February 23, 2018 by Paul G. | Releases, Shield Pro

WP Shield Security – Release 6.4

Shield Image

Shield Security v6.4 for WordPress released 26th February, 2018.

This release sees the introduction of one of our most exciting features for a long while.

This new feature delivers protection against direct hacking and modifications of plugins and themes.

How plugins and themes can get hacked

100% Prevention of intrusion by outsiders is impossible. It can’t be done, and certainly not by WordPress plugins alone.

Shield Security offers numerous ways to lockdown access to a site and prevent many attack vectors, but once someone is inside the perimeter, we need a way to detect it.

Shield comes already equipped with 2x scanners that detect and report on changes to your files and directories. In particular, it examines your core WordPress files and will compare what is on your site with the files taken straight from WordPress.org.

There is rarely any legitimate reason for modifying core WordPress files. So if a file has been modified, then you really need to examine.

Thankfully Shield already has this covered.

While the Core is protected, what about the rest of the site? Plugins and Themes for example?

It’s common for malware and other malicious code to be injected into your theme’s functions.php file. But it could be inserted into absolutely any file.

Until now Shield wasn’t scanning plugins and themes, but this has changed with the introduction of the Plugins and Themes Guard.

What is the Plugins and Themes Guard from Shield Security?

Simply put, the guard will first analyse all your plugins and themes and then periodically scan them to detect changes to them. Changes it can detect are:

  • File modifications
  • New files added
  • File deleted

If any of these events happen inside your plugins/themes folders, you’ll be alerted.

The default for Shield is to scan once each day, but you can increase this scan up to hourly using the scanner frequency option.

We’ll not cover the finer details of the scanner in this article, so to learn more and watch the explanatory video, please go here.

Improvement: Automatic Update Delays By-Passed For Vulnerable Plugins

In the previous Shield release, we introduced an automatic updates delay – where you could turn on automatic updates, but force a delay before they were applied. This helps ensure a degree of stability has been established for that update before it’s applied to your site.

We’ve now tweaked this setting to ensure faster protection for vulnerable plugins and themes.

If Shield discovers a plugin or theme is vulnerable, and an update is ready to be applied, the update delay will be ignored so that the update can be applied immediately.

We’re too-often asked about what folk should do when they get a warning email from Shield for the WordPress Core File scanners.

So, instead of listing the details of the warning, we’re now linking directly to the Scan Wizards to allow you to more quickly and easily address the problem.

This should hopefully make things a bit clearer for everyone.

(Note: these wizards are only available to users running PHP 5.4+)

Questions and Comments

As always, questions and comments are welcome below.

Hey beautiful!

If you're curious about ShieldPRO and would like to explore the powerful features for protecting your WordPress sites, click here to get started today. (14-day satisfaction guarantee!)

You'll get all PRO features, including AI Malware Scanning, WP Config File Protection, Plugin and Theme File Guard, import/export, exclusive customer support, and so much more.

Try ShieldPRO Today →

ShieldPRO Testimonials
@birdev's Gravatar @birdev

Great support

As a free user, when I encountered a bug with this plugin, I did not have much hope of getting support for it. I nevertheless reported it to the One Dollar Plugin team. To my amazement, I heard back from them within days, and they released a new version of…

@paulbarrett1952's Gravatar @paulbarrett1952

Beats WordFence, especially on price

I run a number of private or not for profit sites where security is needed but budgets are tight, so Shield is the perfect antidote to WordFence. Easy to configure and the pro version is not a rip off. I had it installed on 4 sites. Unfortunately I had to…

@ljkeashly's Gravatar @ljkeashly

Super Support!

We were having an issue with one of our sites that we use this plugin on. The .htaccess file was getting corrupted. We found that Simple Firewall was causing the .htaccess file to be re-written about every minute. I reported the problem on the WordPress forum expecting to never get…

@physisbrasil's Gravatar @physisbrasil


I am Helio from Brazil. Recently searched for a plug-in for WordPress Firewall and opted to use Simple Firewall. It’s a great plug in, and has good support from the developer, sir Paul I use and recommend to everyone.

Leave a Comment

Your email address will not be published. Required fields are marked *

Click to access the login or register cheese