I've just upgraded to Pro. What should I do next?
In this walk-through guide, we are going to explain what the next steps you should take upon upgrading to Pro.
The first step to take is activation of the Pro features on your site. To do this, you wont need your license key. Activation is keyless
You simply log into the site associated to that license, and then:
- Open the ShieldPRO section
- Be sure to have first activated your site URL (the URL of the site you want to license inside your Shield Security Pro account) by clicking the "Keyless Activation" section => View.
- Hit the "Check License" button and all the Pro features will be automatically licensed on the site within 30 seconds.
Important: If you have any trouble with keyless activation, just click a little "Debug" link beneath the "Check License" button and send us an error you see.
To learn more about Keyless Activation, read the release article here.
Then, you can review the all Pro features and enable the ones you want.
Each Shield module contains Pro features you may want to use. This is the complete list of the Pro features, what they are used for and how to enable them.
Please note that enabling/using of any of the ShieldPRO features listed below depends on your personal requirements.
Shield Module | Pro Feature | Description | Screenshots |
Integrations |
Shield Security extension for MainWP |
Easily integrate Shield Security to help you manage your site security from within MainWP. You don't need to install a separate extension for MainWP. You can turn-on Shield's built-in extension for MainWP server and client installations through Shield's Integrations module. Important: If this is a MainWP client site, you should add your MainWP Admin Server's IP address to your IP list. |
|
Integrations |
SPAM detection for contact forms |
Use Shield's built-in SPAM detection system to identify contact form SPAM. Choose the form providers that should be checked for antibot and/ or human SPAM. |
|
Integrations | Antibot - Custom User Forms | Automatically detect Bot requests to custom user forms. Select your 3rd party providers to have Shield automatically detect Bot requests to these forms. |
|
General settings | ShieldNET | ShieldNET is the all-encompassing term that covers the technology and features that we use to gather security and threat information from across our entire WordPress ecosystem. By collecting information from all active Shield Security plugins, we can offer this information back as threat intelligence to all sites running Shield. The responsibility of identifying threats is then shifted away from individual sites to the collective. A single site only knows what it knows. But when 10,000 sites get together and share information, they each know what 10,000 sites know. This is massive. It completely transforms what’s possible when mitigating threats to our WordPress sites. For more information about ShieldNET, read the release blog post or watch the video here. |
|
General Settings
|
Allow WP-CLI |
With WP-CLI you can perform many common actions of the ShieldPRO plugin just as you would with the point-and-click UI. More Info Common WP-CLI commands for all modules can be found here. |
|
General Settings | CAPTCHA Style |
Choose your own CAPTCHA style:
Before you use this feature, please ensure that Google reCAPTCHA or hCaptcha is enabled. This feature is available within the following modules:
|
|
General Settings | Import/Export |
Automatically import options and deploy configurations across your entire security network. You can easily setup the Shield Security plugin on 1 site and have all options replicated to your other sites automatically. You can also exclude options you don't want to be imported. More Info |
|
Security Admin | Persistent Security Admins |
Specify usernames for Security Admin role. Admin users provided will be security admins automatically, without needing the security PIN. Enter admin username, email or ID. 1 entry per-line. |
|
Security Admin |
White Label | Rename and re-brand the Shield plugin for your client site installations and own your own brand. You can also chose your own logo to display on the Two-Factor Authentication login page. The all White Label options are best explained here. To activate While Label, make sure that Security Admin system is enabled. |
|
Block Bad IPs/Visitors | User Auto Unblock With Shield Bot Protection |
Allow your site visitors to automatically unblock themselves from Shield. When this feature is activated, your site visitors/users will just need to check the bot protection checkbox and click the "Unblock My IP Address" button. They will automatically get unblocked, and their IP will be removed from the blacklist. A visitor will only be able to remove themselves from the block list once in a 24 hour period. |
|
Block Bad IPs/Visitors |
User Auto Unblock With Magic Link |
Allow your site logged-in users to automatically unblock themselves from Shield. When logged-in site users get blocked by Shield, they can unblock their IP automatically by using a "magic" link sent by email. More Info |
|
Block Bad IPs/Visitors | Request Path Whitelist |
Prevent requests to particular paths on your site from triggering the IP blacklisting system. That is to say, if you specify whitelisted path /my-whitelisted-path/ and a visitor makes a request to your site to this URL and triggers the Shield Security system to blacklist or blackmark the visitor IP address, this trigger will be ignored. |
|
Block Bad IPs/Visitors | Login Bots |
Option
Identify and capture Bot when it tries to login with a non-existent username. This includes the default 'admin' if you've removed that account. This may indicate a bot’s attempt to login. Since it used a non-existent username, chances are higher that it’s a bot. You can also decide how you want Shield to respond:
|
|
Block Bad IPs/Visitors | Probing Bots |
Options
You can also decide how you want Shield to respond:
|
|
Block Bad IPs/Visitors | Bot Behaviors |
Options
You can also decide how you want Shield to respond:
|
|
Block Bad IPs/Visitors | Manual IP Blacklisting | Manually add IP you want to blacklist (if needed). This is done through Manage IPs section. You can add as many IPs as you like. You can also manually block IP address range. Or, you can automatically import a large list of IPs to Whitelist or Blacklist. Note that, if you have the automated black list system enabled, the blacklisted IP will be removed over time. The expiration time depends on your Auto Block Expiration settings. |
|
Audit Trail | Auto Clean | Any audit trail entries older than number of days set will be automatically removed from database |
|
Hack Guard | Malware Scanner |
Scan and monitor files for Malware infections. This scanner monitors and detects presence of Malware signatures. Keep this scanner turned on, at all times. Currently files of the following types are supported: PHP |
|
Hack Guard | Plugins & Themes Scanner |
Scan and monitor Plugin & Theme files for changes. This scanner looks for new files added to plugins or themes, and also for changes to existing files. Keep this scanner turned on, at all times. It doesn't currently detect missing files. You can also automatically repair files that have changes, if you want. |
|
Hack Guard | Vulnerability Scanner |
Regularly scan your list of the installed WordPress plugins and compare their current versions against a list of known plugin vulnerabilities. You can also set this scanner to automatically apply updates to items with known vulnerabilities when an update becomes available. |
|
Hack Guard | File Locker |
Lock files against tampering and changes. File Locker detects changes to the some of the most important WordPress files as they happen (in realtime). Then, lets you examine contents and revert as required. The files covered with File Locker system are
|
|
Hack Guard | Daily Scan Frequency |
The default schedule of the automatic scans is once every 24hrs. Improve security, increase the schedule of the automated scanners so they run more than once per day. |
|
Hack Guard | Show Re-Install Links |
When this feature is enabled, it will make 2 changes to your WordPress admin plugins page:
Plugins & Themes scanner will ensure that the files are clean and original at the time of activation. In this way, plugin files cannot have been compromised or edited in any way. Note that these re-install options are only available for plugins that are installed from WordPress.org. |
|
Hack Guard | Auto-Filter Results | You can use this option to automatically remove items from scan results that are irrelevant. An example of this is filtering out results when
|
|
Traffic Watch | Custom Exclusions |
If you want to manually customize exclusions to skip the logging of web requests you know to be legitimate, you can use Custom Exclusions system.This reduces the size of your traffic log and also prevents your logs from filling up with information you might don't need to have logged. |
|
Traffic Watch | Traffic Rate Limiting |
Traffic rate limiting is where you restrict the number of requests a single visitor can make against your site, within a certain period of time. Use this feature with care. You could block legitimate visitors who load too many pages in quick succession on your site. You can set
Use a larger maximum request limit to reduce the risk of blocking legitimate visitors.
Use a smaller interval to reduce the risk of blocking legitimate visitors. |
|
Login Guard | AntiBot JS |
You can use AntiBot JS includes for custom 3rd party form.
Note that IDs are prefixed with "#". Classes are prefixed with ".". IDs are preferred over classes. This is experimental. |
|
Login Guard | 2FA - Allow Any User |
Allow any user to turn-on Two-Factor Authentication by email. Any user can turn on/off 2FA by email from their profile. |
|
Comms |
SureSend Email |
SureSend is a dedicated email delivery service from Shield Security. It ensures that you get 2FA email with a verification code so you can complete your login. |
|
Login Guard | Hardware 2FA - Allow U2F |
Allow users to register U2F devices to complete their login. Currently only U2F keys are supported. Built-in fingerprint scanners aren't supported (yet). Beta! This may only be used when at least 1 other 2FA option is enabled on a user account. Requires PHP 7.0 or later. |
|
Login Guard | Yubikey multiple keys |
If you’re using Yubikeys on your WordPress sites – losing your Yubikey could cause some major headaches. So with Shield, users can add as many Yubikey devices to their accounts as they’d like. |
|
Login Guard | Multi-Factor By-Pass (Remember Me) |
A user can by-pass Multi-Factor Authentication (MFA) for the set number of days. Enter the number of days a user can by-pass future MFA after a successful MFA-login. 0 to disable. |
|
Login Guard | Allow Backup Codes |
Allow users to generate a backup code that can be used to login if MFA factors are unavailable. More Info |
|
User Management | User Registration |
Options
|
|
User Management | Password Policies |
Have full control over passwords used by users on the site. Once you have Password Policies feature turned on and the password quality requirements set, all users roles (including Security Admin) must meet those requirements - there's no exceptions whatsoever. Otherwise, they will not be able to login. |
|
User Management | User Suspension |
Options
|
|
User Management | User Login Notification Email |
When this feature is enabled, a notification is sent to each user when a successful login occurs for their account. |
|
User Management | Login Notification Email for Admins |
Supply multiple email addresses for Administrator login notifications. More Info |
|
Comments SPAM | Trusted User Roles |
Protect against comments SPAM by registered users. Shield doesn't normally scan comments from logged-in or registered users. Specify user roles here that shouldn't be scanned. Take a new line for each user role. |
|
Automatic Updates | Update Delay |
Protect your WordPress site against auto-update disasters. This feature forces any automatic upgrade to be delayed for a set number of days. This allows time for killer bugs to be discovered and patched before your site automatically updates. So, Shield will delay upgrades until the new update has been available for the set number of days. This helps ensure updates are more stable before they're automatically applied to your site. |
|
HTTP Headers | Manual CSP Rules |
You can add manual CSP rules which are not covered by the rules listed under the CSP Headers section. You should test them on your site thoroughly first. Take a new line per rule. |
|
Other | Shield’s 2FA/MFA UI | Add exactly the same user interface as seen in the WordPress admin area, to the frontend with the use of a simple WordPress shortcode. We’ve adjusted the UI to ensure that the user experience in either formats (backend or frontend) is identical. More Info |
|
Other | 3rd-Party Support |
The 3rd-Party Support feature is a part of the Login Guard module. It works with 3rd party platforms such as WooCommerce, BuddyPress, and Easy Digital Downloads. It provides the following:
The 3rd-Party Support feature is enabled by default on Pro sites. The full list of the compatible WordPress membership plugins can be found here. Note: There's also " AntiBot JS" option you may use to enter the selectors of the 3rd party login forms for use with AntiBot JS. |
|
Other | Customised User Messages |
You have the ability to customize messages displayed to the user. If you want to communicate to the users in a particular manner and add your own custom messages, you can do that by using the following options:
Customised messages are available under the
|
|
Other | Customise 2FA Email Content | You can change the content shown to users through the use of custom templates. At this moment, you can customise Two-Factor Authentication Code email. |
Need Help?
ShieldPRO support has worked very hard putting together comprehensive guides to troubleshooting. We’ve identified the most common customer questions, and have outlined solutions in many articles in our Help Center here.
If you can't find the answer to your question in the Help Center, get in touch any time so we can help. For the best place to start with your support ticket submission, please follow this link here.
Interested in Affiliate Rewards For Shield Security PRO?
All you need to do is complete the registration form, and soon your sites will be setup for automatic referral links using the plugin badge.
We go into all the details here. Also, unlike other referral schemes that only give you once-off rewards, our referrals are for life.