ShieldUp – Bad Bots, Scrapers, Attackers Security & Risk Analysis

wordpress.org/plugins/shieldup

ShieldUp helps you to tackle bad bots, scrapers, hackers, enhancing website security and optimizing performance for a seamless user experience.

80 active installs v1.0.1 PHP 7.2.1+ WP 5.3.2+ Updated Nov 17, 2024
activity-logbad-botsperformanceprotectionsecurity
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ShieldUp – Bad Bots, Scrapers, Attackers Safe to Use in 2026?

Generally Safe

Score 92/100

ShieldUp – Bad Bots, Scrapers, Attackers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The shieldup plugin v1.0.1 demonstrates a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities or CVEs in its history is a significant positive indicator, suggesting a history of secure development practices. The code analysis reveals a commendable 96% of output is properly escaped and a substantial 58% of SQL queries utilize prepared statements. Furthermore, the presence of nonce and capability checks on entry points, coupled with no detected unsanitized taint flows, indicates a proactive approach to preventing common web vulnerabilities. The limited attack surface, with all identified entry points (AJAX handlers, cron events) appearing to have some form of security checks, is also a strength. However, there are minor areas for improvement. The use of bundled libraries, such as DataTables, could present a risk if the bundled version is outdated and contains known vulnerabilities, although this is not explicitly indicated as a current issue. While the majority of SQL queries are prepared, the remaining 42% without prepared statements could still represent a potential risk for SQL injection vulnerabilities if certain conditions are met. The presence of 62 total SQL queries is also a notable quantity, increasing the overall surface area for potential SQL-related issues.

Key Concerns

  • SQL queries not using prepared statements
  • Bundled library (DataTables)
Vulnerabilities
None known

ShieldUp – Bad Bots, Scrapers, Attackers Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ShieldUp – Bad Bots, Scrapers, Attackers Release Timeline

v1.0.1Current
Code Analysis
Analyzed Mar 16, 2026

ShieldUp – Bad Bots, Scrapers, Attackers Code Analysis

Dangerous Functions
0
Raw SQL Queries
26
36 prepared
Unescaped Output
2
51 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

58% prepared62 total queries

Output Escaping

96% escaped53 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
<settings> (backend\settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ShieldUp – Bad Bots, Scrapers, Attackers Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_shieldup_get_ipsincludes\ajax.php:4
authwp_ajax_shieldup_get_all_ipsincludes\ajax.php:5
WordPress Hooks 12
actionadmin_headincludes\functions.php:286
actionwp_headincludes\functions.php:288
actionwp_headincludes\functions.php:291
actionshieldup_cron_hourlyincludes\functions.php:396
filterplugin_row_metasu_main.php:36
actioninitsu_main.php:37
actionplugins_loadedsu_main.php:38
actioninitsu_main.php:39
actionadmin_enqueue_scriptssu_main.php:62
actionadmin_enqueue_scriptssu_main.php:73
actionadmin_menusu_main.php:77
actionadmin_headsu_main.php:78

Scheduled Events 1

shieldup_cron_hourly
Maintenance & Trust

ShieldUp – Bad Bots, Scrapers, Attackers Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 17, 2024
PHP min version7.2.1
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs80
Developer Profile

ShieldUp – Bad Bots, Scrapers, Attackers Developer Profile

shieldup

1 plugin · 80 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ShieldUp – Bad Bots, Scrapers, Attackers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shieldup/includes/style/datatables.min.css/wp-content/plugins/shieldup/includes/style/daterangepicker.css/wp-content/plugins/shieldup/includes/style/su_style.css/wp-content/plugins/shieldup/includes/style/fontawsomefree.min.css/wp-content/plugins/shieldup/includes/js/bootstrap.bundle.min.js/wp-content/plugins/shieldup/includes/js/datatables.min.js/wp-content/plugins/shieldup/includes/js/moment.min.js/wp-content/plugins/shieldup/includes/js/daterangepicker.js+2 more
Script Paths
/wp-content/plugins/shieldup/includes/js/bootstrap.bundle.min.js/wp-content/plugins/shieldup/includes/js/datatables.min.js/wp-content/plugins/shieldup/includes/js/moment.min.js/wp-content/plugins/shieldup/includes/js/daterangepicker.js/wp-content/plugins/shieldup/includes/js/apexcharts.min.js/wp-content/plugins/shieldup/includes/js/shieldup.js

HTML / DOM Fingerprints

CSS Classes
su_style.css
JS Globals
ajax_var
FAQ

Frequently Asked Questions about ShieldUp – Bad Bots, Scrapers, Attackers