We're not trying to replace perimeter firewalls or traditional security plugins; they're useful layers. Guardian Gaze adds code-level reasoning for threats those tools weren't designed to detect. The strongest setups combine all three.
Three layers of WordPress security exist for three different reasons. Most sites benefit from all three working together.
Cloudflare, hosting WAFs
Blocks malicious traffic before it reaches your site. Stops brute-force, DDoS, OWASP-pattern attacks. Operates at the network edge.
Strong at the perimeter. Cannot inspect what's already inside your WordPress files.
Wordfence, Sucuri, MalCare, Solid Security
Match files against known malware signatures, run an endpoint WAF, harden login and provide IP reputation lists. Strong for the patterns they know.
Strong at signatures. Less designed to reason about unfamiliar code patterns.
The code-level layer
LLM-assisted reasoning about whether code inside your WordPress install actually looks legitimate. Reads files and the database.
The layer none of the others were built to be.
Each row is a security capability and where each layer typically lands. We use category language ("varies by tool", "not designed for this") rather than naming specific competitors, because every tool is positioned slightly differently.
Where this table says "varies by tool", the answer depends on which traditional plugin you use and which tier you're on. Some include excellent coverage of these areas; some don't. We've chosen category language so this comparison stays fair across the whole market.
For most WordPress sites we work with, the strongest setup combines all three layers. They're cheap together, and they each cover a category the others can't.
Stops the easy traffic at the edge, bots, brute-force, OWASP-pattern attacks, DDoS. Cloudflare's free tier is enough for most sites; managed hosts often include something equivalent.
Handles the patterns the security industry already knows well, known malware signatures, file-integrity monitoring, login hardening. Pick the one that fits your team.
Adds code-level reasoning for the threats the first two layers were not designed to catch, hidden backdoors, database-resident payloads, trojanized plugin code, obfuscated loaders.
Add Guardian Gaze on top; they complement, they don't conflict.
They cover different angles. Wordfence is a strong endpoint firewall and signature scanner. Guardian Gaze adds LLM-assisted reasoning about code intent, useful for catching backdoors that don't match any known signature, and for database-resident payloads. Many people run both.
Yes, they live at different layers. Cloudflare operates at the network edge (incoming traffic). Guardian Gaze operates inside WordPress (files and database). They don't compete.
Typically not noticeably. Most WordPress security plugins are lightweight when idle. Guardian Gaze runs scans on demand or on schedule and is designed to be light on shared hosting, VPS and cloud environments.
All capable tools, and all fall under "Traditional WP security plugins" in the table above. Each has its own strengths; choose based on the features and UX you prefer. Guardian Gaze is designed to complement any of them.
Managed hosts (Kinsta, WP Engine, Pressable, etc.) typically include strong perimeter protections and core hardening. They generally don't include LLM-assisted code-level reasoning, so Guardian Gaze adds coverage that your host probably doesn't.
Install Guardian Gaze alongside what you already run. Free to start. Findings shown before any action is taken. Nothing else changes about your existing security setup.