Kapsule Protect / Site security

Your website is guarded around the clock, and one screen shows you so.

One screen tells you what is guarding your site right now, what last night's sweep read through, and what you can turn up whenever you want to. All of it runs from the day your site is created, on every plan, and every one of them was switched on for you.

Every protection here is included in your plan.

kpanel.kapsulehost.com/websites/brightwavestudio.co.nz/securityActive
Site protection

4 of 4 protections active

  • Certificate
  • Malware
  • Sign-in
  • Plugin versions
Last malware sweep13 August

Clean: 11,855 files read

Sweeps run on their own every night, on definitions refreshed the same night.

Sign-in protectionThe last thirty days
  • 930Guesses turned away
  • 10 a minuteThe most any one visitor gets

Five refusals and that address is turned away for the next hour.

WordPress checklist7 of 7
  • Editing code from the dashboard is off
  • The uploads folder runs nothing
  • The old remote interface is closed
  • Debug output is off
  • Sign-in keys are set
  • The database prefix is your own
  • The version file is removed
Already running

It was all switched on before you arrived.

All four of these are running on your site from its first day, and the smallest plan we sell gets exactly the same four as the largest.

  • A firewall that knows the attacks by nameThe open rule set the security industry maintains together runs in front of every single site here, with 624 rules live and 88 scanning tools recognised by name. A request that matches an attack is refused before your site runs anything.
  • A malware sweep every nightEvery file in your site is read every night, against definitions refreshed minutes beforehand, and you are emailed the moment anything turns up. On Managed WordPress the file is moved somewhere it cannot run for you.
  • Sign-in protection on WordPressYour WordPress sign-in page allows ten attempts a minute from any one visitor, and an address that keeps guessing after five refusals is turned away for the next hour. You can add a second factor to your own WordPress login, with ten single use recovery codes.
  • Your WordPress is hardened the day it goes onSeven settings that attackers count on are closed the moment WordPress is installed, from editing code inside the dashboard to the file that announces which version you are running. The panel shows you all seven passing on one line.
Yours to set

You decide exactly who reaches your site.

Everything above runs on its own. These four are yours to change whenever you want them changed, and each one takes effect in front of your site rather than inside it, so a visitor you turn away never reaches your pages at all.

  • Turn your protection up in a sentenceAsk Kora for more protection in plain words and it is applied in front of your site. There are five levels of strictness and every site starts on the balanced one, so an ordinary week asks nothing of you and a bad week is one message away.
  • Shut the door on an address or a countryBlock a single address, a whole range or a whole country, on any address format. Allow rules are always read before block rules, so somebody you trust is never caught by a sweep you wrote for somebody else.
  • Write your own rulesDescribe the rule you want and it is written for you, up to 25 a site. Each one can match on a visitor's address, the page they asked for, their browser, where they came from or their country, and each one can turn them away, wave them through, or simply keep a record.
  • Cap how fast anyone can askHold any one visitor to five, fifteen or forty requests a second, whichever suits your site, and set a tighter ceiling on any page that deserves one. Everybody else keeps browsing at full speed while the busy address waits its turn.
When you want a person

An engineer goes through your site, for a price you can read now.

The price of a full security review is on this page, in your own currency, before you speak to anybody. The work is the same review our own tools run every night, with a Kapsule engineer reading the result and writing you what to do about it.

  • A fixed price, in your currency, before you talk to anyone
  • A single charge, paid once
  • Covers the connection, the response headers browsers look for, the eight sensitive addresses attackers try first, and the WordPress checklist
  • Kora answers immediately, and a Kapsule engineer is with you inside 4 business hours
US$240Charged onceBook the auditThe price is right here, so you can order it in a minute.
The record

Every change to your security is written down.

Who did it, when they did it and where they were, kept for every site. If you share your account with a developer or an agency, this is the page that tells you exactly what changed and who changed it.

  • SSL certificate renewed
  • Malware sweep started
  • Address blocked
  • Security headers updated
  • Sign-in lockout enabled
  • Remote interface restricted
  • Application password created
  • Two factor sign-in enabled
Questions

Good questions, answered.

Do I need a security plugin as well?
The protection here sits in front of your site rather than inside it, so an attack is refused before WordPress, your theme and your plugins are ever asked to run. That is the layer a plugin cannot reach, and it is running on your site already.
Does any of this cost extra?
The firewall, the nightly malware sweep, the sign-in protection, the blocking controls and your own rules are all included in the price of your plan, on every plan we sell. The only charged thing on this page is the audit, and its price is printed above.
What happens when somebody tries to break in?
They are refused at the front door and the attempt is recorded, so you can open your site in the panel and read exactly which addresses were turned away, by which rule, and when. On a WordPress site an address that keeps guessing a password is banned outright for an hour.
Can I see what is actually being blocked?
Yes. Ask Kora and it reads your own site's records back to you in plain words: what was refused, how often, and from where. It is the same information our engineers look at, and you get it by asking for it in a sentence.
What if I want somebody to look at my site properly?
Book the audit above and an engineer goes through it for a fixed price. Before that, Kora answers straight away at any hour, and if it needs a person one takes it over within 4 business hours, or 1 hour on Care Pro.

Get your site behind all of it today.

Every protection on this page starts the minute your site is created, on whichever plan you pick.

Get Started