GuardianGaze vs Solid Security
Solid Security hardens WordPress better than we do. We scan for malware and it largely does not. These are two halves of a job rather than two versions of the same one, which is why running both is a reasonable answer.
Which one should you pick?
Neither tool wins on every axis. Here is the honest split, before the detail.
You want to close the doors before anything gets in
The hardening checklist is the best in this comparison, the login controls are deeper than ours, and passkey support is ahead of the field. For prevention, they are the stronger product and we will not pretend otherwise.
You need to know whether something is already there
File change detection tells you a file changed. We assess what it now contains, read the database as well as the filesystem, and remove what we find. If you suspect a compromise, that is the difference that matters.
- Malware scanning as the core product, not an adjacent feature
- Four detection layers, including reasoning about code intent
- Database rows deserialised and assessed
- Firewall and virtual patching on Pro
- One-click removal when something is found
- Excellent hardening checklist and configuration UX
- Passkey support, ahead of most of the field
- Strong login security and access controls
- File change detection with a clear interface
- Long history as iThemes Security
Competitor prices are re-checked against the vendor’s own pricing page and dated. If a figure here has gone stale, tell us and we will correct it.
Hardening is prevention. Scanning is detection.
These two products are less alternatives than they are two halves of a job.
Solid Security, which most people still think of as iThemes Security, is very good at closing doors. Login limits, two-factor, passkeys, file-editor lockdown, database prefix changes, user enumeration blocking, and a hardening checklist that explains what each toggle does. Work through it properly and you have removed a large share of the ways an attack begins.
What hardening cannot do is tell you whether something already got in. Prevention and detection are genuinely different problems: one reduces the chance of compromise, the other finds it once the chance did not go your way. A site can be perfectly hardened today and still be carrying a backdoor installed through a vulnerable plugin last March.
GuardianGaze is a detection product. We ship fifteen hardening toggles and they are useful, but we would not claim they beat Solid Security's hardening UX. What we do that they do not is read every file and database row looking for what is already there.
File change detection is not malware scanning
The distinction sounds pedantic until a site is compromised.
Solid Security's file change detection tells you that a file changed. That is genuinely useful, an unexpected change to a core file is a strong signal, but it is a comparison against a previous state, not an assessment of content. It cannot tell you whether the change was a legitimate plugin update or a backdoor, and it has nothing to say about a malicious file that arrived before you started monitoring.
It also has nothing to say about the database. A serialised payload in wp_options, a hidden administrator account, an injected redirect, none of those are file changes, so none of them show up.
GuardianGaze assesses content rather than comparing state. Signature matching for known malware, integrity checks against WordPress.org checksums, heuristics for suspicious constructs, and a fourth layer that reads code and reasons about what it is for. Database tables are read and deserialised on Pro rather than left alone.
If your site has never been compromised, hardening plus change detection is a reasonable posture and Solid Security covers it well. If you suspect something is already wrong, change detection will probably not answer the question.
Feature comparison
Where the two tools genuinely differ. Anything both do equally well is left out.
| Solid Security | GuardianGaze | |
|---|---|---|
| Primary purpose | Hardening and access control | Malware detection and removal |
| Hardening checklist | Excellent, best in this comparison | Fifteen toggles, one click |
| Passkeys | Yes | No |
| Two-factor authentication | Yes | Yes |
| File change detection | Yes | Yes, plus content assessment |
| Signature malware scanning | Limited | Yes |
| Reasoning about code purpose | No | Yes, on Pro |
| Database malware inspection | No | Yes, on Pro |
| Web application firewall | No | Yes, on Pro |
| Malware removal | No | One-click on Pro |
| Entry price | $99/yr | $99/yr |
Where Solid Security is the better choice
No comparison written by a vendor is neutral, so here is the part we have least incentive to write. These are real, and if one of them matters to you, buy theirs.
- The hardening checklist. It is the clearest in the category, explains consequences before you toggle anything, and we do not match it.
- Passkeys. Properly implemented and ahead of most WordPress security plugins, ours included.
- Login and access control depth, granular, well thought through, and stronger than what we ship.
- A long track record as iThemes Security, with the stability and community knowledge that comes with it.
- If your concern is stopping people getting in rather than finding what is already there, they are the better fit and this is the honest recommendation.
Moving from Solid Security
Running two security plugins at once means duplicated scans and duplicated alerts. Migrate properly rather than layering.
- Consider running both, hardening and detection genuinely complement each other and they do not conflict at a code level
- If you do keep Solid Security, leave its hardening and login features on and rely on us for scanning
- If you are replacing it, work through our fifteen hardening toggles before you deactivate theirs
- Note any custom login URL, lockout thresholds or allow-lists you configured
- Do not leave two file-change monitors running long-term, duplicate alerts train people to ignore both

What you get either way: the GuardianGaze dashboard, grading every site across four areas
Common questions
Does Solid Security scan for malware?
It does file change detection, which flags that a file changed rather than assessing what the file now contains. That is useful as a signal but it is not the same as malware scanning, and it does not cover the database at all.
Can I use both together?
Yes, and this is one of the few pairings where it makes sense. They solve prevention, we solve detection, and there is no code-level conflict. Just avoid running two file-change monitors, or you will get every alert twice.
Is hardening enough on its own?
It substantially reduces the chance of compromise, but it cannot tell you about one that already happened, including through a vulnerability that existed before you hardened anything. Prevention and detection answer different questions.
Which is better value?
Solid Security Basic is $99/yr and Pro is $99/yr, so they are close. The question is not price but which job you need done. If you have no scanning at all, that is the bigger gap.
Decide with your own data
Comparison pages are marketing. A scan of your actual site is evidence.
Free tier, no card. Run both scanners on the same site and keep whichever finds more.

