Available on Free
Features · Configuration

WordPress security notifications, know the moment something matters.

Guardian Gaze tells you what changed, when, where, and why, without filling your inbox. Critical findings get immediate alerts. Routine events bundle into a weekly digest. Channels, severities and thresholds are all configurable so you only get pinged for what's worth interrupting your day.

What triggers an alert

Five categories of events that warrant a notification.

Guardian Gaze fires notifications on a fixed set of categories, chosen because each one is something the site owner needs to know about, not something the dashboard alone is enough for. Each category is independently configurable: silence the ones that don't apply to your workflow.

🚨

New threats (Critical / High)

The scanner found a malware signature, suspicious file, or LLM-flagged backdoor. Critical findings always trigger; High findings trigger by default. Medium / Low / Info bundle into the digest.

📉

Risk score change

Your A to D risk grade dropped by a tier (e.g. B → C). Doesn't fire on small numerical movements within the same grade, only on tier transitions.

🔐

Failed login burst

An IP exceeded the failed-attempt threshold. Configurable, most sites prefer notifications only on lockouts or repeat-offender IPs, not every individual failure.

📂

File integrity change

A file outside an expected version-bump batch changed. Suppressed for known updates (plugin/theme install or update); fired immediately for unattributed changes.

📊

Weekly summary digest

One email per week with everything that happened: scan results, integrity drift, blocked IPs, login lockouts, risk-score movement. Bundles all the "nice to know" items.

🛡️

Hardening regressions

A hardening setting was disabled (intentional or not). Important because regression here is often a sign of compromise, attackers re-enable XML-RPC and File Editor to maintain access.

Channels

Email, Slack, and webhook routing.

✉️

Email

Default channel. Goes to the site's admin email by default; supports multiple recipients (Pro). Uses your configured WP SMTP setup if present, otherwise Guardian Gaze's default delivery.

💬

Slack Pro

Paste an incoming-webhook URL from your Slack workspace; Guardian Gaze posts threaded alerts to the channel of your choice. Critical findings include the file path and quick action links.

🔌

Webhook Pro

Generic webhook for any other destination, PagerDuty, OpsGenie, Microsoft Teams, your own ingestion endpoint. Signed payloads so you can verify they're really from Guardian Gaze.

Avoiding alert fatigue

The notification system is tuned against fatigue.

Plenty of WordPress security plugins email you so much that the alerts become noise, and you stop paying attention right when there's something worth seeing. Guardian Gaze is built to avoid that.

  • Severity-based routing. Critical and High get immediate pings; Medium / Low / Info go to the digest. Most days, you only see the digest.
  • Bursts are bundled. If 50 things happen in 10 minutes (likely during a real attack), you get one summary alert, not 50 individual emails.
  • Known-cause suppression. File changes during a plugin update? Not flagged. Risk score moves during a configuration cleanup? Not flagged.
  • Per-event silencing. Don't want to know about failed logins? Silence that category without touching the rest.
  • Snooze on individual findings. A flagged file you've already decided is a false positive can be snoozed; the system won't re-alert on subsequent scans of the same file.
  • Quiet hours. Configurable do-not-disturb window for non-critical alerts. Critical always bypasses (you do want a Critical at 2am).
Anatomy of an alert

What you actually see in your inbox.

A Guardian Gaze alert is designed to give you a complete picture from the email body alone, so you can triage from your phone without logging in to the dashboard.

Subject line

Severity tier + site nickname + one-line finding summary.
e.g. [Critical · acme-shop] PHP web shell in uploads/2024/02/

Body, top section

The finding's plain-English description, the file path, the severity badge, the timestamp. Designed to be readable from a phone notification preview.

Body, middle section

Recommended action(s) and one-click quarantine link (signed and authenticated). For Critical findings, also a "call our team" escalation path on Agency plans.

Body, footer

Link to the full report in the Guardian Gaze dashboard, link to silence this category, link to the Notifications settings.

Tier availability

Channels and digests at every tier.

CapabilityFreeProAgency
Email alerts (single recipient)
Multiple email recipients
Weekly digest
Slack webhook
Generic webhook (PagerDuty, Teams, etc.)
Quiet hours
Multi-site digest (one email for all sites)
Client-facing branded notifications

Stop checking dashboards. Get pinged when it matters.

Set up email alerts in under two minutes. Add Slack or webhooks on Pro for richer routing.