Skip to content
Feature · For WordPress

Notifications, find out the moment something matters.

Guardian Gaze tells you what changed, when, where, and why, without filling your inbox. Critical findings get immediate alerts. Routine events bundle into a weekly digest. Channels, severities and thresholds are all configurable so you only get pinged for what’s worth interrupting your day.

Availability: included from Pro upwards, via the Premium add-on · Slack and webhook notifications

GuardianGaze plugin view inside the WordPress admin

The plugin view: findings, severity and next steps inside the WordPress admin

At a glance

Notifications at a glance

What it does

New threats (Critical / High)

The scanner found a malware signature, suspicious file, or LLM-flagged backdoor. Critical findings always trigger; High findings trigger by default. Medium / Low / Info bundle into the digest.

How it helps

Risk score change

Your A to D risk grade dropped by a tier (e.g. B → C). Doesn’t fire on small numerical movements within the same grade, only on tier transitions.

What's next

Failed login burst

An IP exceeded the failed-attempt threshold. Configurable, most sites prefer notifications only on lockouts or repeat-offender IPs, not every individual failure.

The problem

An alert nobody reads is not an alert

Every security tool produces notifications and almost every one of them ends up in a folder nobody opens. The pattern is consistent: alerts arrive by email, most are routine, someone writes a filter, and the filter catches the one that mattered along with the ninety that did not.

This is not carelessness. It is what happens to any channel with a poor signal-to-noise ratio and no consequence for ignoring it. The fix is not sending more alerts or marking them urgent; it is sending fewer, to somewhere people already look.

So notifications exist at several tiers with different destinations, and the useful question is not how loud they are but whether the person who can act on one will actually see it.

Channels

Email at Basic, Slack and webhooks at Pro

Email security notifications arrive at Basic, alongside real-time monitoring, because a monitor nobody is told about is a log file. For a single-owner site, email is genuinely the right channel: it is where that person already is.

Slack notifications arrive at Pro, and for a team they change the outcome. A message in a channel the team already watches gets read, discussed and acted on within minutes, and the discussion stays attached to the event rather than happening in a thread nobody else can see.

Webhooks, also Pro, make findings available to anything else you run: a ticketing system, an on-call rotation, an internal dashboard, whatever already holds your operational events. If security findings belong in a system you already have, this is how they get there rather than living in a second place you have to remember to check.

Practice

Route by severity, or you will mute everything

The configuration that survives contact with reality routes by severity rather than sending everything everywhere. Critical findings go to the channel that interrupts people. Routine informational events go somewhere reviewable, or nowhere at all.

The failure mode is well documented and entirely predictable: send every event to the channel that interrupts, and within two weeks the channel is muted, including for the finding that would have mattered. Alert fatigue is not a personality flaw: it is an engineering outcome.

For agencies, digest emails serve the other half of this. A per-event stream across forty sites is unreadable by construction, and a daily summary of what changed across the estate is the only version anybody reads.

FAQ

Notifications - common questions

Which plan has email notifications?

Basic and above. Slack and webhook notifications are Pro.

Can I control what triggers a notification?

Yes, by severity and event type. Routing by severity is the configuration that stays useful, sending everything to one channel is how channels get muted.

Do webhooks support a specific format?

Findings are posted as JSON to the endpoint you supply, so they can be consumed by whatever you already run.

What if I manage many sites?

Digest emails, on Agency, summarise the whole estate rather than sending per-site events. A per-event stream across dozens of sites is unreadable and gets ignored.

Do notifications cost performance?

No. They are dispatched from our infrastructure, not from your server.

Related

Works with

Instant Email Alerts →

Stay informed without logging in.

AI Reports →

Every finding, explained in plain English.

Scheduled Scanning →

Set it once and it keeps checking.

See it on your own site

The free scan takes under five minutes and tells you the truth.