BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Nullis Shield icon
Actively maintained Tested up to 7.0.6

Nullis Shield

A Prevention-First security engine that eliminates bots before they hit your database. Lightweight, zero-bloat, and incredibly fast.

Active installs10+10+ tier
Downloads · 30d67▼ -48.1% vs prev. 30d
Rating5/51 reviews
Health score64/100Good
All-time downloads170Since Aug 2026
Support resolved—No recent threads
RequiresWP 6.0PHP 8.0+
Downloads · 7d11▼ -45% week over week
Our verdict

Solid choice

Nullis Shield is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites, is rated 5/5 and was last updated 1 month ago, and scores 64/100 on our health check.

  • Small user base (10+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

51015Aug 13Sep 6Sep 30
Yesterday2
Daily average (1y)4
Peak day21Aug 13, 2026
Last 12 months174

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Nullis Shield stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
anti-spam >100 723 Best anti-spam plugins →
bot blocker #36 180 Best bot blocker plugins →
firewall >100 966 Best firewall plugins →
honeypot >100 789 Best honeypot plugins →
security >100 10,000 Best security plugins →

Version adoption

Share of active sites per release.

  • 1.3100.0%

Rating breakdown

★★★★★★★★★★ 5 from 1 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About Nullis Shield

From the official readme · v1.3.0

Description

Nullis Shield is a lightweight micro-firewall designed to stop automated bots and spam registrations at the perimeter. It does not perform heavy file scans or maintain large database tables.

Instead, it deploys a honeypot matrix and transient-based IP lockouts to keep your registration endpoint clean.

Key Features:

  • Lightweight Architecture: Stores lockouts using native WordPress Transients. On sites with an object cache (Redis, Memcached), no database writes occur per block. On standard installations, lockouts are written to wp_options.
  • Cloudflare-Aware IP Resolution: When a request arrives via a verified Cloudflare IP range, the plugin reads HTTP_CF_CONNECTING_IP to identify the real attacker. Proxy headers from unverified origins are ignored to prevent IP spoofing.
  • Ghost Purge Review Queue: Optionally flags subscriber accounts older than 7 days that have no display name, no associated orders, and a registration IP the bouncer has already caught elsewhere. This feature is disabled by default, and flagged accounts are never deleted automatically — you review the queue in the dashboard and approve or dismiss each one.

Real-World Results

An earlier internal build of this plugin has been running in production on a live client site. Per that installation’s own Perimeter dashboard, it has logged over 6,000 blocked bot registration attempts to date. This is a single-site field result, not a benchmark or guarantee — actual numbers will vary by site traffic and how heavily your registration endpoint is targeted.

Privacy Policy

Nullis Shield does not collect, transmit, or share any personal data. No telemetry, analytics, or external network calls are made by this plugin. All lockout logs and statistics stay in your site’s own database.

Installation

  1. Upload the nullis-shield folder to the /wp-content/plugins/ directory, or install directly through the WordPress plugins screen.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress.
  3. Navigate to Settings → Nullis Shield in your dashboard to view blocked threat counts and configure settings.
  4. The Ghost Purge review-flagging feature is off by default. Enable it only after confirming it is safe for your user registration flow.

Frequently asked questions

Does this conflict with Wordfence or Solid Security?

No. Nullis Shield targets registration-layer bot traffic. It can run alongside deeper file-scanning plugins without conflict, though it will often stop threats before they reach those layers.

Will this ban Cloudflare?

No. IP resolution first verifies that the incoming connection originates from a genuine Cloudflare IP range before trusting the HTTP_CF_CONNECTING_IP header. Traffic not arriving from a verified Cloudflare range will use REMOTE_ADDR or HTTP_X_FORWARDED_FOR instead.

Is the Ghost Purge review queue safe for WooCommerce sites?

The scan includes a WooCommerce order guard — it will never flag or delete any subscriber account that has at least one associated order. However, you should review your registration flow before enabling this feature, especially if users commonly register without a first or last name.

Does this work on WordPress Multisite?

Banning and lockout transients operate per-site. On uninstall, the plugin cleans up all data across every site in the network.

Changelog

This release contains significant security and privacy improvements. Updating is strongly recommended. If you had the Ghost Purge review-flagging feature enabled, review the updated behaviour — the review window is now 7 days (previously 1 day) and WooCommerce orders are now protected.

1.3.0

  • Security: Cloudflare IP resolution now supports IPv6 ranges in addition to IPv4.
  • Security: Repeat offenders now receive escalating lockouts (1h → 6h → 24h → 48h across a 30-day strike window) instead of a flat 48-hour ban.
  • Reliability: Block counter now uses INSERT ... ON DUPLICATE KEY UPDATE, fixing a race condition where the counter could silently fail to increment if the option row didn’t already exist.
  • Reliability: Lockout responses now include a Retry-After header, computed from the stored ban expiry rather than reading transient internals — correct whether or not an object cache (Redis/Memcached) is active.
  • Behaviour change: Ghost Purge no longer deletes accounts automatically. It now flags likely-spam accounts (no name, no orders, and a registration IP the bouncer has already caught) into a review queue; deletion requires explicit admin approval from the dashboard.
  • Removed: The optional telemetry toggle has been removed from this release. No network calls are made by this plugin.
  • Security: X-Forwarded-For is no longer trusted by default — it was previously accepted unconditionally, letting an attacker spoof it to evade bans or frame another IP. It’s now only trusted if the site owner explicitly declares a reverse-proxy range via the new nullis_shield_trusted_proxies filter.
  • Extensibility: Added nullis_shield_ban_duration, nullis_shield_min_human_time, nullis_shield_max_token_age, nullis_shield_log_ip_format, and nullis_shield_trusted_proxies filter hooks.

1.2.0

  • Security: IP resolution now validates that HTTP_CF_CONNECTING_IP originates from a genuine Cloudflare IP range before trusting it. Spoofed proxy headers are ignored.
  • Security: Registration timestamp is now server-signed via WordPress nonce, preventing forgery by bots.
  • Security: IP lockout keys now use SHA-256 instead of MD5.
  • Security: register_setting() now enforces strict yes/no sanitization callbacks.
  • Security: Dashboard render() callback now re-verifies manage_options capability.
  • Security: All target="_blank" links now include rel="noopener noreferrer".
  • Reliability: Block counter now uses an atomic SQL increment to prevent race conditions.
  • Reliability: Deactivation hook now correctly clears the scheduled cron event.
  • Reliability: Uninstall is now multisite-aware and cache-layer aware.
  • Reliability: Ghost Purge window extended to 7 days; WooCommerce order guard added; batch cap of 200 users per run prevents timeouts.
  • UX: All inline styles moved to admin.css; CSS custom properties introduced for brand colour.
  • Accessibility: :focus-visible ring added to all dashboard links; WCAG AA compliant.

1.1.2

  • Added 48-hour IP lockout.
  • Added Spam User Sniper (Ghost Purge) — internal staging release.

1.0.0

  • Initial release.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Nullis Shield alternatives

All anti-spam plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Akismet Anti-spam: Spam Protection Akismet Anti-spam: Spam Protection The best anti-spam protection to block spam comments and spam in a contact form. The most… by Automattic 5M+ ★★★★★★★★★★ 4.7 (1.2K) 1 month ago 94
2 Antispam Bee Antispam Bee Sophisticated antispam plugin for effective daily comment and trackback spam-fighting… by pluginkollektiv 700K+ ★★★★★★★★★★ 4.8 (226) 1 month ago 78
3 WP Armour – Honeypot Anti Spam WP Armour – Honeypot Anti Spam Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR… by Dnesscarkey 400K+ ★★★★★★★★★★ 5 (1.5K) 4 weeks ago 84
4 CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 CF7 Apps Add hCaptcha, Honeypot, and Redirection to Contact Form 7 with CF7 Apps, and generate forms… by Saad Iqbal 300K+ ★★★★★★★★★★ 3.8 (135) 2 days ago 90
5 Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA Stop spam in contact forms, comments, registrations, and WooCommerce automatically. CAPTCHA… by CleanTalk Inc 200K+ ★★★★★★★★★★ 4.8 (3.2K) 1 day ago 93
6 CloudSecure WP Security CloudSecure WP Security CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。… by XServer 100K+ ★★★★★★★★★★ 5 (2) 3 days ago 86
7 Gravity Forms Zero Spam Gravity Forms Zero Spam Block form spam in Gravity Forms with an invisible token check, email rejection rules, and… by GravityKit 100K+ ★★★★★★★★★★ 4.3 (24) 1 month ago 88
8 Email Encoder – Protect Email Addresses and Phone Numbers Email Encoder – Protect Email Addresses and Phone Numbers Protect email addresses and phone numbers on your site and hide them from spambots. Easy to… by Online Optimisation 90K+ ★★★★★★★★★★ 4.9 (93) 2 weeks ago 91
9 Spam Protection | Maspik Spam Protection | Maspik Blocks spam the moment you activate it. No CAPTCHA, no setup, no API key. Multi-Layer. Just… by yonifre 30K+ ★★★★★★★★★★ 4.7 (87) 3 days ago 94
10 Blackhole for Bad Bots Blackhole for Bad Bots Blackhole is a WordPress security plugin that detects and traps bad bots in a virtual black… by Jeff Starr 30K+ ★★★★★★★★★★ 4.7 (148) 1 month ago 90

FAQ

Nullis Shield: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 1, 2026

Is Nullis Shield free?

Yes. Nullis Shield is free to download and use from the official WordPress.org plugin directory.

Is Nullis Shield safe to use in 2026?

Nullis Shield is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites, is rated 5/5 and was last updated 1 month ago, and scores 64/100 on our health check.

How many websites use Nullis Shield?

Nullis Shield is active on 10+ WordPress websites and has been downloaded 170 times since it launched in August 2026. It was downloaded 67 times in the last 30 days.

Does Nullis Shield work with WordPress 7.1?

Nullis Shield is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does Nullis Shield need?

Nullis Shield requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Nullis Shield last updated?

The latest version, 1.3.0, was released on August 19, 2026 (1 month ago).

Who makes Nullis Shield?

Nullis Shield is developed and maintained by Edward Samuel (Enigmaking).

What are the best alternatives to Nullis Shield?

The most popular alternatives to Nullis Shield are Akismet Anti-spam: Spam Pro… (5M+ installs), Antispam Bee (700K+ installs) and WP Armour (400K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.