Skip to content
Feature · For WordPress

AI scan reports, plain-English explanation for every finding.

Most security scanners hand you a list of suspicious files and a CVSS score and assume you can figure it out from there. Guardian Gaze’s AI reports explain, in language a site owner can read, what each flagged piece of code actually does, why it’s suspicious, what the impact would be if you ignored it, and the specific remediation step to take.

Availability: included from Pro upwards, via the Premium add-on · Plain-English AI explanations on every finding

GuardianGaze plugin view inside the WordPress admin

The plugin view: findings, severity and next steps inside the WordPress admin

At a glance

AI Reports at a glance

What it does

Threat summary

One-line plain-English description: "Obfuscated PHP backdoor that grants remote code execution when a specific cookie is present."

How it helps

Severity level

Critical · High · Medium · Low · Info. Calibrated to threat type, exploitability and reachability; a backdoor in mu-plugins/ is Critical regardless of what it does.

What's next

Technical details

File path, line numbers, the exact code snippet that triggered the finding, the hash of the file, and the version of the host plugin/theme if applicable.

The problem

A file path and a severity score are not an explanation

Most scanner output is written for somebody who already knows what it means. A path, a rule name, a number between one and ten. To an experienced developer that is enough. To the person who actually runs most WordPress sites it is a sentence in a language they do not speak, attached to something frightening.

The consequence is predictable and expensive. Findings get ignored because they cannot be assessed, or acted on far too aggressively: a legitimate file deleted, a plugin removed, a site broken in the course of fixing a problem that may not have existed.

Neither outcome is a detection failure. The scanner was right. It simply did not communicate in a way that let anybody make a good decision.

What you get

What it does, why it was flagged, what to do

Each finding on Pro is explained in plain language: what the code actually does, why it was flagged, what an attacker would use it for, and what your options are.

That last part is the one that changes behaviour. Knowing a file contains an obfuscated remote shell tells you it is bad. Knowing whether to quarantine it, remove it, or check the hosting account first is what turns knowledge into a resolved incident, and it is the part that is usually missing.

The explanation also makes disagreement possible, which matters more than it sounds. A finding that shows its reasoning can be evaluated and rejected. A finding that shows only a score can only be believed or ignored, and most people ignore it.

Reports

For clients, for insurers, and for the conversation afterwards

Explanations also make reports worth sending. On Agency, white-label client reports carry your branding and are written for a non-technical reader, which is the difference between security being an invisible cost you absorb and a service you can show and charge for.

That is the honest commercial reason agencies ask about reports before they ask about detection. Retainers get cut when the client cannot see what they pay for, and a monthly summary of what was scanned, found, blocked and fixed makes the line item defensible.

The same document does work after an incident, when a client, an insurer or a payment processor wants to know what happened and what was done. A written record beats a recollection, and it is much easier to produce one when the findings were legible in the first place.

FAQ

AI Reports - common questions

Which plan includes AI explanations?

Pro and above. Free and Basic report findings with path and severity; Pro adds the plain-English explanation of each one.

Are the reports white-label?

On Agency, yes: your branding, written for a non-technical reader, forwardable without an editing pass.

Can I trust an AI-written explanation?

Treat it as a well-informed second opinion that shows its reasoning, which is what makes it checkable. A finding you can evaluate is more useful than a score you can only believe or ignore.

Can I export a report?

Yes. Reports are exportable for sending to clients or keeping as a record, which is what makes them useful after an incident as well as during one.

Does the explanation include remediation steps?

Yes, what the code does, why it was flagged, what it would be used for, and what your options are, including when the right answer is that the problem is at the hosting level and outside what a plugin can fix.

Related

Works with

AI Detection →

Catches what has never been catalogued.

Notifications →

Alerts that matter, digests for the rest.

Audit Log →

Who did what, and when.

See it on your own site

The free scan takes under five minutes and tells you the truth.