Agency Program Get 2× more leads and save 50% on hosting. Built for agencies ready to grow. Book a call

InstaWP Shield: Managed WordPress Hosting With Security Built In

Shield is the built-in edge security layer on InstaWP: a managed WAF, DDoS mitigation, and no-CAPTCHA bot detection that keep WordPress safe before traffic ever reaches your site.

VS
Vikas Singhal
Founder, InstaWP
Updated Aug 3, 2026 14 min read

After years of helping developers and agencies launch WordPress sites, one question keeps coming back to me in different words: is my site actually safe?

It almost always arrives after something has already gone wrong. A login page being hammered by a brute force script. A checkout crawling because bots outnumber customers. A plugin vulnerability in the news, and no clear way to tell whether it matters for you.

What struck me is that most of those people were already paying for security. Premium firewall plugins, scanners, stacked rules, the lot. The tools were there. What was missing was protection at the right layer, switched on by default.

So when we built managed WordPress hosting at InstaWP, I wanted security to be part of the hosting itself rather than a shopping list. That is Shield: a built-in edge security layer, powered by Bunny Shield, that is on by default on every paid site and fully tunable the moment you want to take the wheel.

INSTAWP SHIELD

The Short Version

What managed WordPress hosting with security built in actually gets you.

Security ships with the hosting

Shield runs at the edge, in front of WordPress. Nothing to install, nothing to renew, no server resources spent.

Three layers, one panel

A managed WAF, DDoS mitigation, and bot detection, all controlled from Site › Configuration › Shield.

Two tiers

Starter gets Basic Shield. Plus, Pro, Turbo, and Elite get Advanced Shield with edge bot detection and custom WAF rules.

On by default, still yours to tune

Switch any layer between Log and Block, adjust bot sensitivity, allowlist trusted services, and export the raw event log.

A safe first week

Learning Mode logs every WAF match for seven days without blocking, so you catch false positives before enforcement begins. Automatic SSL is included and managed for you.

What Shield Is, and Why Edge Security Beats a Plugin

Shield is InstaWP’s built-in security layer for hosted WordPress sites. It is powered by Bunny Shield, the same edge technology behind a lot of high traffic platforms, and the important part is where it sits: at the CDN edge, in front of your site, not inside it.

That single architectural choice is what separates it from a security plugin. A plugin lives inside WordPress, so a request has to reach your server, boot PHP, and hit the database before anything can decide whether it was hostile. You have already paid for the attack in CPU, memory, and queries by the time you block it. Under a real flood, that is exactly why a well secured site still falls over.

Shield makes that decision earlier. Requests are inspected in milliseconds, at the edge, and the bad ones are stopped before your origin ever hears about them. Your PHP workers spend their time on customers instead of on scanners. It is the same reason we handle backups at the platform level: some things belong in the hosting, not in your plugin list.

Every paid plan from Starter upward also gets automatic SSL, issued and renewed for you. It is a small thing until the day a certificate quietly expires on a client site.

Three Layers That Keep WordPress Safe at the Edge

Shield is not one switch. It is three protection layers that each handle a different kind of threat, plus a warm-up mode that stops you from breaking your own site while you tune them.

Managed WAF

A web application firewall that inspects every request for SQL injection, XSS, and the wider OWASP threat set. Run it in Log mode to watch, or Block mode to enforce. Counters show what was triggered, blocked, and logged.

DDoS mitigation

Absorbs volumetric and Layer 7 floods at the edge, so a traffic attack never becomes an origin outage. The Valid Challenge Window controls how long a visitor stays trusted once they have passed a challenge.

Bot detection

Scores traffic on request integrity, IP reputation, and browser fingerprinting, then logs or challenges what looks automated. No CAPTCHA, so real visitors never have to prove anything.

All of it lives in one place in your dashboard, under Site, then Configuration, then Shield.

The InstaWP Shield configuration panel showing the three protection layers and the seven day Learning Mode banner
The Shield panel: three layers, live counters, and the Learning Mode banner across the top.

The managed WAF

The firewall is fully managed, which means we maintain the rule set and you do not buy, configure, or update anything. Every request is checked against known exploit patterns before it reaches WordPress, and none of that inspection costs your site a single PHP worker.

You choose how it behaves. Log records matches without touching traffic. Block enforces them. The counters next to it tell you how many rules were triggered, how many requests were blocked, and how many were merely logged, so you are never guessing.

The managed WAF layer in InstaWP Shield set to Log or Block mode with triggered, blocked, and logged counters
The WAF layer, switchable between Log and Block, with live counters.

DDoS mitigation

Layer 7 attacks are the nasty ones for WordPress. They look like ordinary traffic and aim straight at the expensive pages: search, cart, checkout, login. Shield absorbs them at the edge and challenges what it cannot immediately trust.

The one control worth knowing is the Valid Challenge Window, which sets how long a visitor stays trusted after passing a challenge. A longer window is friendlier for browsing sessions. A shorter one is stricter under active attack.

DDoS mitigation in InstaWP Shield with the Valid Challenge Window control and challenge counters
DDoS mitigation, with the Valid Challenge Window and counters for challenges served, verified, and logged.

Bot detection, without a CAPTCHA

Modern bots forge headers and impersonate real browsers, so a simple block list does very little. Shield scores each request instead, across three signals you can tune independently: request integrity, IP address reputation, and browser fingerprint, with a separate fingerprint aggression setting from Low to High.

Like the WAF, it runs in Log or Challenge mode. And because the scoring is invisible, genuine visitors never meet a puzzle, which matters if you care about conversions and bounce rate. There is also a service allowlist for the tools you actually want crawling your site, such as ManageWP and ShortPixel, so your own stack never gets challenged.

Bot detection in InstaWP Shield showing Log and Challenge modes, request integrity, IP address and browser fingerprint sensitivity, and the trusted service allowlist
Bot detection: modes, three sensitivity controls, fingerprint aggression, and the trusted service allowlist.

Learning Mode, your safe first week

This is the part I would not ship a firewall without. For the first seven days after Shield is enabled, every WAF match is logged and nothing is blocked. You get a full picture of what the rules would have caught on your real traffic, which is exactly when false positives show up: a form builder, a webhook, an API integration, a plugin doing something unusual but legitimate.

Log first, block second

Learning Mode ends on its own after seven days, or you can click Exit Learning Mode as soon as the logs look clean. The same habit applies to every layer you touch afterwards: set it to Log, review the events, then switch it to Block or Challenge.

Download Logs gives you the raw WAF, DDoS, and bot events per site, so the review takes minutes rather than guesswork.

Basic Shield vs Advanced Shield: What Each Plan Includes

Shield comes in two tiers, and this is the bit worth being precise about, because it decides how much protection a given site gets.

Basic Shield covers the fundamentals every live site needs: automatic SSL, the managed WAF, and standard DDoS mitigation. Advanced Shield adds the parts that stop the smarter traffic: edge bot detection with browser fingerprinting and invisible scoring, premium DDoS mitigation, and custom WAF rules of your own.

SHIELD TIERS

Basic Shield vs Advanced Shield

What each tier includes, and where the difference actually shows up.

Capability Basic Shield Advanced Shield
Automatic SSL Included Included
Managed WAF, Log or Block Included Included
DDoS mitigation Standard Premium
Edge bot detection and fingerprinting, no CAPTCHA Not included Included
Custom WAF rules Not included Included
Learning Mode and downloadable logs Included Included

Which plan gets which tier

Sandbox $2 No Shield Built for work in progress, not for live sites.
Starter $5 Basic Shield SSL, managed WAF, and DDoS mitigation.
Plus $9 Advanced Shield Adds bot detection and custom rules.
Pro $15 Advanced Shield Full edge protection.
Turbo $25 Advanced Shield Full edge protection.
Elite $45 Advanced Shield Full edge protection.

Two practical notes. Sandbox is our entry tier for work in progress rather than live traffic, so it has no Shield. And because of that, a site needs Shield disabled before it can be downgraded to Sandbox. The docs cover which plans include Shield and how to downgrade a site plan when you need to.

If you are weighing tiers, the site plans guide and the pricing page put everything else side by side too.

How Shield Works, Step by Step

Follow a single request through the stack and the whole model makes sense.

Step 1: Every request lands at the edge first

Nothing goes straight to your server. Visitor or bot, the request arrives at Bunny Shield, which sits right behind our CDN and ahead of your origin.

Step 2: Shield scores it in milliseconds

Three questions get answered at once: does the request match a known exploit signature, does the source have a bad reputation, and does the client actually look like the browser it claims to be. Request integrity, IP reputation, and browser fingerprinting all feed that score, and it happens in milliseconds, at the edge.

Step 3: It passes, gets challenged, or gets dropped

  • A clean request continues to your site with no delay and no CAPTCHA.
  • A suspicious one is logged or challenged, depending on the mode you set.
  • An attack, whether an exploit attempt or a flood aimed at login and search, is stopped at the edge.

Step 4: Only verified traffic reaches WordPress

By the time a request touches PHP, it has already been filtered. Brute force attempts on wp-login, credential stuffing, spam bots, exploit probes against plugin and theme vulnerabilities, and Layer 7 floods on dynamic pages never consume your resources. Your site does not slow down defending itself, because it never has to.

That is the whole idea. Shield does not run on your site. It runs in front of it.

How to Turn On and Configure Shield

Shield is on by default on every plan that includes it, so for most people there is nothing to do on day one. When you do want to tune it, everything lives in one panel.

  1. Open your site in the InstaWP dashboard and go to Configuration, then Shield.
  2. Check the Learning Mode banner. During the first seven days, WAF matches are logged and never blocked.
  3. Use Download Logs to review the real WAF, DDoS, and bot events from your own traffic.
  4. Add anything legitimate that got flagged to the service allowlist, then move the layer from Log to Block or Challenge.
  5. Tune bot sensitivity if you need to. Request integrity, IP address, and browser fingerprint are separate controls, and fingerprint aggression runs from Low to High.

The safe rollout order for any layer is always the same: Log, review, then Block. If you want the click by click version, the docs walk through configuring Shield in full.

WordPress Security Without Plugins: Shield vs Wordfence and Sucuri

I have used most of them over the years. Wordfence, iThemes Security, Sucuri, and plenty of others. They are good at what they do, and they share one structural limit: they work inside WordPress. The request has to arrive, PHP has to run, and the database has to answer before the plugin can judge it.

Shield moves that decision one layer out. Here is how the day to day difference tends to look.

EDGE VS PLUGIN

A Security Plugin vs InstaWP Shield

Where protection happens, and what that costs your site.

What Matters A Security Plugin InstaWP Shield
Where it runs Inside WordPress, after the request has arrived. At the CDN edge, in front of your site.
Cost of blocking an attack Spends PHP workers, memory, and database queries on traffic you reject. Costs your origin nothing, because it never gets there.
Behaviour under a flood Can go down with the site it is defending. Absorbs volumetric and Layer 7 attacks upstream.
Visitor experience Often leans on CAPTCHA and challenge pages. Invisible scoring, so real visitors prove nothing.
Setup and upkeep Install, license, configure, and keep updated on every site. On by default and fully managed, per site.
Rolling it out safely Usually enforce first, discover the false positives later. Seven day Learning Mode, then Log to Block on your terms.
Certificates Handled separately from the plugin. Automatic SSL issued and renewed for you.

To be clear, Shield does not make plugins pointless. Local file scanning, login auditing, and two factor authentication are all still worth having, and a security plugin is a reasonable complement. What changes is that you are no longer relying on one to be your firewall.

Frequently Asked Questions

How do I secure my WordPress site without plugins?

Host it somewhere that puts security in the hosting layer. On InstaWP, Shield filters exploits, floods, and malicious bots at the CDN edge before a request reaches WordPress, so there is no firewall plugin to install, license, or update. Automatic SSL is included too.

Which InstaWP plans include Shield?

Starter includes Basic Shield, which covers automatic SSL, the managed WAF, and DDoS mitigation. Plus, Pro, Turbo, and Elite include Advanced Shield, which adds edge bot detection with browser fingerprinting, premium DDoS mitigation, and custom WAF rules. Sandbox has no Shield, because it is built for work in progress rather than live sites.

Can I turn Shield off or customise it?

Yes. Shield is on by default, and it is fully configurable at Site, then Configuration, then Shield. You can switch the WAF between Log and Block, set bot detection to Log or Challenge, tune request integrity, IP address, and browser fingerprint sensitivity, adjust the Valid Challenge Window, allowlist trusted services, and download the raw event log.

What is Learning Mode?

For the first seven days after Shield is enabled, every WAF match is logged and nothing is blocked. It lets you spot false positives on your real traffic before enforcement starts. You can click Exit Learning Mode to enforce early once the logs look clean.

Does Shield slow my site down?

No, it usually helps. Filtering happens at the edge in milliseconds, so your origin processes far less junk traffic and your PHP workers stay free for real visitors.

Will visitors see a CAPTCHA?

No. Bot detection uses invisible scoring based on request integrity, IP reputation, and browser fingerprinting, so genuine visitors are never asked to prove they are human. That matters for conversions and for search performance.

Does Shield work with WooCommerce and other dynamic sites?

Yes. It is designed for dynamic, high traffic WordPress, including stores, membership sites, and client projects. It filters threats without caching or breaking sensitive areas such as carts, checkouts, and dashboards.

What happens to Shield if I downgrade my site plan?

Sandbox does not include Shield, so a site needs Shield disabled before it can be downgraded to Sandbox. Moving between Starter and the higher tiers simply changes which Shield tier applies.

Do I still need a security plugin?

For firewall, DDoS, and bot protection, no. Shield covers that at the edge. Plugins are still useful for local file scanning, login auditing, and two factor authentication, so treat them as a complement rather than your main line of defence.

Managed WordPress Security That Is Already On

When we started InstaWP, the goal was to take the friction out of building WordPress sites. Fast spin ups, easy testing, clean handoffs. Moving into managed hosting meant taking on the part nobody enjoys owning, which is security.

You should not need to read five articles to work out how to keep WordPress safe, or stack four plugins to stop bots, or refresh the news every time a vulnerability lands. Shield is our answer: on by default, running at the edge, tunable when you want it, and out of your way when you do not.

Pick a plan, launch a site, and it is already protecting you. New accounts get 25 dollars in signup credits, which is plenty to put the whole thing through its paces first.

VS
Vikas Singhal
Founder, InstaWP

Vikas builds tools that take the friction out of WordPress development. He writes about WP-CLI, dev workflows, and running WordPress at agency scale.