RankShield — Ranking & Ad-Spend Attack Protection

Descripció

RankShield defends your site against the bot attacks that quietly damage your search rankings and waste your ad spend:

  • CTR manipulation & sitemap-sweep attacks — bots that pull your sitemap and run your pages through fake impressions and fast click-and-bounce sessions to poison Google’s engagement signals.
  • Ad click fraud — bots and competitors clicking your Google Search Ads to drain your budget. RankShield ties on-site behavior to each paid click and builds a ready-to-apply IP exclusion list for your ads team.
  • Real-customer safety first — flagged traffic gets a one-second JavaScript challenge, never a hard block. Logged-in users and visitors who already passed are never challenged. Shared/residential networks are never auto-excluded.
  • Speed Optimization (paid plans) — page caching that runs AFTER the firewall inspects each request, native lazy loading, self-hosted Google Fonts with preloading, CSS/JS optimization, and service-powered Remove Unused CSS. Ships in Safe Mode (observe-only) so you see exactly what would change before going live, and every optimizer fails open.
  • Virtual Patching & security modules (paid plans) — an exploit-blocking layer that stops SQL-injection, XSS, object-injection and file-upload attacks against known-vulnerable plugins in the hours before the author ships a fix, plus daily CVE scanning, login-brute-force visibility, user-enumeration blocking, and XML-RPC abuse control. Every module is off/observe/protect by your choice, network-validated in shadow first, and fails open — it can never take your site down.

A live security dashboard shows protection status, threats stopped, the per-URL attack story, and your ad click-fraud overview.

Plans: RankShield is free to install and use as a full monitoring console — it detects ranking attacks, ad click-fraud, and AI-agent traffic, and shows you everything on a live dashboard. Active blocking is a paid upgrade you can turn on in one click from the Plans tab:

  • Free — detection + the full security & analytics dashboard. See every attack; contribute to and benefit from the shared RankShield Network threat intelligence.
  • Monitoring — $39/mo — everything in Free, plus RankShield actively blocks bot, sitemap-sweep, and spoofed-AI-agent attacks (the customer-safe one-second challenge), and gives you full ad click-fraud monitoring (every wasted click, fraud source, and the exact IP exclusion list you could apply).
  • Full Protection — $99/mo — everything in Monitoring, plus active blocking of datacenter bots clicking your paid ads, the ready-to-apply Google Ads IP exclusion list unlocked, and RankShield Network instant immunity (attackers confirmed on any other protected site are blocked on yours too).

External services

This plugin connects to the RankShield protection service (an external SaaS operated by SEO Elite Agency) to detect and block attacks. Detection and threat intelligence run on the RankShield servers; the plugin enforces the decisions on your site.

Service: RankShield API — https://sea-shield-production.up.railway.app

What is sent, and when:
* On each page view, the plugin sends anonymized behavioral signals (time on page, mouse/scroll/keystroke counts, a bot score, the request URL/path, and — for visitors arriving from a paid ad — the ad click identifier such as gclid) so attacks can be scored. The visitor’s IP is read server-side for attribution and is never exposed in the browser.
* Periodically, the plugin requests the current block rules and your protection dashboard data using your site’s API key.
* Once a day, the plugin reports its own version and your WordPress and PHP versions (no personal data) so update availability and compatibility can be tracked.
* When an attack is confirmed on your site, the attacker’s network indicator (e.g. IP / IP range) is contributed to the RankShield Network (RankShield’s shared threat-intelligence network) so other protected sites can be defended — this is how the network protects everyone. Paid plans additionally receive the full RankShield Network feed for instant immunity.
* If the plugin’s integrity monitoring detects site tampering (for example a hidden or malicious plugin, injected code, or an executable file placed in the uploads folder), it reports the detection — the affected file path and a de-fanged indicator, never your file contents — to the RankShield Network so the same attack can be recognized on other protected sites. Requests to decoy «honeypot» paths that no real visitor would ever request similarly contribute the probing source’s network indicator. No files on your site are ever modified or deleted automatically.
* Your API key is used to authenticate these requests and is never exposed to the public front-end.
* When the paid Speed Optimization module’s «Remove Unused CSS» feature is enabled, the plugin sends the public URLs of your own pages to the RankShield service, which renders them and returns only the CSS each page uses. No visitor data is sent, and the service only accepts URLs on your registered domain.
* When «Self-host Google Fonts» is enabled, the server downloads your Google Fonts CSS/files once from fonts.googleapis.com / fonts.gstatic.com so your visitors never contact Google (Google’s terms: https://developers.google.com/fonts/terms). The YouTube facade loads video thumbnails from i.ytimg.com in the visitor’s browser, exactly as a normal embed would.
* When the «Vulnerability Scan» module is enabled (off by default), once a day the plugin sends the slugs and version numbers of your installed plugins/themes plus your WordPress version to /api/wordpress/vulncheck so the service can report which have a known published vulnerability. Slugs and versions only — no file contents, no visitor data. Virtual-patch exploit-blocking rules ride the existing rules request (no extra call).

This service is required for the plugin to function. By installing and activating the plugin you agree to the RankShield Terms of Service and Privacy Policy:
* Terms of Service: https://portal.seoeliteagency.com/terms
* Privacy Policy: https://portal.seoeliteagency.com/privacy

Instal·lació

  1. Install and activate the plugin.
  2. Open RankShield Dashboard and click Activate free protection — no account or payment required. (If you have a paid plan, paste your API key instead.)
  3. Protection begins immediately. Open RankShield Dashboard to see live status.

PMF

Do I need a paid account?

No — the plugin is free to install and use as a full monitoring console: it detects ranking attacks, ad click-fraud, and AI-agent traffic and shows you everything on a live dashboard, and it contributes to the shared RankShield Network. Active blocking is a paid upgrade: the $39/mo Monitoring plan actively challenges bot, sitemap-sweep, and spoofed-AI-agent attacks, and the $99/mo Full Protection plan additionally blocks the datacenter bots clicking your paid ads, unlocks the ready-to-apply Google Ads IP exclusion list, and adds full RankShield Network immunity. You can upgrade in one click from the Plans tab; cancel anytime.

Will it block my real customers?

No. RankShield uses a one-second JavaScript challenge instead of hard blocks, never challenges logged-in or already-verified visitors, and never auto-excludes shared/residential networks. Clicks that convert are always treated as real customers.

Does it work without Cloudflare?

Yes. The plugin is fully standalone; an optional Cloudflare edge worker is a bonus, not a requirement.

Does page caching bypass the firewall?

No — and this is the point of RankShield Speed. The firewall inspects every request BEFORE the cache is allowed to answer; challenged visitors never receive cached HTML, and responses for flagged requests are never stored.

Ressenyes

No hi ha ressenyes per a aquesta extensió.

Col·laboradors i desenvolupadors

«RankShield — Ranking & Ad-Spend Attack Protection» és programari de codi obert. La següent gent ha col·laborat en aquesta extensió.

Col·laboradors

Registre de canvis

2.17.2

  • Connecting Google is faster and clearer: after you approve access with Google you now come straight back to your WordPress dashboard (no more landing on a separate login screen), the connection registers immediately, and a confirmation appears right away.
  • Connections: the list of your Google accounts/properties now loads on its own without holding up the page, so the Connections tab opens instantly and each dropdown fills in a moment later instead of making you wait.
  • Clearer status while data loads: tabs waiting on Google now say your account is connected and the data is being retrieved (it can take a few minutes to populate) instead of looking like nothing happened.
  • Security: connecting Google no longer passes your site key through the sign-in link.

2.17.1

  • Automatic updates: RankShield now keeps itself up to date from WordPress.org by default, so your protection never falls behind (turn it off with the standard per-plugin control or the rankshield_self_auto_update filter).
  • Cleaner console: the module status labels are now a restrained, professional style — no more colored status dots.

2.17.0

  • Much faster console: every tab now paints instantly and streams its live data in behind a brief loading placeholder, instead of waiting on Google/RankShield before showing anything. Pages that previously felt slow or occasionally failed to load — Ad Protection, Connections, SEO ROI, Audience — now open immediately, and a slow or unreachable backend no longer blocks the page.
  • Connections: pick the right account when a Google login has more than one. Search Console and Google Analytics now let you choose the correct property, and Google Ads lets you choose the correct account (once the Ads API access is approved). Fixes reports occasionally showing data for the wrong business when a login manages several accounts.
  • Reliability: connection status and sign-in links are cached briefly and failed requests back off, so reopening a tab no longer re-hits the network on every load.

2.16.1

  • Faster console: the dashboard data feed now loads in a fraction of the time, so the Dashboard and Live Traffic tabs open reliably and tab-to-tab navigation is instant even on busy sites.
  • Modules tab redesign: the Off / Observe / Protect controls are now a clean instrument-grade segmented switch that matches the rest of the console, with clear live status for every module.

2.16.0

  • NEW: Virtual Patching (paid plans) — an exploit-blocking layer that inspects incoming requests for SQL-injection, XSS, PHP object-injection, path-traversal and file-upload/code-execution payloads and blocks attacks against known-vulnerable plugins in the hours between a vulnerability going public and the author shipping a fix. Network-validated (every rule proves itself in shadow across the RankShield Network first), only fires when the affected plugin is installed at an affected version, never hard-blocks logged-in users, and fails open.
  • NEW: Security modules with a Modules tab — daily vulnerability (CVE) scanning, login-brute-force visibility (lockout impossible by design), user-enumeration blocking, and XML-RPC abuse control. Each module is independently Off / Observe / Protect; all default to off or observe, so updating changes nothing until you opt in.
  • WooCommerce-aware: payment webhooks and cart/checkout flows are never inspected or challenged, so a sale can never be blocked.
  • Includes the full Speed Optimization module (page caching, lazy loading, self-hosted Google Fonts, CSS/JS optimization, Remove Unused CSS) introduced in 2.15.

2.15.6

  • Speed tab: new Speed Test at the bottom — scores your homepage (A–F, 0–100), shows response time / page weight / render-blocking counts, and lists the exact optimizations to turn on, ranked by impact.

2.15.3

  • Speed tab: new «Apply recommended settings» button — one click turns on the best speed optimizations (all fail-open and self-disabling on any page they would break) so you don’t have to configure each option.

2.15.2

  • Speed tab: toggle switches replace checkboxes, and the interface copy is cleaned up to match the rest of the console.

2.15.1

  • Fix: File & Content Integrity monitoring no longer false-flags legitimate libraries (Google Site Kit’s API client, EWWW Image Optimizer, and similar). The injection detector now requires the front-end injection surface (wp_head + admin-ajax) that defines real malware, skips vendored library trees, and matches executable calls precisely — so it still catches hidden and self-injecting malware while eliminating false positives on trusted plugins.

2.15.0

  • NEW: Speed Optimization module (paid plans) — firewall-first page caching, native lazy loading with LCP protection, missing image dimensions, YouTube facade, self-hosted Google Fonts with preloading, CSS minify/async, JS defer/delay, and service-powered Remove Unused CSS.
  • Safe Mode ships ON: every optimization runs observe-only and reports what it WOULD change until you flip it live.
  • Every optimizer fails open — an error always serves the original page. RankShield’s protection scripts are never deferred or delayed.

2.14.0

  • New: File & Content Integrity monitoring — detects and reports website tampering (hidden or malicious plugins, injected code, altered core files, executable files in uploads) so a site compromise is caught in hours instead of going unnoticed for months. Detection and reporting only by default; no files are ever changed automatically.
  • New: Passive honeypot — decoy paths that flag attackers probing your site and contribute the attacker’s network indicator to the RankShield Network so other protected sites are defended too.

2.13.1

  • Audience page never goes blank: if Google Analytics is connected but not returning data (e.g. wrong property), it now falls back to your real first-party audience data instead of a «gathering data» message.
  • GA4 property selector restyled to match the dashboard theme.

2.13.0

  • Google Analytics: you can now pick which GA4 property to report on. If your Google login has several businesses, the Connections tab shows a property selector so the Audience tab always shows the right one (previously it auto-picked a property, which could be the wrong business).

2.12.2

  • Agents and Audience pages now clearly show a «Live» indicator and explain that all numbers are your real data that fills in automatically — so an empty page reads as «no activity yet,» never as placeholder.

2.12.1

  • Polish: fixed a stray character next to the agent name in the recent-captures list on the Agents tab.

2.12.0

  • New «Agents» tab: a comprehensive AI-agent monitoring view that’s populated from the moment you install it — the 14 AI agents RankShield tracks (ChatGPT, Claude, Perplexity, Gemini, Copilot, GPTBot and more) with their operator, type, and how each is verified, plus live activity, the data categories captured, and the full agent journeys. You don’t have to wait for an agent to visit to see what’s covered.
  • Audience page now shows your real first-party audience data (sessions, where visitors come from including AI assistants, and where they are) even before you connect Google Analytics — no more empty page.

2.11.0

  • Agent captures now show the full journey: every AI agent’s entire visit is stitched into one record — the pages it moved through and exactly what data it read at each step, with duration, page count, and a warning when it reached PII or customer data. RankShield never blocks AI agents (which protects your search rankings and AI-referred customers) — it welcomes them, verifies who they really are, and puts the whole visit on record, post-quantum signed.

2.10.0

  • New «What AI agents captured» panel on your dashboard: see not just how many AI agents (ChatGPT, Claude, Perplexity, Gemini, GPTBot and more) read your pages, but exactly which data categories each one accessed — pricing, product data, reviews, form/PII fields and more. Each capture is verified and post-quantum-signed server-side so the record can’t be forged. Data categories only, never your customers’ raw data.

2.9.2

  • Edge Protection: the «Get Edge Protection» button now opens a live, secure checkout page for the $39/mo edge add-on. You can still set your own purchase link on the Edge tab to override it.

2.9.1

  • SEO ROI report: a «what people search to find you» section — live search terms from real visitors (when the engine passes them) plus your top Google ranking queries from Search Console. Each customer journey now shows the search term and the visitor’s location, and a lead is counted when a visitor reaches your contact or booking page.
  • More accurate visitor locations: the journey + hot-spots map now geolocates the real visitor rather than the relaying server, so «where your visitors are» reflects your actual audience.
  • Edge Protection: set your own purchase link for the «Get Edge Protection» button right from the Edge tab.

2.9.0

  • New Edge Protection tab: an optional top-tier upgrade that adds a Cloudflare network-edge layer on top of your existing protection, so attacks are stopped before they reach your server. Your site stays fully protected at the origin without it; setup is fully managed.

2.8.4

  • Update notices: when a new version is available on WordPress.org, the RankShield console now shows a clear notice with a link to review what changed, so your developer can update on their own schedule. RankShield never auto-updates and every release is backward-compatible, so your site won’t break.

2.8.3

  • New customer-journey view in the SEO ROI report: follow each visitor’s page-by-page path — from where they came (e.g. ChatGPT) to the blog they landed on, through your site, to the page where they converted — with their location and outcome. The «where your visitors are» hot-spots are now visual heat bars.

2.8.2

  • New blog lifecycle in the SEO ROI report: for each blog post, see how many days it took to get picked up by AI assistants and by search engines after you published it, which AI tools (ChatGPT, Claude, Perplexity) are citing it, and — with Google Search Console connected — the exact queries it ranks for and its position.

2.8.1

  • New SEO ROI report: see your visitors and leads broken down by where they came from — including AI assistants like ChatGPT, Claude, and Perplexity — plus a blog-to-engaged-to-converted funnel, per-blog performance with the top traffic source, where your visitors are located, and month-over-month trends.
  • Form submissions now count as conversions on any page (not just paid-ad visits), and a new «Conversion pages» setting lets you mark your high-value lead pages.

2.8.0

  • New: SEO attribution foundation. RankShield now records where each visitor actually came from — including AI assistants like ChatGPT, Claude, and Perplexity, alongside Google, Bing, and social — plus their on-site journey, page context (which blog post, when published), and approximate location. This powers the upcoming SEO ROI & customer-journey reports.
  • Improvement: visit tracking is now far more reliable (captured ~2.5 seconds after load instead of only when the page is closed), so short visits are no longer missed.

2.7.3

  • Polish: fixed low-contrast headings in the console (some text was blending into the dark background), and stopped other plugins’ admin notices (e.g. FluentSMTP) from overlapping the RankShield dashboard.
  • Google connections now appear faster: a not-yet-connected Search Console / Analytics response is cached for only 90 seconds instead of 15 minutes, so a freshly connected account populates right away.

2.7.2

  • Lockout safety: RankShield now always lets the WordPress login page through. The firewall never challenges wp-login.php, registration, or your host’s one-click admin login, so you can never be locked out of your own site — even if your IP is mistakenly flagged. (Login security stays WordPress’s job; RankShield protects your rankings and ad spend.)

2.7.1

  • New Plans tab: upgrade to Monitoring ($39/mo) or Full Protection ($99/mo) in one click, right inside the plugin. Secure Stripe checkout; your plan activates automatically the moment payment completes — no license key to copy.
  • Clearer plan model: Free is a full monitoring console (see every attack). Monitoring ($39) actively blocks bot, sitemap-sweep, and spoofed-AI-agent attacks and gives you full ad click-fraud monitoring. Full Protection ($99) adds active blocking of the datacenter bots clicking your ads, the ready-to-apply IP exclusion list, and RankShield Network immunity.

2.7.0

  • New look: the whole console was rebuilt to RankShield’s instrument-grade design — a dark engineering canvas, a command-bar header with a live RankShield Network readout, and a cleaner full-width layout.
  • New live ledger on the Dashboard: watch your firewall’s real recent enforcement decisions stream in — datacenter ad-clicks challenged, spoofed agents blocked, ranking-attack bots stopped — each one sealed to the RankShield Network so every protected site is immunized.
  • New Audience tab: a full Google Analytics report — sessions, users, pageviews, engagement, a 90-day trend, top channels, top pages, devices, new-vs-returning visitors, and top countries.
  • Live Traffic is now a full SOC view: blocked-over-time chart, attack vectors, bot & AI-agent defense breakdown, top attacking networks, your most-attacked pages, and a live block feed.
  • Ad Protection is now agency-grade: real ad spend, fraud rate, a wasted-spend trend, fraud broken down by network and by campaign, exclusion effectiveness, and the ready-to-apply IP exclusion list.
  • Presentation only — no change to how protection works; all figures stay live from your account.

2.6.1

  • Two plans: Full Protection actively blocks bot ad-clicks and spoofed AI agents in real time; Monitoring shows you every threat and all your analytics without active blocking. (Existing protected sites are unchanged.)

2.6.0

  • New SEO dashboard: a full agency-grade Search Console report — clicks/impressions/CTR/position with period-over-period change, a 90-day trend, your biggest ranking winners and drops, «striking distance» keywords (quick wins), CTR opportunities, ranking distribution, top keywords and pages, plus devices and countries.
  • The console now uses the full screen width.

2.5.1

  • Real Google Ads spend: the dashboard now shows your actual ad spend, clicks, and average CPC for the month — pulled live from your linked Google Analytics property, no extra setup. (If your Google Ads account isn’t linked to Analytics yet, the dashboard shows the one-time step to enable it.)

2.5.0

  • New «Ad spend protected» figure and a real-time bot & AI-agent defense panel on the dashboard — see datacenter ad-bot clicks challenged, spoofed AI agents blocked, and verified agents allowed, all in dollars and counts.
  • One-click, zero-configuration setup: activate free protection and everything turns on automatically — no account, no settings.

2.4.2

  • Real-time ad-fraud defense: a paid-ad click (gclid/wbraid/msclkid) arriving from datacenter/cloud space is challenged the moment it lands — a real person passes the one-second check, a bot never reaches your page or wastes the click. Apple iCloud Private Relay and Cloudflare WARP users are exempt, so real customers are never affected.

2.4.1

  • AI-agent defense now verifies agents against each operator’s own official published IP ranges (delivered by the RankShield Network), in addition to reverse DNS — so agents that publish IP lists are accurately told apart from impersonators.

2.4.0

  • AI-agent defense: the firewall now tells real AI agents apart from impersonators. Verified agents (confirmed by reverse DNS) pass through untouched; bots spoofing a known AI agent get the one-second verification challenge. No effect on normal visitors.

2.3.3

  • Google Analytics 4: once connected, the dashboard now shows a live Audience panel — 90-day sessions, users, pageviews, engagement rate, a sessions-over-time chart, and your top traffic channels.

2.3.2

  • Google Search Console: once connected, the dashboard now shows a live Search performance panel — 90-day clicks, impressions, CTR, average position, a clicks-over-time chart, and your top-ranking keywords.

2.3.1

  • Dashboard now shows a 30-day «threats stopped» trend chart so you can see your protection at a glance.

2.3.0

  • Verify-challenge page now loads its CSS/JS through the WordPress enqueue system (wp_register/enqueue_style/script) instead of hardcoded tags.
  • Decision dedupe uses the object cache instead of transients (no wp_options row growth under heavy bot traffic).

2.2.0

  • Wordfence-style security console: Dashboard, Live Traffic, and Ad Protection sections.
  • Ad click-fraud protection with a copyable, ready-to-apply IP exclusion list.