Threat protection

What we block — and what you can see.

A WordPress site on the open internet is probed constantly: bots guessing passwords, scanners hunting for known holes, crawlers scraping whatever they can. Most hosts don’t tell you. We stop it at the front door and show you the count.

Blocked across the sites we host · last 30 days

Bot, scanner and login attacks turned away at the origin, before they reach any site.

How it works

Layers, each doing one job well.

  1. 01

    Bots and scanners turned away at the origin

    Recon bots and exploit scanners are identified and refused at the server, before WordPress ever runs. They never touch your site, your database, or your PHP — which also keeps your site fast under attack.

  2. 02

    Login brute-force blocked

    Repeated password guessing against your login is stopped, and the usual back doors attackers try first are hardened. Two-factor authentication is available for every account that logs in.

  3. 03

    Malware protection and a hardened setup

    Malware scanning and a hardened WordPress configuration are part of the platform, not a plugin you have to remember to renew — and every site runs isolated from every other, so one site’s problem is never your problem.

  4. 04

    Free SSL, always renewed

    Every site is served over HTTPS with a certificate that renews itself. We monitor expiry anyway, so it can’t lapse quietly.

  5. 05

    Good bots still get through

    Blocking is precise. Search engines, real browsers, and the services you rely on are on a safelist — protection never means disappearing from Google.

What you see

In your dashboard, not in a brochure.

This is the part most hosts skip: showing you. Threat protection has its own screen in your dashboard.

  • “Threats blocked” — the number of bot and scanner attempts turned away from your site, per day, over the last 30 days
  • Your login-security status in the site review, including whether two-factor is on for the accounts that should have it
  • The same protection view for every site you have with us
app.siteschema.com/app/bot-activity
Bot & scanner protection
Automated bots and vulnerability scanners we turned away from your sites — before they could slow anything down.
Blocked for you
1,686unwanted visits
across the last 7 days
Your sites protected
2
every site is shielded by default
SiteBlocked
yourbusiness.com1,284
shop.yourbusiness.com402
Example of the client “Threats blocked” screen. Sample data.
Straight answer

AI crawlers — including the ones you might want

A growing share of the traffic we turn away is AI scrapers and unwanted crawlers. Many are blocked by default alongside the other bots. But not every AI bot is unwanted — some businesses want to be findable in AI search the same way they want to be on Google — so this is a choice, not a blanket rule.

Bot and scanner protection can be tuned per site: which crawlers are refused and which are allowed. If you have a view on AI crawlers, tell us and we’ll set it that way. If you don’t, the sensible default already protects you.

FAQ

Questions people ask.

Do I need a security plugin as well?
Usually not for the basics — bot blocking, login hardening, malware protection, and SSL are handled by the platform. If you already run one you like, it can stay; we’ll make sure it isn’t doubling up or slowing you down.
Will blocking bots hurt my SEO?
No. Search engines and legitimate crawlers are on the safelist. Blocking is aimed at attackers and scrapers, not at anything that helps you be found.
What about AI crawlers?
Many are blocked by default. It’s adjustable per site — if you want particular AI bots allowed (for example to appear in AI search), say so and we’ll set it.
What if a site is hacked anyway?
No protection is absolute. If something gets through, we have your nightly backups to restore from and we handle the clean-up as part of looking after your site.
Where does the “threats blocked” number come from?
It’s counted at the server for each site and shown per day in your dashboard. The figure on our homepage is the same count, added up across every site we host and updated every fifteen minutes.
Is two-factor authentication required?
It’s available for every account and we recommend it for anyone who can log into your site. Your dashboard shows whether it’s on.
Read more

Protected — and you can see it.

Bot and attack blocking, login hardening, malware protection, and SSL are included on every plan.