ThreatWall Shield
Calm, application-aware protection for your WordPress estate.
Priority actions recommended next steps
Severity distribution
Security score trend last 20 scans
Website connection health
| Website | Status | Score | Firewall | Action |
|---|
Sort your WordPress portfolio by protection state, scan freshness, and urgent risk.
Websites
| Website | Verified | Score | Schedule | Actions |
|---|
Review what matters first, whether protection is active, and what action closes the risk.
Findings
Click any finding for evidence, analysis and remediation.
| Priority | Risk | Vulnerability | Asset | Protection | Status |
|---|
Alerts
Application-aware WordPress firewall controls: monitor-first rules, signed packages, exclusions, rollback, and investigated IP actions.
Firewall active extended protection
Connect a website install the agent
Generate a one-time connection token, then send it to the site owner with the installer. They upload one file, paste the token, and press Connect.
Firewall rules
| Rule | Lifecycle | Telemetry | Action |
|---|
Blocked IPs
| IP/CIDR | Reason | Status |
|---|
Network defense
| IP/CIDR | Corroboration | Categories | Expires |
|---|
External intelligence
Firewall health
Exclusions and overrides
| Scope | Reason | Status |
|---|
Related detections collapse into groups by rule, site, and path. Review a group once — the verdict covers every event in it, past and future.
Detection groups
| Severity | Rule | Path | Site | Events | Sources | Last seen | Status | Verdict |
|---|
Rule quality reviewed groups only
False-positive rate is computed over groups a human actually reviewed — never over raw event counts.
| Rule | Groups | Reviewed | FP rate | Confirmed | Health |
|---|
Raw event stream last 30 days
| Time | Source | Target | Attack | Rule | Action |
|---|
Show customers they are protected while permanent WordPress updates are pending.
File integrity, suspicious PHP changes, uploaded scripts, and plugin/theme drift.
Malware protection status
Download executive and technical reports, then schedule recurring summaries.
Scheduling
Map scan findings, firewall evidence, and platform controls to GDPR, OWASP, ISO 27001, NIS2, and CIS readiness. ThreatWall provides technical evidence, not legal certification.
Scan → Protect → Govern → Prove Evidence
Control matrix weighted technical controls
| Control | Status | Risk | Evidence | Action |
|---|
Evidence repository stored proof
| Evidence | Hash | Captured |
|---|
Governance settings readiness support
ThreatWall explains risk, prioritizes remediation, and grounds every answer in scan and attack evidence.
Ask ThreatWall
Answer
Threat intelligence feeds CISA KEV · FIRST EPSS · NIST NVD
Feeds sync automatically on a schedule. When a CVE affecting your assets lands on KEV or its EPSS score jumps, open findings are re-scored and you are alerted — without waiting for the next scan.
| Feed | Status | Records | Last run |
|---|
Known exploited vulnerabilities CISA KEV catalogue
| CVE | Product | EPSS | Ransomware | Due |
|---|
Team members
| Member | Role | Status | Staff controls |
|---|
Tracks auditable security and account actions: websites, verification, scans, findings, reports, staff changes, firewall changes, billing, API keys, agents, and compliance. Platform admins see all organization activity; other users see only their own actions.
Activity log recent actions
| Actor | Action | Target | Details | When |
|---|
Upgrade plan subscription access
Personalization workspace preferences
Profile account identity
Settings security and workspace controls
Issue tracking file findings into Jira or GitHub
Connect the tracker your team already works in. Findings become tickets with the full explanation and remediation, and ThreatWall closes them automatically once a rescan proves the fix.
Reports who receives the recurring security report
ThreatWall emails a security report covering every verified website, with the full per-site report attached as a PDF. Leave the recipients empty to send it to this organization's owners and admins.
Set up, operate, and troubleshoot ThreatWall from website verification through scanning, active protection, reporting, and access management.
Guided Security Setup the safe first-run path
Owners and organization administrators see a resumable setup guide on their first dashboard session. Progress is calculated from ThreatWall's records, not from browser checkboxes, so it remains accurate after logout, on another computer, and for every website independently.
| Role | Use during setup |
|---|---|
| Viewer | Reads dashboards, findings, setup status, and reports without changing protection. |
| Analyst | Adds and verifies websites, runs scans, reviews events, and operates site-level firewall workflows. |
| Organization admin | Adds company accounts, assigns invite roles, configures organization settings, and performs analyst work. |
| Billing admin | Handles subscription and billing responsibilities without receiving security-administration rights. |
| Owner | Controls the organization and can complete every guided setup action available to customers. |
Security Lifecycle from discovery to verification
Web Verification how ownership is proven
Scan Engine what each intensity means
| Intensity | Best for | Coverage | Admin expectation |
|---|---|---|---|
| Safe | First checks and low-impact reviews | Passive checks, homepage plus small crawl, conservative templates | Fastest, lowest noise, may miss deeper issues |
| Standard | Routine monitoring | Broader same-site crawling, headers, TLS, fingerprinting, WordPress checks, Nuclei standard templates | Recommended default for verified websites |
| Thorough | Pre-launch, incident review, important sites | Deeper crawl, more URLs, more Nuclei coverage, WordPress-specific checks | Takes longer and may produce more findings to triage |
Connect A Protection Agent live protection runs on the website
Firewall Protection how requests are handled
False Positives & Safe Exclusions review first, tune narrowly
A false positive is legitimate application traffic that resembles an attack and matches a firewall rule. A false-positive verdict records the analyst's conclusion; it does not automatically change enforcement.
| Decision | What changes | Safety rule |
|---|---|---|
| False-positive verdict | Closes the investigation group and updates rule-quality statistics. | Does not alter firewall enforcement. |
| Exclusion preview | Shows which recent events the proposed scope would have silenced. | Uses the same matcher as live enforcement. |
| Temporary exclusion | Allows the exact scoped match after agent synchronization. | Must remain rule-, tenant-, website-, and route-scoped. |
| High-risk override | May affect site-wide, permanent, or confirmed-malicious evidence. | Requires an organization administrator and written justification. |
Virtual Patches & Shared Defense temporary and collective protection
Reports & Delivery stored evidence and scheduled email
Admin Workflow what to do each day
| Where | Question it answers | What the admin should do |
|---|---|---|
| Overview | Am I protected and what is urgent? | Start with Priority actions. Fix critical items first, then disconnected sites. |
| Websites | Are all websites connected and scanned? | Verify new sites, run scans, adjust schedules, and download site reports. |
| Vulnerabilities | What is risky and how do I fix it? | Open each critical/high item, read evidence and remediation, then verify after fixing. |
| Firewall | Is protection active? | Check rule package version, active rules, health, and blocked IPs. |
| Attack Events | Is someone attacking me? | Review blocked requests by source, target, attack type, and matched rule. |
| Virtual Patches | Am I temporarily protected? | Confirm temporary protection, then complete the permanent plugin/theme/core update. |
| Malware | Have protected files changed? | Review integrity drift and suspicious-file signals, confirm legitimate deployments, and investigate unexplained changes. |
| Reports | What can I share with clients or management? | Download reports, configure delivery under Settings → Reports, and use Send now to test email. |
| Compliance | What technical evidence supports audit readiness? | Review framework scores, open mapped controls, export evidence, and confirm manual governance items outside ThreatWall. |
| Threat Intelligence | Is exploitation likely or known? | Use KEV, EPSS, CVE context, and feed freshness to prioritize—not as a replacement for finding evidence. |
| AI Advisor | How should I understand the evidence? | Use grounded explanations and remediation guidance, then validate changes with a rescan. |
| Team & Activity | Who can act and what changed? | Keep least-privilege roles, review security-sensitive actions, and investigate unexpected account or firewall changes. |
Access & Integrations people, automation, and issue tracking
Operations & Troubleshooting what to check when work stops
| Symptom | Check first | Next action |
|---|---|---|
| Verification fails | Exact file URL, meta tag, or DNS TXT value | Correct placement, account for DNS propagation, and retry. |
| Scan fails or stalls | Ownership, target reachability, intensity, and scanner error | Retry Safe, confirm the site permits authorized scanning, then escalate the recorded error. |
| Agent disconnected | Heartbeat, outbound HTTPS, site clock, agent state, and API reachability | Restore connectivity and run the agent status/sync command; do not create a new token unless re-enrollment is required. |
| Ruleset behind | Current and latest package versions plus signature/sync status | Trigger a sync and investigate connectivity or signature errors before enabling blocking. |
| Expected email missing | Report enabled, cadence, recipients, verified sites, and Send now result | Platform operators should check SMTP configuration and scheduled-job execution. |
| Normal request matched | Matched rule, route, source, mode, and sanitized evidence | Keep monitor mode and create the narrowest justified exclusion; never disable broad protection without evidence. |
Compliance Readiness technical evidence, not certification
ThreatWall maps completed website scans and their open normalized findings to a bounded set of technical controls. It does not currently score raw firewall events, contracts, staff training, legal decisions, or incident-notification procedures.
| If you see | What it means | What to do |
|---|---|---|
| Score unavailable | No completed scan exists in the selected scope. | Complete a scan, review scanner coverage, then refresh Compliance. |
| Passed | No mapped open finding was found by the relevant completed assessment. | Retain the evidence and confirm that scan coverage was sufficient. |
| Partial | Mapped findings exist, but none is High or Critical. | Review and schedule remediation, then verify with a rescan. |
| Failed | A mapped High or Critical finding remains open. | Prioritize the finding, apply a permanent fix, and run verification. |
| Manual review | The control needs organizational evidence, or the selected scope has no completed scan. | Collect the external record or complete the missing scan. |
Translation Key badges, clues, and signals
| Signal | Meaning | How to respond |
|---|---|---|
| Critical | High-impact issue that may allow serious compromise or is known to be actively exploited. | Fix first. Confirm whether a virtual patch is active. |
| High | Important vulnerability or misconfiguration with meaningful risk. | Schedule immediate remediation and monitor firewall events. |
| Medium | Risk exists, but exploitation or impact is more limited. | Fix after critical/high items or combine with maintenance work. |
| Low | Minor hardening or hygiene issue. | Track and resolve during routine cleanup. |
| Info | Useful context, fingerprinting, or non-dangerous evidence. | Use for awareness; usually no urgent action. |
| Verified | The system has confirmed ownership, protection, or a positive state. | No immediate action unless paired with a warning elsewhere. |
| Pending | An action is waiting: verification, scan completion, review, or scheduled work. | Open the related page and complete the next step. |
| Failed | A verification, scan, sync, or protection step did not complete. | Read the error, retry, or reconnect the plugin. |
| Risk score | A prioritization number based on severity, confidence, exploit signals, and business context. | Use it to sort work, but always read the evidence before making a change. |
| Evidence | The observed proof: URL, header, scanner output, CVE/CWE, or sanitized firewall event. | Use it to confirm the issue and avoid guessing. |
| Compliance readiness | A weighted technical score for automatic controls inside a selected framework. | Use it to prioritize technical work, then complete manual governance review separately. |
| Manual review | A compliance control that depends on organizational or legal evidence ThreatWall cannot observe. | Track the item with policy, contract, training, incident-response, or legal records. |
| Virtual patch active | The firewall is temporarily reducing exposure before the permanent fix is applied. | Do not treat it as the final fix. Update the vulnerable component and verify. |
| Nuclei enabled | The scan used Nuclei templates for broader detection. | Expect deeper coverage, especially on standard/thorough scans. |
| CISA KEV | The vulnerability appears in the Known Exploited Vulnerabilities catalog. | Escalate. Treat as urgent even if the scan score is not the highest. |
| EPSS | Probability-style exploit prediction signal from threat intelligence. | Higher EPSS means prioritize sooner, especially with exposed WordPress components. |