Title: DawsonyWeb – Security Shield
Author: DawsonyWeb
Published: <strong>26 ខែ​ឧសភា, 2026</strong>
Last modified: 13 ខែ​កញ្ញា, 2026

---

ស្វែងរក កម្មវិធីបន្ថែម

![](https://ps.w.org/dawsonyweb-security-shield/assets/banner-772x250.png?rev=3694262)

![](https://ps.w.org/dawsonyweb-security-shield/assets/icon.svg?rev=3694262)

# DawsonyWeb – Security Shield

 By [DawsonyWeb](https://profiles.wordpress.org/dawsonyweb/)

[Download](https://downloads.wordpress.org/plugin/dawsonyweb-security-shield.1.1.0.zip)

 * [Details](https://km.wordpress.org/plugins/dawsonyweb-security-shield/#description)
 * [Reviews](https://km.wordpress.org/plugins/dawsonyweb-security-shield/#reviews)
 *  [Installation](https://km.wordpress.org/plugins/dawsonyweb-security-shield/#installation)
 * [Development](https://km.wordpress.org/plugins/dawsonyweb-security-shield/#developers)

 [Support](https://wordpress.org/support/plugin/dawsonyweb-security-shield/)

## Description

DawsonyWeb – Security Shield provides focused controls for comment spam, XML-RPC
and REST API access. Choose the settings that suit your site. It is not a malware
scanner, firewall service or a substitute for updates and backups.

**Comment Protection**

 * Master switch to completely disable all comments (form, REST API, XML-RPC, feeds)
 * Invisible honeypot field to trap bots
 * Minimum comment length enforcement
 * Block all links or cap links per comment
 * Require login to comment
 * Keyword/phrase blocklist

**API & REST Hardening**

 * Disable XML-RPC entirely (removes X-Pingback header too)
 * Hide `/wp/v2/users` endpoints from guests while keeping them available to signed-
   in users
 * Require authentication for all REST API requests
 * Optionally disable the REST API completely
 * Block author enumeration via `/?author=N`

**Spam Rules**

 * Per-IP comment rate limiting (configurable max and time window)
 * IP address blocklist — blocked IPs receive a 403 on any front-end request
 * Rolling activity log (last 200 events)

### Privacy

When activity logging is enabled, the plugin stores up to 200 blocked-event entries
locally, including IP address, time and reason. Administrators can clear the log
or turn logging off. Comment rate limits use temporary counters. No log data is 
sent to DawsonyWeb or a third-party service. Uninstalling removes the plugin settings,
logs and rate-limit transients.

## Screenshots

[⌊Overview of configured comment and API controls.⌉⌊Overview of configured comment
and API controls.⌉[

Overview of configured comment and API controls.

[⌊API settings with explanations of compatibility impacts.⌉⌊API settings with explanations
of compatibility impacts.⌉[

API settings with explanations of compatibility impacts.

## Installation

 1. Upload the `dawsonyweb-security-shield` folder to `/wp-content/plugins/`.
 2. Activate the plugin through the Plugins menu in WordPress.
 3. Go to Security Shield in the admin menu to configure.

## FAQ

### Can API restrictions affect other plugins?

Yes. Requiring login for all REST requests can affect public forms, WooCommerce 
blocks and external integrations. Disabling REST completely also breaks the block
editor. Start with the defaults and test the affected workflow after changing a 
restriction.

### Do settings on other tabs stay unchanged when I save?

Yes. Each form changes only the settings included on that tab.

### Does this use a cloud security service?

No. Rules run on your WordPress site. There is no external scanning or telemetry.

### Which IP address does the plugin use?

The direct connection address supplied by the server (REMOTE_ADDR). It does not 
trust visitor-supplied forwarding headers. If you use a reverse proxy, configure
real client IP handling with your host before relying on IP controls.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“DawsonyWeb – Security Shield” is open source software. The following people have
contributed to this plugin.

Contributors

 *   [ DawsonyWeb ](https://profiles.wordpress.org/dawsonyweb/)

[Translate “DawsonyWeb – Security Shield” into your language.](https://translate.wordpress.org/projects/wp-plugins/dawsonyweb-security-shield)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/dawsonyweb-security-shield/),
check out the [SVN repository](https://plugins.svn.wordpress.org/dawsonyweb-security-shield/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/dawsonyweb-security-shield/)
by [RSS](https://plugins.trac.wordpress.org/log/dawsonyweb-security-shield/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.0

 * Preserves settings on other tabs when saving. Keeps user endpoints available 
   to signed-in editors. Added validated IP entries, bounded limits and a fixed 
   rate-limit window. Refreshed the DawsonyWeb workspace.

#### 1.0.1

 * Compatibility: tested up to WordPress 7.0.

#### 1.0.0

 * Initial release.

## មេតា

 *  Version **1.1.0**
 *  Last updated **3 ថ្ងៃ មុន**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.0.4**
 *  PHP version ** 8.0 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/dawsonyweb-security-shield/)
 * Tags
 * [comments](https://km.wordpress.org/plugins/tags/comments/)[rest-api](https://km.wordpress.org/plugins/tags/rest-api/)
   [security](https://km.wordpress.org/plugins/tags/security/)[spam](https://km.wordpress.org/plugins/tags/spam/)
   [xmlrpc](https://km.wordpress.org/plugins/tags/xmlrpc/)
 *  [Advanced View](https://km.wordpress.org/plugins/dawsonyweb-security-shield/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/dawsonyweb-security-shield/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/dawsonyweb-security-shield/reviews/)

## Contributors

 *   [ DawsonyWeb ](https://profiles.wordpress.org/dawsonyweb/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/dawsonyweb-security-shield/)