BACK TO DIRECTORY



DawsonyWeb – Security Shield provides focused controls for comment spam, XML-RPC and REST API access. Choose the settings that suit your site. It is not a malware scanner, firewall service or a substitute for updates and backups.
Comment Protection
- Master switch to completely disable all comments (form, REST API, XML-RPC, feeds)
- Invisible honeypot field to trap bots
- Minimum comment length enforcement
- Block all links or cap links per comment
- Require login to comment
- Keyword/phrase blocklist
API & REST Hardening
- Disable XML-RPC entirely (removes X-Pingback header too)
- Hide
/wp/v2/usersendpoints from guests while keeping them available to signed-in users - Require authentication for all REST API requests
- Optionally disable the REST API completely
- Block author enumeration via
/?author=N
Spam Rules
- Per-IP comment rate limiting (configurable max and time window)
- IP address blocklist — blocked IPs receive a 403 on any front-end request
- Rolling activity log (last 200 events)
Privacy
When activity logging is enabled, the plugin stores up to 200 blocked-event entries locally, including IP address, time and reason. Administrators can clear the log or turn logging off. Comment rate limits use temporary counters. No log data is sent to DawsonyWeb or a third-party service. Uninstalling removes the plugin settings, logs and rate-limit transients.
Screenshots

Overview of configured comment and API controls.

API settings with explanations of compatibility impacts.