
RankShield defends your site against the bot attacks that quietly damage your search rankings and waste your ad spend:
A live security dashboard shows protection status, threats stopped, the per-URL attack story, and your ad click-fraud overview.
Plans: RankShield is free to install and use as a full monitoring console — it detects ranking attacks, ad click-fraud, and AI-agent traffic, and shows you everything on a live dashboard. Active blocking is a paid upgrade you can turn on in one click from the Plans tab:
This plugin connects to the RankShield protection service (an external SaaS operated by SEO Elite Agency) to detect and block attacks. Detection and threat intelligence run on the RankShield servers; the plugin enforces the decisions on your site.
Service: RankShield API — https://sea-shield-production.up.railway.app
What is sent, and when:
* On each page view, the plugin sends anonymized behavioral signals (time on page, mouse/scroll/keystroke counts, a bot score, the request URL/path, and — for visitors arriving from a paid ad — the ad click identifier such as gclid) so attacks can be scored. The visitor’s IP is read server-side for attribution and is never exposed in the browser.
* Periodically, the plugin requests the current block rules and your protection dashboard data using your site’s API key.
* Once a day, the plugin reports its own version and your WordPress and PHP versions (no personal data) so update availability and compatibility can be tracked.
* When an attack is confirmed on your site, the attacker’s network indicator (e.g. IP / IP range) is contributed to the RankShield Network (RankShield’s shared threat-intelligence network) so other protected sites can be defended — this is how the network protects everyone. Paid plans additionally receive the full RankShield Network feed for instant immunity.
* If the plugin’s integrity monitoring detects site tampering (for example a hidden or malicious plugin, injected code, or an executable file placed in the uploads folder), it reports the detection — the affected file path and a de-fanged indicator, never your file contents — to the RankShield Network so the same attack can be recognized on other protected sites. Requests to decoy “honeypot” paths that no real visitor would ever request similarly contribute the probing source’s network indicator. No files on your site are ever modified or deleted automatically.
* Your API key is used to authenticate these requests and is never exposed to the public front-end.
* When the paid Speed Optimization module’s “Remove Unused CSS” feature is enabled, the plugin sends the public URLs of your own pages to the RankShield service, which renders them and returns only the CSS each page uses. No visitor data is sent, and the service only accepts URLs on your registered domain.
* When “Self-host Google Fonts” is enabled, the server downloads your Google Fonts CSS/files once from fonts.googleapis.com / fonts.gstatic.com so your visitors never contact Google (Google’s terms: https://developers.google.com/fonts/terms). The YouTube facade loads video thumbnails from i.ytimg.com in the visitor’s browser, exactly as a normal embed would.
* When the “Vulnerability Scan” module is enabled (off by default), once a day the plugin sends the slugs and version numbers of your installed plugins/themes plus your WordPress version to /api/wordpress/vulncheck so the service can report which have a known published vulnerability. Slugs and versions only — no file contents, no visitor data. Virtual-patch exploit-blocking rules ride the existing rules request (no extra call).
This service is required for the plugin to function. By installing and activating the plugin you agree to the RankShield Terms of Service and Privacy Policy:
* Terms of Service: https://portal.seoeliteagency.com/terms
* Privacy Policy: https://portal.seoeliteagency.com/privacy