Guardian Gaze creates a secure baseline of every core, plugin, theme, and custom file on your site. On every scan, it compares current files against this baseline to instantly detect unauthorized changes, new files, or deletions, the most common signs of a hack. Spot a suspicious change? Review the diff, then approve it as legitimate or flag it for removal, all from one dashboard.
Almost every WordPress compromise leaves a fingerprint on disk, a webshell dropped intouploads/, a backdoor injected into a plugin'sfunctions.php, or a hijackedwp-config.php. Attackers count on the fact that nobody is actually watching the filesystem. Real-time monitoring removes that assumption.
Unlike scanners that only look at known-bad signatures, integrity monitoring catches zero-day modifications too, because anything that doesn't match the baseline gets flagged, regardless of whether anyone has seen that malware before.
On install, Guardian Gaze fingerprints every file in core, themes, plugins, mu-plugins and your uploads directory with a SHA-256 hash.
Every scheduled scan re-hashes the filesystem and compares against the baseline. New files, changed files and deletions are all surfaced.
For text files you see a side-by-side diff of what changed, not just that it changed. Context matters for triage.
Legitimate change? Approve it to update the baseline. Suspicious? Flag for removal, Guardian Gaze guides you through restoring a clean copy.
Baseline file monitoring is included on every tier, including the free plugin. Real-time change detection is a Pro feature; the free tier checks once daily.