Keep WordPress for content management while Static Shield serves visitors a faster, safer static representation wherever it can — shrinking the hackable attack surface without a rebuild.
WordPress 7.1 and older back to 5.2 Supported WordPress versions 5.2 5.3 5.4 5.5 5.6 5.7 5.8 5.9 6.0 6.1 6.2 6.3 6.4 6.5 6.6 6.7 6.8 6.9 7.0 7.1 · PHP 8.5 and older back to 7.0 Supported PHP versions 7.0 7.1 7.2 7.3 7.4 8.0 8.1 8.2 8.3 8.4 8.5
Full feature set on WordPress 5.5+ with PHP 8.1+. Older versions run in Legacy Safe Mode.
The same modes — and the same diagrams — you configure right from the plugin's own setup wizard. Pick how much of WordPress stays reachable.
No public request reaches the WordPress runtime at all — only static files and narrow Shield services.
| Speed | ●●●●● |
| Protection | ●●●●● |
| Compatibility | ●●●○○ |
Best for: Brochure sites, blogs, high-security needs
Static for every visitor, with a small number of explicit routes bridged back to WordPress for forms or consent.
| Speed | ●●●●○ |
| Protection | ●●●●○ |
| Compatibility | ●●●●● |
Best for: Sites with contact forms or a consent banner
Static by default, dynamic where required — WordPress stays reachable for anything not explicitly built yet.
| Speed | ●●●○○ |
| Protection | ●●●○○ |
| Compatibility | ●●●●● |
Best for: E-commerce, membership, dynamic sites
Default-deny for the public internet — any request that isn't a known static file, the Shield Bridge API, or a verified admin IP gets denied outright, never silently handed to WordPress.
| Speed | ●●●●● |
| Protection | ●●●●● |
| Compatibility | ●●○○○ |
Best for: Maximum lockdown once your static coverage is high
No standing wp-admin access at all, not even your own IP — wake a short-lived signed grant on demand when you actually need in, then let it expire or put it back to sleep.
| Speed | ●●●●● |
| Protection | ●●●●● |
| Compatibility | ●●●○○ |
Best for: Sites that need admin access rarely and want zero standing attack surface
A public static release out front — WordPress narrowed to what it actually needs to stay reachable for.
Every tab in the dashboard, captured straight from the plugin itself — click one to watch it, or see the full tour with captions →
Hybrid Mode serves static pages directly while WordPress stays reachable for cart, checkout, account, and anything else genuinely dynamic — nothing you rely on breaks by default.
Static + Bridges and Fully Static modes reduce what stays reachable further, for sites that don't need as much left dynamic.
Zero-WordPress Mode and Vault Mode gate wp-admin independent of whichever serving mode you pick — default-deny for every public request except static files, the Shield Bridge API, and your allowlisted IP, with Vault Mode going one step further: no standing access at all, woken temporarily only when you actually need it.
Visitors get a pre-built static page instead of a fresh WordPress render — no database query, no PHP execution, no plugin overhead on the request path. Pages load faster, and your server does less work under traffic spikes.
Every route served statically is one fewer route that reaches WordPress or its plugins at request time. Zero-WordPress Mode (Pro) goes further: default-deny for every public request except static files, Static Shield's own Shield Bridge API, and your allowlisted admin IP.
A coded compatibility profile for 50+ popular plugins and themes — WooCommerce, Elementor, Contact Form 7, Yoast, and more — classifies exactly what stays static, what's bridged, and what needs to stay dynamic, instead of guessing. See the full Integrations & Compatibility list.
Free subscription — a Tulapp account is required, no payment.
Not included:
First website
Every additional website (for agencies / developers) on the same subscription is €39/year excl. VAT.
Download the free Static Shield plugin and install it on your WordPress site, then run the guided Configuration Wizard.
Coming soon to WordPress.org
Static Shield crawls and renders your site into a static release, without touching your WordPress workflow.
Visitors get the static release; you keep the usual wp-admin. Pro adds cloud monitoring, verification, and Zero-WordPress/Vault Mode on top.
No — no software makes a site “unhackable” or “100% secure.” Static Shield reduces public exposure by serving a static release wherever possible and narrowing what stays reachable, but it does not make vulnerable software intrinsically secure.
Yes, by default. Hybrid Mode keeps WordPress reachable for anything not built statically or inherently dynamic. Tighter modes (Static + Bridges, Fully Static, Zero-WordPress Mode) narrow this further and can affect other plugins’ AJAX, REST, or webhook endpoints — review your active plugins before turning them on.
No. Install the plugin, run the wizard, and your existing WordPress site is used as-is — Static Shield builds a static release alongside it.
No. Static Shield is a defensive WordPress security and performance product — it reduces your own site’s public attack surface, it is not a penetration-testing tool.
Get Static Shield Pro for the first website at €59/year, excl. VAT.
Get Static Shield Pro