Behavior over single requests
Nexus looks for repetition, target and application context instead of turning one odd URL into a permanent verdict.
Traffic Shield evaluates repeated behavior, protected surfaces and site context so Nexus can respond to pressure without treating every unusual request—or every shared IP—as the same attacker.
Nexus looks for repetition, target and application context instead of turning one odd URL into a permanent verdict.
Shared mobile networks, NAT and CGNAT are handled conservatively so one public address does not automatically become one attacker.
Pressure states are designed to tighten protection when needed and relax again when the evidence window ends.
Traffic Shield works inside WordPress where Nexus can understand the surface being touched, the surrounding behavior and whether the activity is consistent with a real visitor, useful automation or sustained pressure.
The goal is not to collect the most blocks. It is to make safer decisions under real WordPress traffic.
Choose a practical baseline for ordinary operation, or temporarily tighten the runtime layer when a site is genuinely under pressure.
Build local history when a source repeatedly touches sensitive or exploit-shaped surfaces instead of overreacting to one request.
Use privacy-preserving client continuity alongside the public IP so multiple real visitors behind one network are not automatically collapsed into one identity.
Investigate, trust, watch, block and release individual sources from one operational view.
Traffic Shield is designed to be proportionate rather than permanently suspicious.
Normal and unusual activity are evaluated in the context of the surface being used.
Repetition, automation and source/client evidence increase or reduce confidence.
Temporary protection is applied to the relevant source or surface when evidence becomes strong enough.
Temporary state expires or returns to normal when the pressure window clears.
No. Early WAF handles high-confidence traffic before normal WordPress loading. Traffic Shield works during runtime where richer site and application context is available.
Normal Protection is the recommended everyday profile. Very Light is more relaxed. Under Attack and Custom are advanced profiles available while the Nexus PRO licence is active.
Nexus does not treat the public IP as a complete identity. Where possible it combines network pressure with privacy-preserving client continuity and other evidence before escalating.
No. Pressure responses are designed to be temporary and reason-bound. Manual controls remain explicit.
Traffic Shield is part of the Nexus PRO defense stack; advanced Under Attack and Custom profiles require an active licence.