Signup Shield

Stops the wp-signup.php bot flood dead. No captcha, no paid service, no false positives on real people.

v2.1.0

What it does

Must-use plugin

Loads before everything else and refuses the request at the earliest possible point.

.htaccess hard block

Generated for you, so most attempts never reach PHP at all.

Firewall rules

Ready-made ConfigServer (CSF) regex rules to ban repeat offenders at the network edge.

ModSecurity ruleset

Drop-in rules for servers running mod_security.

Edge rules

Copy-paste Cloudflare expressions for the last layer.

Live counter

A dashboard widget showing exactly what was blocked and when.

If you run WordPress Multisite, you already know the problem: bots hammer wp-signup.php thousands of times a day, filling your database with junk accounts and your logs with noise.

Signup Shield blocks them in layers — a must-use plugin that never loads for a bot, an .htaccess rule that rejects the request before PHP starts, firewall regex rules, and optional edge rules. On our own network it logged over 16,800 blocked hits in the first three days, with no legitimate registration ever touched.

Specifications

Blockswp-signup.php, wp-activate.php, xmlrpc registration
Layersmu-plugin, .htaccess, CSF, ModSecurity, edge
RequiresWordPress 6.0+, PHP 7.4+
MultisiteFully supported

Questions about this product

Do real users ever get blocked?

No. The rules target the signup endpoints specifically, and registration by an invited or admin-created user is untouched.

Do I need all the layers?

No. The mu-plugin alone stops the flood; the rest is for people who want the traffic gone before it reaches PHP.

Leave a comment

Your email address will not be published. Required fields are marked *

Release notes, once a month

New products, major updates and the occasional deep-dive. No spam, unsubscribe in one click.