Title: Nullis Shield
Author: Edward Samuel (Enigmaking)
Published: <strong>13 augustus 2026</strong>
Last modified: 13 augustus 2026

---

Plugins zoeken

![](https://s.w.org/plugins/geopattern-icon/nullis-shield.svg)

# Nullis Shield

 Door [Edward Samuel (Enigmaking)](https://profiles.wordpress.org/countteddy/)

[Download](https://downloads.wordpress.org/plugin/nullis-shield.zip)

 * [Details](https://nl.wordpress.org/plugins/nullis-shield/#description)
 * [Beoordelingen](https://nl.wordpress.org/plugins/nullis-shield/#reviews)
 *  [Installatie](https://nl.wordpress.org/plugins/nullis-shield/#installation)
 * [Ontwikkeling](https://nl.wordpress.org/plugins/nullis-shield/#developers)

 [Ondersteuning](https://wordpress.org/support/plugin/nullis-shield/)

## Beschrijving

Nullis Shield is a lightweight micro-firewall designed to stop automated bots and
spam registrations at the perimeter. It does not perform heavy file scans or maintain
large database tables.

Instead, it deploys a honeypot matrix and transient-based IP lockouts to keep your
registration endpoint clean.

**Key Features:**

 * **Lightweight Architecture:** Stores lockouts using native WordPress Transients.
   On sites with an object cache (Redis, Memcached), no database writes occur per
   block. On standard installations, lockouts are written to `wp_options`.
 * **Cloudflare-Aware IP Resolution:** When a request arrives via a verified Cloudflare
   IP range, the plugin reads `HTTP_CF_CONNECTING_IP` to identify the real attacker.
   Proxy headers from unverified origins are ignored to prevent IP spoofing.
 * **Ghost Purge Review Queue:** Optionally flags subscriber accounts older than
   7 days that have no display name, no associated orders, and a registration IP
   the bouncer has already caught elsewhere. **This feature is disabled by default,
   and flagged accounts are never deleted automatically** — you review the queue
   in the dashboard and approve or dismiss each one.

### Real-World Results

An earlier internal build of this plugin has been running in production on a live
client site. Per that installation’s own Perimeter dashboard, it has logged over
6,000 blocked bot registration attempts to date. This is a single-site field result,
not a benchmark or guarantee — actual numbers will vary by site traffic and how 
heavily your registration endpoint is targeted.

### Privacy Policy

Nullis Shield does not collect, transmit, or share any personal data. No telemetry,
analytics, or external network calls are made by this plugin. All lockout logs and
statistics stay in your site’s own database.

## Installatie

 1. Upload the `nullis-shield` folder to the `/wp-content/plugins/` directory, or install
    directly through the WordPress plugins screen.
 2. Activate the plugin through the ‘Plugins’ screen in WordPress.
 3. Navigate to **Settings  Nullis Shield** in your dashboard to view blocked threat
    counts and configure settings.
 4. The Ghost Purge review-flagging feature is **off by default**. Enable it only after
    confirming it is safe for your user registration flow.

## FAQ

### Does this conflict with Wordfence or Solid Security?

No. Nullis Shield targets registration-layer bot traffic. It can run alongside deeper
file-scanning plugins without conflict, though it will often stop threats before
they reach those layers.

### Will this ban Cloudflare?

No. IP resolution first verifies that the incoming connection originates from a 
genuine Cloudflare IP range before trusting the `HTTP_CF_CONNECTING_IP` header. 
Traffic not arriving from a verified Cloudflare range will use `REMOTE_ADDR` or `
HTTP_X_FORWARDED_FOR` instead.

### Is the Ghost Purge review queue safe for WooCommerce sites?

The scan includes a WooCommerce order guard — it will never flag or delete any subscriber
account that has at least one associated order. However, you should review your 
registration flow before enabling this feature, especially if users commonly register
without a first or last name.

### Does this work on WordPress Multisite?

Banning and lockout transients operate per-site. On uninstall, the plugin cleans
up all data across every site in the network.

## Beoordelingen

Er zijn geen beoordelingen voor deze plugin.

## Bijdragers & ontwikkelaars

“Nullis Shield” is open source software. De volgende personen hebben bijgedragen
aan deze plugin.

Bijdragers

 *   [ Edward Samuel (Enigmaking) ](https://profiles.wordpress.org/countteddy/)

[Vertaal “Nullis Shield” in je eigen taal.](https://translate.wordpress.org/projects/wp-plugins/nullis-shield)

### Interesse in ontwikkeling?

[Bekijk de code](https://plugins.trac.wordpress.org/browser/nullis-shield/), haal
de [SVN repository](https://plugins.svn.wordpress.org/nullis-shield/) op, of abonneer
je op het [ontwikkellog](https://plugins.trac.wordpress.org/log/nullis-shield/) 
via [RSS](https://plugins.trac.wordpress.org/log/nullis-shield/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.3.0

 * Security: Cloudflare IP resolution now supports IPv6 ranges in addition to IPv4.
 * Security: Repeat offenders now receive escalating lockouts (1h  6h  24h  48h 
   across a 30-day strike window) instead of a flat 48-hour ban.
 * Reliability: Block counter now uses `INSERT ... ON DUPLICATE KEY UPDATE`, fixing
   a race condition where the counter could silently fail to increment if the option
   row didn’t already exist.
 * Reliability: Lockout responses now include a `Retry-After` header, computed from
   the stored ban expiry rather than reading transient internals — correct whether
   or not an object cache (Redis/Memcached) is active.
 * Behaviour change: Ghost Purge no longer deletes accounts automatically. It now
   flags likely-spam accounts (no name, no orders, and a registration IP the bouncer
   has already caught) into a review queue; deletion requires explicit admin approval
   from the dashboard.
 * Removed: The optional telemetry toggle has been removed from this release. No
   network calls are made by this plugin.
 * Security: `X-Forwarded-For` is no longer trusted by default — it was previously
   accepted unconditionally, letting an attacker spoof it to evade bans or frame
   another IP. It’s now only trusted if the site owner explicitly declares a reverse-
   proxy range via the new `nullis_shield_trusted_proxies` filter.
 * Extensibility: Added `nullis_shield_ban_duration`, `nullis_shield_min_human_time`,`
   nullis_shield_max_token_age`, `nullis_shield_log_ip_format`, and `nullis_shield_trusted_proxies`
   filter hooks.

#### 1.2.0

 * Security: IP resolution now validates that `HTTP_CF_CONNECTING_IP` originates
   from a genuine Cloudflare IP range before trusting it. Spoofed proxy headers 
   are ignored.
 * Security: Registration timestamp is now server-signed via WordPress nonce, preventing
   forgery by bots.
 * Security: IP lockout keys now use SHA-256 instead of MD5.
 * Security: `register_setting()` now enforces strict `yes/no` sanitization callbacks.
 * Security: Dashboard `render()` callback now re-verifies `manage_options` capability.
 * Security: All `target="_blank"` links now include `rel="noopener noreferrer"`.
 * Reliability: Block counter now uses an atomic SQL increment to prevent race conditions.
 * Reliability: Deactivation hook now correctly clears the scheduled cron event.
 * Reliability: Uninstall is now multisite-aware and cache-layer aware.
 * Reliability: Ghost Purge window extended to 7 days; WooCommerce order guard added;
   batch cap of 200 users per run prevents timeouts.
 * UX: All inline styles moved to `admin.css`; CSS custom properties introduced 
   for brand colour.
 * Accessibility: `:focus-visible` ring added to all dashboard links; WCAG AA compliant.

#### 1.1.2

 * Added 48-hour IP lockout.
 * Added Spam User Sniper (Ghost Purge) — internal staging release.

#### 1.0.0

 * Initial release.

## Meta

 *  Versie **1.3.0**
 *  Laatst geüpdatet **1 dag geleden**
 *  Actieve installaties **Minder dan 10**
 *  WordPress versie ** 6.0 of nieuwer **
 *  Getest t/m **7.0.4**
 *  PHP versie ** 8.0 of nieuwer **
 *  Taal
 * [English (US)](https://wordpress.org/plugins/nullis-shield/)
 * Tags
 * [anti-spam](https://nl.wordpress.org/plugins/tags/anti-spam/)[bot blocker](https://nl.wordpress.org/plugins/tags/bot-blocker/)
   [firewall](https://nl.wordpress.org/plugins/tags/firewall/)[honeypot](https://nl.wordpress.org/plugins/tags/honeypot/)
   [security](https://nl.wordpress.org/plugins/tags/security/)
 *  [Geavanceerde weergave](https://nl.wordpress.org/plugins/nullis-shield/advanced/)

## Waarderingen

Er zijn nog geen beoordelingen ingediend.

[Je beoordeling](https://wordpress.org/support/plugin/nullis-shield/reviews/#new-post)

[Bekijk alle beoordelingen](https://wordpress.org/support/plugin/nullis-shield/reviews/)

## Bijdragers

 *   [ Edward Samuel (Enigmaking) ](https://profiles.wordpress.org/countteddy/)

## Ondersteuning

Iets te melden? Hulp nodig?

 [Het supportforum bekijken](https://wordpress.org/support/plugin/nullis-shield/)