WordPress 6.2+PHP 7.4+GPL on WordPress.org

Security one layer above WordPress.

Every security plugin runs inside the site it protects. When the site is taken over, so is the plugin. Nivoli Edge runs at Cloudflare's edge: attacks are refused before they reach your server, and the settings that refuse them cannot be switched off from inside a hacked WordPress.

Start a 14-day trial Install the free plugin Card at checkout, nothing charged for 14 days.
Layer 1 Visitors, bots, attackers Every request, from everywhere. About half of them are not people.
Layer 2, Nivoli Edgerefuses before PHP Twelve shields, three locks, the page cache Hostile traffic stops here. Settings live here, behind an email the site does not hold.
login floodXML-RPCstray PHPenumerationcountry lockchange lockinstall lock+ 6 more
Layer 3 Your server, your WordPress Renders only what the edge lets through and does not already have.
reaches your serverrefused at the edge
1.11M
attacks and junk requests refused before PHP, 30 days
0
shield changes or plugin installs without a click on the owner's email
61%
of all requests answered at the edge, never reaching the server
307 ms
HTML arrives; the server alone takes about 517 ms

One real month on one real production site, measured at the edge. Not averages or projections; your numbers depend on traffic shape and cache fit.

The edge security layer

Three things a security plugin cannot be.

Wordfence and Sucuri run inside the site they protect. This runs one layer up, at the edge, and the site cannot reach it.

Refused before PHP

Your server never boots PHP to turn a request away. Twelve shields, all on every plan.

  • Login flood, 10 per 10 min 429 at the edge
  • Comment and search floods 429 at the edge
  • XML-RPC 410 cached
  • Stray .php requests monitor, then 404
  • User lists, readme, installer, debug.log monitor, then 404
  • Path traversal, any encoding 404, on by default
  • Five refusals, then the whole scan 403 for 10 min
  • Login from other countries 403
  • wp-admin from unknown addresses 403
  • AI crawlers 403
  • Missing security headers added
What each shield refuses →

Nothing inside can turn it off

Weakening a shield, installing a plugin, editing a theme file: each waits for a click on a link mailed to the license holder. The site does not hold that address.

FROM NIVOLI EDGE · TO OWNER@YOURSITE.COM
Confirm this change on yoursite.com?
- stray PHP shield: block
+ stray PHP shield: off
requested 14:02 from 185.220.101.4, Frankfurt
Apply this change Not you? Ignore it. Nothing changes.
How a takeover is contained →

Every refusal leaves a line

Who did what, from where, on the Locks page and in your inbox as it happens. A monthly report; for agencies a posture matrix across every site.

14:02:11 REFUSED install plugin wp-file-manager from 185.220.101.4
14:02:40 REFUSED shield change stray-php block→off, mail sent
14:03:05 REFUSED theme editor write functions.php
14:09:52 CONFIRMED nothing, link unused, window closed
14:10:00 NOTE 3 attempts, 1 address, owner notified
The numbers →

Takeovers

If a plugin gets hacked, the edge still answers to you.

One plugin with a hole hands an attacker an administrator account, and no shield stops that: it arrives as a normal request. What happens next is where the layers differ.

MINUTE 0

An intruder gets admin

Through a vulnerable plugin. Every security plugin is now a settings page they own.

inside the site
MINUTE 1

They try to switch a shield off

The edge refuses. Weakening protection waits for a click on the owner's email, which WordPress cannot redirect.

refused, mail sent
MINUTE 2

They try to install a backdoor

Plugin installs, uploads, updates and the file editors are refused site-wide until a 15-minute window is opened by email.

refused, named in the log
MINUTE 3

You know, and they are stuck

Three refusals in your inbox with time and address. The site keeps serving. The compromise stays where it landed.

contained

Pages from the edge

The same edge that protects the site keeps it up and fast.

Surgical purge

Every page carries tags for what built it. Saving a post refreshes only the pages that feature it; the rest of the cache stays hot. No Enterprise plan needed.

Origin shield

When your server errors or goes down, visitors keep getting the last good copy of every cached page, for a day on Shield and a week from Shield Plus. You get an email when it engages and when it recovers.

Static assets

Stylesheets, scripts and fonts on addresses that change when you purge, so no browser holds a stale file.

Numbers

Hit rate, bandwidth, audience without a tracking script, most-missed URLs, a Recent 404s page with one-click redirect or block. Inside WP admin.

yoursite.com, last 48 hoursserved from edge
48h agoserver down 09:00 to 11:00now

Origin shield engaged for 2 h 04 min. 100% of cached pages kept serving; visitors saw no error. Two emails: engaged, recovered.

Free versus managed

The plugin is free. The edge is what you connect.

Everything that runs on your own server is free, GPL, any number of sites, nothing phones home. The managed edge is the part you cannot self-host.

Free plugin

On your own infrastructure. No account.

  • Security check of the WordPress install with one-click hardening fixes
  • Image URL rewriting through your own Cloudflare zone, rules and size mapping
  • Page-cache tag headers and surgical purge to Fastly, Cloudflare Enterprise or a webhook
  • Fake-image detection and repair, heaviest-uploads scan with Tinify
  • Coverage audit, prewarm on save, purge-failure alerts, WP-CLI

Managed edge

Connect with a key. Three plans sized by sites and pageviews; every shield on every plan.

  • Twelve shields refused before PHP, three locks a takeover cannot undo
  • Whole pages from the edge, origin shield, versioned assets
  • URL rules, Recent 404s, per-path cache duration, query-param manager
  • Edge insights, monthly report, alerts when the origin goes down
  • Agency: ten sites on one key, the fleet console, white-label reports
Managed Images, optional add-on: right-sized WebP and AVIF variants from the edge, in blocks that stack. Without it your images serve from your server, untouched.

Install the plugin. Connect the edge. Sleep.

The setup overview inside the plugin walks the six steps: the key, the two DNS records that put the site behind the edge, the shields on in one click, the locks on in one click, the report. Most sites are done in fifteen minutes.

# or from the command line
wp plugin install nivoli-edge --activate
wp nivoli-edge activate cfimg-xxxx-xxxx-xxxx --enable
# provisions the tenant, tests an image, flips the switch

Inside WP admin

Every number the edge measures, where you already work.

Real panes from a live production site, last 14 to 30 days. Click any one to look closer.