Tulapp Static Shield
Tulapp WP Static Shield

Don’t rebuild it yet. Shield it.

Keep WordPress for content management while Static Shield serves visitors a faster, safer static representation wherever it can — shrinking the hackable attack surface without a rebuild.

Get Static Shield Pro

WordPress 7.1 and older back to 5.2 Supported WordPress versions 5.2 5.3 5.4 5.5 5.6 5.7 5.8 5.9 6.0 6.1 6.2 6.3 6.4 6.5 6.6 6.7 6.8 6.9 7.0 7.1 · PHP 8.5 and older back to 7.0 Supported PHP versions 7.0 7.1 7.2 7.3 7.4 8.0 8.1 8.2 8.3 8.4 8.5

Full feature set on WordPress 5.5+ with PHP 8.1+. Older versions run in Legacy Safe Mode.

Choose your protection mode

The same modes — and the same diagrams — you configure right from the plugin's own setup wizard. Pick how much of WordPress stays reachable.

Fully Static

Visitors Static edge Blocked elsewhere WordPress private Admin
Visitors only ever reach the static edge; every other WordPress route is blocked. Admins reach WordPress through a private, authenticated path.

No public request reaches the WordPress runtime at all — only static files and narrow Shield services.

  • Zero public WordPress endpoints
  • Only Shield services stay reachable
  • Maximum attack-surface reduction
Speed●●●●●
Protection●●●●●
Compatibility●●●○○

Best for: Brochure sites, blogs, high-security needs

Static + Bridges

Visitors Static edge Allowed bridge routes Blocked elsewhere WordPress private Admin
Forms and consent go through a narrow, explicit bridge; everything else is static or blocked.
FormsConsent

Static for every visitor, with a small number of explicit routes bridged back to WordPress for forms or consent.

  • Static pages by default
  • Only approved bridge routes allowed
  • Built for forms and simple integrations
Speed●●●●○
Protection●●●●○
Compatibility●●●●●

Best for: Sites with contact forms or a consent banner

Hybrid

Default
Visitors Static edge Allowed dynamic routes Blocked elsewhere WordPress private Admin
Cart, checkout, account, and anything else dynamic stay live; everything else is served static or blocked.
CartCheckoutAccountAPI

Static by default, dynamic where required — WordPress stays reachable for anything not explicitly built yet.

  • Static pages served directly
  • WordPress handles cart, account, and anything else dynamic
  • Best for shops and complex sites
Speed●●●○○
Protection●●●○○
Compatibility●●●●●

Best for: E-commerce, membership, dynamic sites

Zero-WordPress Mode

Pro
Visitors Static edge Allowed API + IP admin Blocked elsewhere WordPress private Admin
Only static files, the Shield Bridge API, and your allowlisted admin IP stay reachable; everything else is blocked outright.
Shield APIAdmin IP

Default-deny for the public internet — any request that isn't a known static file, the Shield Bridge API, or a verified admin IP gets denied outright, never silently handed to WordPress.

  • Denies everything except static files, the Shield Bridge API, and your allowlisted admin IP
  • Independent of whichever mode above you pick — layers on top of any of them
  • Can affect other plugins' AJAX, REST, or webhook endpoints — review before activating
Speed●●●●●
Protection●●●●●
Compatibility●●○○○

Best for: Maximum lockdown once your static coverage is high

Vault Mode

Pro
Visitors Static edge Sealed wake grant only Blocked elsewhere WordPress private Admin
wp-admin stays sealed with no permanent allowlist — even your own IP. Wake a short-lived signed grant when you need in, then let it reseal (sleep) automatically or close it yourself.
Wake grantSleep

No standing wp-admin access at all, not even your own IP — wake a short-lived signed grant on demand when you actually need in, then let it expire or put it back to sleep.

  • wp-admin and wp-login.php are sealed by default — no permanent allowlist, not even your own IP
  • Wake a short-lived signed grant (15 min default, 60 min max) from Tulapp Cloud when you need in
  • Close it yourself (sleep) or let it expire automatically — stricter than Zero-WordPress Mode, and layers on top of it
Speed●●●●●
Protection●●●●●
Compatibility●●●○○

Best for: Sites that need admin access rarely and want zero standing attack surface

The shape of the change

One public release, two systems underneath

A public static release out front — WordPress narrowed to what it actually needs to stay reachable for.

Before
WordPress · PHP + MySQL + plugins · publicly reachable
After Static Shield
Static site (fast) + WordPress (shielded)
See it in action

Real screens

Every tab in the dashboard, captured straight from the plugin itself — click one to watch it, or see the full tour with captions →

Overview
Serving Mode
Plugins
Dynamic Content Scan
Fingerprint Shield
Attack Surface
Access & Isolation
Server Integration
Shield Preview
Static Search
Site DNA
About

What Static Shield does

Static by default, dynamic where required

Hybrid Mode serves static pages directly while WordPress stays reachable for cart, checkout, account, and anything else genuinely dynamic — nothing you rely on breaks by default.

Tighter modes when you want them

Static + Bridges and Fully Static modes reduce what stays reachable further, for sites that don't need as much left dynamic.

Admin access, locked down separately

Zero-WordPress Mode and Vault Mode gate wp-admin independent of whichever serving mode you pick — default-deny for every public request except static files, the Shield Bridge API, and your allowlisted IP, with Vault Mode going one step further: no standing access at all, woken temporarily only when you actually need it.

Faster by default

Visitors get a pre-built static page instead of a fresh WordPress render — no database query, no PHP execution, no plugin overhead on the request path. Pages load faster, and your server does less work under traffic spikes.

Smaller attack surface

Every route served statically is one fewer route that reaches WordPress or its plugins at request time. Zero-WordPress Mode (Pro) goes further: default-deny for every public request except static files, Static Shield's own Shield Bridge API, and your allowlisted admin IP.

Compatible with what you already run

A coded compatibility profile for 50+ popular plugins and themes — WooCommerce, Elementor, Contact Form 7, Yoast, and more — classifies exactly what stays static, what's bridged, and what needs to stay dynamic, instead of guessing. See the full Integrations & Compatibility list.

Pricing

Static Shield Lite
Free

Free subscription — a Tulapp account is required, no payment.

  • Hybrid, Static + Bridges & Fully Static modes
  • Admin Access Gateway (IP allowlisting for wp-admin / wp-login)
  • Static builds & the core serving engine
  • Attack Surface Map, Site DNA, Compatibility Matrix & Fingerprint Shield
  • Shield Preview (manual validation) & Static Search

Not included:

  • Zero-WordPress Mode & Vault Mode (full isolation)
  • Continuous monitoring, history & alerts
  • Shield Verify & the Shield Search API (Tulapp Cloud infrastructure)
  • Automatic compatibility overrides & advanced isolation
Coming soon to WordPress.org
Static Shield Pro
€59 / year excl. VAT

First website

Every additional website (for agencies / developers) on the same subscription is €39/year excl. VAT.

  • Reduced WordPress attack surface
  • Faster static delivery for visitors
  • WordPress workflow stays available
  • Cloud-powered monitoring & verification
  • Annual subscription, cancel any time before renewal
  • Prices exclude VAT — VAT is calculated at checkout
Start with 1 website — €59/year

How it works

1. Install

Download the free Static Shield plugin and install it on your WordPress site, then run the guided Configuration Wizard.

Coming soon to WordPress.org

2. Build

Static Shield crawls and renders your site into a static release, without touching your WordPress workflow.

3. Serve & monitor

Visitors get the static release; you keep the usual wp-admin. Pro adds cloud monitoring, verification, and Zero-WordPress/Vault Mode on top.

Download Pro after subscribing →

Learn more

FAQ

Does Static Shield make my site unhackable?

No — no software makes a site “unhackable” or “100% secure.” Static Shield reduces public exposure by serving a static release wherever possible and narrowing what stays reachable, but it does not make vulnerable software intrinsically secure.

Will my dynamic features (cart, checkout, forms) keep working?

Yes, by default. Hybrid Mode keeps WordPress reachable for anything not built statically or inherently dynamic. Tighter modes (Static + Bridges, Fully Static, Zero-WordPress Mode) narrow this further and can affect other plugins’ AJAX, REST, or webhook endpoints — review your active plugins before turning them on.

Do I need to rebuild my site to use Static Shield?

No. Install the plugin, run the wizard, and your existing WordPress site is used as-is — Static Shield builds a static release alongside it.

Is this an offensive security or hacking tool?

No. Static Shield is a defensive WordPress security and performance product — it reduces your own site’s public attack surface, it is not a penetration-testing tool.

Ready to reduce your attack surface and make your site faster?

Get Static Shield Pro for the first website at €59/year, excl. VAT.

Get Static Shield Pro