Sensible defaults out of the box, deep control when you need it. Configure scan cadence, scope, thresholds, hardening toggles, notification routing, dashboard preferences and integrations from a single settings screen. No code, no SSH, no wp-config.php edits required.
Most security plugins fail one of two ways: too much configuration (a thousand knobs, you're paralysed) or too little (one big "secure" button and no granularity). Guardian Gaze ships with defaults tuned for the typical WordPress site, then exposes the specific settings that real site owners actually need to change.
If you never touch the settings page, the plugin still gives you a solid baseline. If you do, every setting is labelled in plain English with the trade-off explained.
Daily (Free default) · Hourly (Pro default) · Weekly · Custom interval. Set independently for the file scanner and the database scanner. Most sites are well-served by the defaults.
Full site · Core files only · Plugins only · Themes only · Database only. Useful when you want a quick targeted check rather than a full deep scan.
Pin scans to your lowest-traffic hours (default 03:00 to 05:00 server time). Especially relevant for high-traffic e-commerce sites that don't want scans competing with checkout traffic.
Trigger a scan immediately from the dashboard. Free tier: 3 on-demand scans per day. Pro: unlimited. Useful for verifying a cleanup or right after applying a plugin update.
Scheduled scans run via WordPress cron. The cron task queues a job and returns immediately; the actual scan runs server-side outside the request lifecycle, so cron never holds up the next page load. No additional system cron or WP-CLI configuration is required.
A scanner with very low thresholds catches more threats but produces more false positives. A scanner with very high thresholds produces less noise but might miss subtler malware. Guardian Gaze gives you three presets and lets you fine-tune each detection layer independently.
Each hardening option is a toggle. Defaults are conservative (we don't break sites on activation). The full hardening menu is available from the Configuration → Hardening screen and covered in detail on the hardening page.
Disable File Editor · Disable XML-RPC · Hide WP Version · Protect wp-config.php · Filter Uploads · Generate Security Keys.
IP whitelisting for admin · Disable Comments (if you don't use them) · Disable Database Repair page · Hide Database Errors from visitors · Robots.txt Blackhole Protection.
Not every event needs to ping you. The notifications configuration lets you route severity tiers and event types to specific channels (email, Slack, webhook) and silence the categories you don't care about. Full breakdown on the notifications page.
WordPress.org checksum manifest · Wordfence Intelligence Community Edition vulnerability feed · AbuseIPDB · Spamhaus · Project Honeypot · CVE databases.
Email provider for alerts (your configured SMTP or Guardian Gaze's default) · Slack webhook URL (if you provide one) · arbitrary webhook for custom routing (Pro).
Passwords · post content · customer PII · session tokens · database contents. Only security-relevant metadata: site URL, plugin/version, finding hashes, IP addresses involved in security events. All traffic is HTTPS.
Configuration profiles can be pushed across all sites in an Agency account, set thresholds, schedules and hardening once, apply everywhere.
Install free, accept the defaults, run the first scan. Come back and tune the knobs once you've seen what's flagged on your site.