Overview
SiteLock's cloud, DNS-based web application firewall, historically branded TrueShield and now marketed simply as the SiteLock WAF, filters inbound traffic before it reaches your site. Originally built on Incapsula technology, it blocks the OWASP Top 10, including SQL injection and cross-site scripting, plus malicious bots and DDoS via machine learning and IP reputation.
The platform pairs the WAF with an integrated CDN across 44+ data centers, virtual patching, and a separate malware scanning and removal suite. A dedicated WordPress plugin is available, and setup is a single DNS change of about five minutes. SiteLock is sold directly and through hosting resellers such as HostGator, Bluehost, and Network Solutions.
It targets small businesses and shared-hosting owners wanting hands-off protection. Pricing runs three monthly tiers (Basic $19.99, Pro $29.99, Business $44.99), with roughly two months free on annual billing; the WAF starts at the Pro tier, not Basic, and a host's bundled price can differ from buying direct.
Ratings Breakdown
Key Features
TrueShield WAF
Cloud-based WAF providing OWASP Top 10 protection via DNS redirect.
Malware Scanning
Daily website scanning for malware, backdoors, and suspicious files.
Hosting Provider Integration
Available directly through many hosting control panels.
Pros & Cons
Pros
-
Easy setup
DNS-based deployment accessible to non-technical users.
-
Hosting provider availability
Available through many hosting providers' control panels.
-
All-in-one website security
Combines WAF with malware scanning and removal.
Cons
-
Basic WAF features
WAF capabilities are limited compared to enterprise solutions.
-
Mixed reputation
Some criticism for aggressive upselling through hosting partners.
-
Limited transparency
Less detailed documentation and threat intelligence sharing.
Pricing
Pricing model: Monthly subscription
Basic
Malware scanning and backup; does not include the WAF
- Daily malware scanning
- Automatic malware removal
- Website backup
Pro
Adds the WAF and CDN
- Everything in Basic
- Web Application Firewall (WAF)
- CDN acceleration
- Bot and DDoS blocking
Business
Advanced WAF and compliance
- Everything in Pro
- Custom WAF rules
- PCI firewall compliance reporting
- Two-factor authentication
Our Verdict
SiteLock TrueShield provides basic WAF protection for small businesses and shared hosting environments. While easy to set up, it lacks the advanced features of dedicated WAF solutions.
Our verdict: Adequate for small sites needing basic protection, but consider Cloudflare's free tier as an alternative.
CVE Coverage
SiteLock TrueShield can detect and block attacks matching 105K+ known CVEs based on its supported rule sets.
Coverage by Attack Type
Latest Blockable CVEs
| CVE | Severity |
|---|---|
| CVE-2026-49294 | UNKNOWN |
| CVE-2026-20262 | MEDIUM |
| CVE-2026-9863 | UNKNOWN |
| CVE-2026-9862 | UNKNOWN |
| CVE-2025-15659 | UNKNOWN |
| CVE-2025-15658 | UNKNOWN |
| CVE-2026-52704 | UNKNOWN |
| CVE-2019-25746 | HIGH |
| CVE-2018-25436 | CRITICAL |
| CVE-2016-20084 | HIGH |
Frequently Asked Questions
Is SiteLock TrueShield a real WAF?
Yes. It is a genuine cloud-based web application firewall that filters traffic at the DNS layer and blocks the OWASP Top 10 attack classes, malicious bots, and DDoS attempts. SiteLock has increasingly dropped the "TrueShield" name in its current marketing and simply calls it the SiteLock WAF, but it is the same product. Historically the WAF was powered by Incapsula's technology.
How is SiteLock sold, and what does it cost?
SiteLock is sold both directly on sitelock.com and through many hosting providers (HostGator, Bluehost, Network Solutions, and resellers). Current direct pricing is three monthly tiers: Basic $19.99, Pro $29.99, and Business $44.99, with roughly two months free on annual billing. Prices bought through a host can differ, so compare the host's quote against SiteLock's direct pricing.
Does SiteLock work with WordPress?
Yes. SiteLock offers a dedicated WordPress plugin alongside its DNS-based WAF and scanning, and the help center has WordPress-specific setup guides. Because the WAF sits in front of the site via DNS, it protects WordPress without server-side installation; the plugin adds dashboard integration.
Is the WAF the same as SiteLock's malware scanning?
No. They are separate layers. Malware scanning (included from the entry Basic plan) inspects your site's files and database for infections and can remove them. The WAF (included from the Pro plan upward) is a preventive firewall that blocks malicious requests before they reach your site. A full security posture uses both, but on SiteLock the WAF requires at least the Pro tier.
How is SiteLock's WAF deployed?
It is a cloud, DNS-based deployment. You point your domain to SiteLock's network with a single DNS change; there is no software install, code change, or server access needed, and setup typically takes about five minutes. Traffic then routes through SiteLock's global network (44+ data centers) which also provides CDN acceleration.
Ready to try SiteLock TrueShield?
Visit the website to learn more or request a demo.