/ul>\n\n<p><strong>Spam Rules<\/strong><\/p>\n\n<ul>\n<li>Per-IP comment rate limiting (configurable max and time window)<\/li>\n<li>IP address blocklist \u2014 blocked IPs receive a 403 on any front-end request<\/li>\n<li>Rolling activity log (last 200 events)<\/li>\n<\/ul>\n\n<h3>Privacy<\/h3>\n\n<p>When activity logging is enabled, the plugin stores up to 200 blocked-event entries locally, including IP address, time and reason. Administrators can clear the log or turn logging off. Comment rate limits use temporary counters. No log data is sent to DawsonyWeb or a third-party service. Uninstalling removes the plugin settings, logs and rate-limit transients.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>dawsonyweb-security-shield<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin through the Plugins menu in WordPress.<\/li>\n<li>Go to Security Shield in the admin menu to configure.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20api%20restrictions%20affect%20other%20plugins%3F\"><h3>Can API restrictions affect other plugins?<\/h3><\/dt>\n<dd><p>Yes. Requiring login for all REST requests can affect public forms, WooCommerce blocks and external integrations. Disabling REST completely also breaks the block editor. Start with the defaults and test the affected workflow after changing a restriction.<\/p><\/dd>\n<dt id=\"do%20settings%20on%20other%20tabs%20stay%20unchanged%20when%20i%20save%3F\"><h3>Do settings on other tabs stay unchanged when I save?<\/h3><\/dt>\n<dd><p>Yes. Each form changes only the settings included on that tab.<\/p><\/dd>\n<dt id=\"does%20this%20use%20a%20cloud%20security%20service%3F\"><h3>Does this use a cloud security service?<\/h3><\/dt>\n<dd><p>No. Rules run on your WordPress site. There is no external scanning or telemetry.<\/p><\/dd>\n<dt id=\"which%20ip%20address%20does%20the%20plugin%20use%3F\"><h3>Which IP address does the plugin use?<\/h3><\/dt>\n<dd><p>The direct connection address supplied by the server (REMOTE_ADDR). It does not trust visitor-supplied forwarding headers. If you use a reverse proxy, configure real client IP handling with your host before relying on IP controls.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Preserves settings on other tabs when saving. Keeps user endpoints available to signed-in editors. Added validated IP entries, bounded limits and a fixed rate-limit window. Refreshed the DawsonyWeb workspace.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Compatibility: tested up to WordPress 7.0.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Spam comment protection, comment disabling, XML-RPC hardening, REST API lockdown, user enumeration blocking, and IP blocklisting.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/307449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=307449"}],"author":[{"embeddable":true,"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dawsonyweb"}],"wp:attachment":[{"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=307449"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=307449"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=307449"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=307449"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=307449"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/cl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=307449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}