Configuration, tune Guardian Gaze to your site.
Sensible defaults out of the box, deep control when you need it. Configure scan cadence, scope, thresholds, hardening toggles, notification routing, dashboard preferences and integrations from a single settings screen. No code, no SSH, no wp-config.php edits required.
Availability: in the free plugin on WordPress.org: no account, no licence key · Scheduled scans, daily or weekly

The plugin view: findings, severity and next steps inside the WordPress admin
Configuration at a glance
Cadence
Daily (Free default) · Hourly (Pro default) · Weekly · Custom interval. Set independently for the file scanner and the database scanner. Most sites are well-served by the defaults.
Scope
Full site · Core files only · Plugins only · Themes only · Database only. Useful when you want a quick targeted check rather than a full deep scan.
Execution window
Pin scans to your lowest-traffic hours (default 03:00 to 05:00 server time). Especially relevant for high-traffic e-commerce sites that don’t want scans competing with checkout traffic.
Choosing a schedule that matches how the site changes
The free plugin schedules scans daily or weekly. Pro moves to hourly. The right answer follows from how often the site changes and how much an unnoticed hour costs.
A brochure site that is edited twice a year gains very little from hourly scanning; weekly is honest and sufficient. A store taking card details is a different calculation entirely, because the cost of an unnoticed skimmer accrues per hour of trading, and hourly scanning is cheap against that.
File and database scanning schedule independently, which is useful because they answer different questions and cost different amounts. A site with a large uploads directory and a small database can reasonably run one often and the other less so.
Targeted modes, and when each one earns its place
Full-site scanning is the right default on a schedule. Scoped modes (core, plugins, themes, uploads) are for the specific questions that come up in between.
After updating a plugin, a plugins-only scan answers the question you have in a fraction of the time. After restoring a backup, core-only confirms the restore before you go further. After any incident involving user-submitted files, uploads-only is the fastest way to check the directory a WordPress site is designed to let strangers write to.
Uploads deserves the extra attention. A PHP file there has no legitimate reason to exist, and a scan scoped to that directory finishes quickly enough to run often, which is the property that decides whether a check actually gets run.
Exclusions, thresholds, and the config that survives a month
Every security tool arrives with defaults that suit an average site, and yours is not average in at least one way. The settings worth revisiting are the ones that determine whether you still trust the output in a month.
Exclusions matter most for real-time monitoring, because WordPress writes files constantly during normal operation, caching, logs, uploads, update runs. Excluding paths that change as a matter of course is what keeps the remaining events worth reading, and a monitor whose alerts are all noise gets muted, which is strictly worse than not having one.
Notification thresholds are the same argument in a different place. Route by severity so that critical findings interrupt and routine events do not. The configuration that works is the one that is still unmuted after a month.
Scan cadence by plan
| Plan | Scheduled cadence | On-demand scans |
|---|---|---|
| Free | Daily or weekly | 3 per day |
| Basic | Daily or weekly | 3 per day |
| Pro | Hourly | Unlimited |
| Agency | Hourly, with bulk scheduling across the fleet | Unlimited |
Configuration - common questions
How often should I scan?
Match it to how often the site changes and what an unnoticed hour costs. Weekly is honest for a rarely-edited brochure site; hourly is cheap insurance for a store taking payments.
Can I scan only part of the site?
Yes, core, plugins, themes or uploads. These are in the free plugin and are usually the faster way to answer a specific question.
Can file and database scans run on different schedules?
Yes, they are configured independently.
Why would I exclude a directory?
Because WordPress writes files legitimately all the time. Excluding cache and log paths from real-time monitoring is what keeps the alert stream readable, and a readable stream is the only kind anyone acts on.
Do settings survive plugin updates?
Yes. Configuration persists across updates, and the dashboard shows current state so you can confirm rather than assume.
Works with
Scheduled Scanning →
Set it once and it keeps checking.
Notifications →
Alerts that matter, digests for the rest.
Security Hardening →
Fifteen toggles, applied in one click.
See it on your own site
The free scan takes under five minutes and tells you the truth.

