About

Built by security researchers, not just plugin developers.

Guardian Gaze is a product of RedSecLabs, a London-based cybersecurity firm. We build the plugin we wanted while investigating compromised WordPress sites, one that doesn't just match signatures, but actually reasons about what code is doing.

The plugin started as a research tool. The RedSecLabs research team spends a lot of time inside compromised WordPress estates, usually called in after a client's site has been hacked, and traditional security tools have marked it clean.

What we kept seeing was the same pattern. The signature scanners had done their job. The firewalls had done theirs. But sitting inside the install, across the file tree and the database, were backdoors that looked just enough like legitimate plugin code to pass automated review.

We started reasoning about code intent manually, file by file. We built tools to help. Then we realised those tools were the security plugin WordPress needed, one that does not ask "have I seen this exact pattern before?" but "would a reasonable person look at this code and call it legitimate?"

That's the wedge Guardian Gaze fills. It's deliberately narrow. It complements the security stack you already have, rather than trying to replace it.

"Attackers have evolved beyond simple malware signatures. They're writing backdoors that look exactly like legitimate plugin code. You need AI that can reason about what code is actually doing."

Rafay Baloch/CEO, RedSecLabs
Founded2026
Based inLondon, UK
Parent companyRedSecLabs Ltd
Plugin versionv2.2.8
WordPress.org rating★★★★★ early reviews
Open to disclosureYes, see policy
How we work

Four principles that shape every release.

Principle 01

You stay in control.

Guardian Gaze never modifies or deletes anything without your sign-off. Every finding is presented for review. No silent quarantine. No automatic deletion. Ever.

Principle 02

Privacy by design.

No passwords leave your site. Only minimal security metadata is sent to our API. External services are limited and documented in our privacy disclosure. Source code is public on WordPress.org.

Principle 03

Findings explained in English.

A rule name on its own does not help anyone act. Every Guardian Gaze finding includes a reasoning summary in plain English, so you can decide what to do without re-reading the file yourself.

Principle 04

Honest about scope.

Guardian Gaze is the code-level layer. It is not a perimeter firewall and it is not trying to be one. We tell you exactly where it fits in your stack, and when something else is the better tool.

FOUNDERS & TEAM

The Humans Behind the Shield

A tight-knit team of cybersecurity experts united by one goal; making WordPress protection accessible to everyone.

Founder / CEO
Rafay Baloch

Rafay Baloch

Founder / CEO

CEO of RedSecLabs, a CREST & PCI QSA-certified offensive security firm. White-hat hacker, published author, and international speaker with deep expertise in penetration testing and security engineering.

White-Hat HackingCREST & PCI QSAAuthor & Speaker
View Profile
Co-Founder
Atif Shaukat

Atif Shaukat

Co-Founder

Regional Director of Cyber Security (EEMEA) at Mastercard. Accomplished entrepreneur who has led technology products to multimillion-dollar deals across high-growth markets with a value-driven approach.

Cyber SecurityEntrepreneurshipTech Sales
View Profile
Data Analyst
Raabia Riaz

Raabia Riaz

Data Analyst

Detail-oriented Data Analyst skilled in Python, SQL, ML, and NLP. Specialises in predictive analytics, machine learning models, and translating complex datasets into actionable business insights.

Python & SQLMachine LearningNLP
View Profile
Technical Lead & Security Expert
Muhammad Samaak

Muhammad Samaak

Technical Lead & Security Expert

Penetration Tester & AppSec Engineer at RedSecLabs. Specialises in web application, mobile, API, and cloud security testing, leveraging deep expertise in vulnerability management and the OWASP framework.

PentestingAppSecOWASP
View Profile
Senior Software Engineer
Huzoor Bux

Huzoor Bux

Senior Software Engineer

Senior Software Engineer focused on building secure, scalable, and high-performance systems. Experienced in backend architecture, application security, and developing reliable solutions for modern web platforms.

Backend DevelopmentSystem DesignWordPress
View Profile
The team

A small team of WordPress malware analysts.

We are a research-led team; most of us spend more time reading malware than writing plugin features. That informs everything Guardian Gaze does.

RB
CEO, RedSecLabs

Rafay Baloch

Security researcher and founder. Long history of publishing on browser security, web application vulnerabilities, and emerging malware techniques. Drives research direction at RedSecLabs.

TR
Threat Research

Threat Research team

Investigates real-world WordPress compromises, reverse-engineers backdoor families, and turns what we find into detection logic that ships in Guardian Gaze. Adds new patterns to our threat library as they appear in the wild.

PE
Product Engineering

Product & Engineering team

Builds the plugin itself, scanner core, reasoning layer, admin UI, alerting, integrations. Focused on making security tooling that does not slow your site down or scare your customers.

Want to talk?

Whether you are a customer, a journalist, a researcher with a finding, or someone considering Guardian Gaze for your stack, we would love to hear from you.

Get in touch
Free on WordPress.org

Try the plugin we built for our own work.

Install Guardian Gaze on one WordPress site for free. Run a scan. See the kind of reasoning we wished we had when this all started.

How it works
Available through the official WordPress plugin directory.