ScaleShield: the security and speed layer in front of every site
ScaleShield sits between the internet and your site. It handles HTTPS with your free certificate, absorbs traffic spikes well past 100,000 requests per second, drops abusive bots, blocks attack traffic and serves cached pages in milliseconds, all before a request reaches your PHP, your app or your database. When a site is attacked it raises its own defences and lowers them again once the attack passes. No plugin. No configuration. No extra charge.
One layer, three jobs
What sits in front of your site
ScaleShield does three jobs on every request: it caches, it filters, and it inspects. Each one has its own page if you want the full mechanism.
G7Cloud Cache
Full copies of your WordPress pages, served from in front of your site without starting PHP or touching the database. As each page is cached, G7Cloud Cache records what it displays, so when you edit something only the pages that show it are refreshed. Nothing goes stale, and the cache never rebuilds from cold.
How precise refresh worksBot protection
A large share of raw traffic to any site is automated: scrapers, credential-stuffing scripts, spam bots, exploit scanners. ScaleShield drops it in front of your site with an invisible browser check that real visitors never notice, and verifies claimed search-engine crawlers against Google's and Bing's own published address ranges. Your SEO is safe.
How bots are filteredManaged firewall
Every request is inspected against rules that block known attack patterns: SQL injection, cross-site scripting, exploit probes against common software. The attack paths WordPress actually gets hit on (wp-login, xmlrpc) get specific rules. We maintain it all platform-wide, and rule changes take effect in about 5 seconds.
What the firewall blocksWell over 100,000 requests per second, absorbed in front of your site
Traffic does not arrive politely. A television mention, a product drop, a campaign landing at nine in the morning, a scraper fleet finding your catalogue: all of it turns up at once. ScaleShield takes that surge in front of your site and answers it from cache, so your container spends its resources on the requests that genuinely need it.
This is the same layer on every plan, and it is the reason a spike does not become a queue. Cached pages are served without starting PHP or touching your database. Hostile traffic is dropped before it reaches your container at all. What arrives at your site is the traffic worth serving.
It raises its own defences
ScaleShield watches the traffic arriving for each site separately. When the pattern in front of one site turns hostile, that site moves to a higher security tier on its own: every visitor without a verified-human pass is checked before the request travels any further.
Verified search engines and your own allowlisted addresses stay exempt the whole time, so being attacked never costs you search visibility.
Spikes are absorbed in front of your site, so a surge never becomes a queue at your container.
A site under attack moves to a higher security tier on its own, then stands down once the traffic settles.
A change we make reaches every site on the platform in about five seconds.
Allow, challenge or block by country or by whole continent, per site.
Blocked before it ever hits your PHP
A WordPress security plugin can only inspect a request after WordPress has already booted: PHP starts, the database is queried, and only then does the plugin decide the request was junk. The attacker still cost you CPU, memory and database connections.
ScaleShield works the other way round. It sits in front of your dedicated container, where the managed firewall rejects hostile requests and bot protection drops automated traffic before either reaches your site. Your site never boots for it, never queries the database for it, and never slows down real visitors because of it. That matters most on login pages, search endpoints and checkout flows, where bot traffic is heaviest.
- Hostile traffic is dropped in front of your site, before it reaches your container
- Junk traffic consumes zero PHP workers and zero database connections
- Login and admin endpoints are shielded from credential-stuffing bots
- One layer, maintained by us: no rule sets for you to keep updated
The attack is blocked, but it already cost you server resources.
Hostile traffic never touches your container. Your resources serve real visitors only.
Search engines are never blocked. Impostors always are.
The usual bargain with a security layer is that you tighten it and hope your rankings survive. ScaleShield settles that before any rule gets a say. A request claiming to be Googlebot is checked against Google's own published address ranges. If it came from Google, it goes through: never challenged, never rate limited, never blocked, whatever else is happening on the site at the time.
A request wearing the same name from an address Google does not own is treated as the disguise it is. Claiming to be a search engine is one of the most common covers a scraper uses, and it stops working here. The check runs on every request, on every plan, with nothing for you to switch on and nothing to get wrong.
- Confirmed crawlers bypass the browser check, the rate limits and the country rules
- They stay exempt while a site is under attack and at a raised security tier
- Spoofed crawlers are challenged instead of being taken at their word
- No allowlist for you to maintain, and the same behaviour on every plan
Verified against their own published ranges
The address ranges are refreshed from each search engine directly, so a crawler that moves to a new network keeps working without anyone touching a setting.
The rendered page is stored in front of your site, along with a record of what it displays.
Served in milliseconds. PHP never starts and the database is never queried.
Served before it ever hits your PHP, too
The same layer that blocks hostile traffic also serves your pages. G7Cloud Cache keeps full copies of your WordPress pages in front of your site, so a cached page is served in milliseconds without starting PHP or touching the database. Your site's own resources stay free for the visits that need them: checkout, admin, search.
As each page is cached, G7Cloud Cache records what that page displays: which posts, categories, menus, sidebars and widgets it rendered. Edit something and only the pages that actually show it are refreshed, instantly and automatically. Nothing goes stale, and the cache never rebuilds from cold. The full mechanism is on the G7Cloud Cache page, and it pairs with the managed object-cache add-on that speeds up the dynamic pages the cache leaves alone.
- Nothing to install: no caching plugin, no TTLs, no exclusion rules
- Logged-in visitors, carts, checkouts and wp-admin are never cached
- WooCommerce-safe: you cannot serve one customer another customer’s basket
- Static files and images are cached in front of your site too
Googlebot crawls your whole site in under 100ms a page
Crawlers are the visitors that most want a cache and least need a brand new copy. So they get their own. ScaleShield keeps a separate store of your pages for crawler traffic, held for 30 days rather than the week a visitor copy gets, which means the page a crawler last saw a fortnight ago is still sitting there waiting for it.
The effect is a hit rate close to total and answers in tens of milliseconds, and it holds the same whether the site has ten thousand pages or ten million. A crawler working through a deep catalogue is not waiting on PHP, a database or a slow template on any of them.
- Kept apart from your visitors’ copies, so crawler traffic and customer traffic never compete
- Held for 30 days, so a crawler returning after a gap still lands on a stored page
- Survives a cache clear, so purging your site never cold-starts your crawl performance
- Logged-in visitors, carts and checkouts are never eligible, crawler or not
Fast and fresh, without choosing between them
A stored page counts as fresh for 60 seconds. After that, the next crawler still gets its answer immediately from the stored copy while a refresh runs quietly in the background. Nobody waits for the rebuild, and the crawler behind them collects the updated page.
Publishing an edit does not wait for any of that. The same surgical refresh that updates your visitors reaches the crawler store at the same moment, so corrections are picked up on the next crawl.
Why this shows up in your crawl budget
Google decides how hard to crawl a site partly on how well the site copes. Its own guidance on optimising crawl budget puts it plainly: when a site responds consistently and its response times stay stable or improve, the crawl limit goes up and more of the site gets crawled. When the site slows down, Google crawls less.
That is the whole argument for giving crawlers their own store. A large catalogue, a news archive or a store with a million variant pages is only ever discovered as fast as it can be served, and serving those pages from a store built to survive between crawls is what keeps the rate up. Your pages get found sooner, and your site spends none of its own resources on the crawl.
Rate limits, country rules and an attack switch
ScaleShield also carries the controls you hope never to need, plus per-site allow and block lists. We run all of it for you.
Rate limiting
Floods of requests from one source are slowed and stopped before they reach your site.
Country rules
Allow, challenge or block traffic per country (all 243 of them) or by whole continent. Useful when a store only ships to the UK.
Attack mode
Engaged automatically the moment a site is attacked, and available as a switch we can flip on request. Every visitor without a verified-human pass gets the browser check while it lasts. Real visitors barely notice. The flood stops reaching the site.
Automatic bans
Trap links that only bots follow, plus a per-address reputation score that decays over time, so one bad request years ago does not brand a visitor forever. Repeat offenders are banned automatically.
Free wildcard TLS
Certificates are issued and renewed automatically on every site, wildcards included. You never touch a certificate.
Watched by us
We maintain the rules platform-wide and watch a live console with automatic anomaly detection: a traffic spike or block surge flags itself to us. You maintain nothing.
One layer for every site: the same protection whether you run WordPress, WooCommerce, a Node.js app or a site built with the AI Website Builder.
On by default. Nothing to manage.
ScaleShield activates the moment a site goes live on G7Cloud, whether it's a managed WordPress site, a git-deployed app, or a site you shipped with the AI Website Builder. There is no onboarding step, no rules dashboard you are expected to babysit, and no premium security tier.
No plugin to install, no cache settings to tune
The protection and the cache live in front of your site, outside it entirely. No TTLs or exclusion rules to maintain.
No certificates to renew
TLS certificates (including wildcards) are issued and renewed automatically.
No rules to maintain
Firewall and bot rules are managed by us, platform-wide, for every customer at once.
No security surcharge
ScaleShield is part of the platform baseline on every plan, Free included.
ScaleShield works best with the rest of the platform
The security and speed layer in front of your site is one layer of the platform. It pairs with the rest of what every G7Cloud site gets:
- Per-minute uptime monitoring so you know your site is up, checked every minute.
- Backups that are restore-tested nightly (the recovery layer for when something goes wrong inside the site itself).
- Dedicated containers, one per site, behind ScaleShield. Nothing shared, nothing queued behind a neighbour.
ScaleShield FAQ
What the security and speed layer in front of your site does and doesn't do.
Is ScaleShield included on every plan?
Yes. ScaleShield sits in front of every site on G7Cloud, including sites published on the Free plan of the AI Website Builder. The firewall, bot protection, G7Cloud Cache and TLS are all part of it. It is not an add-on and there is nothing extra to pay.
What does ScaleShield actually include?
Free automatic TLS certificates (wildcards included), a managed web application firewall (WAF) that blocks known attack patterns, bot detection with an invisible browser check, verified-crawler allowlisting, full-page WordPress caching through G7Cloud Cache, a separate cache reserved for search-engine crawlers, rate limiting, per-country traffic rules and an attack mode that engages by itself when a site is targeted. We maintain all of it, and rule changes take effect across the platform in about 5 seconds.
What is G7Cloud Cache?
G7Cloud Cache is the full-page WordPress cache built into ScaleShield. It serves complete copies of your pages from in front of your site, without starting PHP or touching the database, so cached pages are served in milliseconds. As each page is cached it records what that page displays, so when you edit something only the pages that actually show it are refreshed. Logged-in visitors, carts, checkouts and wp-admin are never cached.
Do I still need a caching plugin or a security plugin?
You no longer need a caching plugin: G7Cloud Cache does full-page caching in front of your site, with no settings pages of TTLs and exclusion rules to maintain. On the security side, ScaleShield replaces the firewall and bot-blocking layers of a typical security plugin, and it works before a request ever reaches WordPress. Plugins that do other jobs (malware scanning inside wp-content, for example) can still be useful.
Will ScaleShield block search engines or real visitors?
No. Every verified crawler is allowed straight through: a visitor claiming to be Googlebot, Bingbot, Applebot or any other known crawler is checked against that crawler's own published address ranges before anything else decides what to do with the request. Confirmed crawlers are never challenged, never rate limited and never blocked, on any plan and with no setting to get right. Anything claiming the name from an address the crawler does not own is treated as the disguise it is. Traffic that merely looks automated gets a quick, invisible browser check rather than a block, and real visitors pass through without noticing.
How much traffic can ScaleShield absorb?
Well over 100,000 requests per second in front of a single site. Spikes are answered from the cache layer sitting in front of your site, so a campaign landing, a product drop, a national news link or a scraper fleet arriving at once is absorbed before it reaches your container. Your site keeps its resources for the requests that genuinely need it: checkout, search, admin.
What happens when my site comes under attack?
Protection steps up on its own. ScaleShield watches the pattern of traffic arriving for each site, and when that pattern turns hostile the site moves to a higher security tier automatically: every visitor without a verified-human pass is checked before the request goes any further. The higher tier holds for an hour, or until the attack settles down, then stands down by itself. Verified crawlers and your allowlisted addresses stay exempt throughout, so an attack never costs you search visibility. Nobody has to raise a ticket or wait for an engineer at 3am.
Does the crawler cache serve Google stale pages?
No. A stored page is considered fresh for 60 seconds. Past that the crawler still gets an answer immediately from the stored copy while a refresh runs in the background, so the next crawler receives the updated page. Editing content refreshes the crawler copy straight away rather than waiting for any timer, because the same surgical refresh that updates your visitors reaches the crawler bucket too.
How do custom domains connect to ScaleShield?
You point a single A record at ScaleShield, using the address shown in your dashboard when you add the domain. Traffic arrives there first, gets its HTTPS handled with your free certificate, is filtered and checked against the cache, and clean requests are forwarded to your dedicated container.
Is there anything to install or configure?
No. ScaleShield is active from the moment your site goes live: firewall, bot protection and G7Cloud Cache included. There is no plugin, no cache settings to tune, no DNS puzzle beyond a single A record for custom domains, and no rule set for you to maintain.
Every site deserves this layer in front of it
The spike absorption, the automatic attack response, the verified-crawler allowlist, the crawler cache, the firewall and free TLS are on every G7Cloud plan, from Free upwards. The site serving a hundred visitors a day gets what the site serving a hundred thousand gets.