RedSecLabs: security research, threat intelligence, consulting.
The London-based cybersecurity firm behind Guardian Gaze. We do more than the plugin; and this page is the longer story.
RedSecLabs is a London-based cybersecurity firm. Our work spans offensive security research, web application security testing, and threat intelligence. Guardian Gaze is one product of that work, but it is not the whole of it.
What we do
RedSecLabs operates across three connected areas:
- Security research. We publish original research on browser security, web application vulnerabilities, supply-chain attacks, and emerging malware techniques. Several findings have been recognised in industry hall-of-fame programmes and academic conferences.
- Threat intelligence. We track real-world compromises across the WordPress ecosystem, turning what we find into pattern libraries, advisories, and detection logic for Guardian Gaze.
- Consulting. Selective engagements with companies whose web infrastructure carries real consequences, financial, regulatory, or reputational. We do code reviews, pen tests, and incident-response retainers.
Why we built Guardian Gaze
For years we were called in to investigate WordPress compromises only after the damage was done, usually after traditional scanners had already declared the site clean. The plugin is our attempt to put what we know up front, where it can prevent the incident rather than explain it afterwards.
Leadership
Security researcher with a long history of published findings on browser and web application security. Speaks regularly at industry conferences. CEO of RedSecLabs.
Press & research inquiries
For research collaboration, vulnerability disclosure unrelated to Guardian Gaze, or press requests, email [email protected]. For Guardian Gaze-specific security issues, please use our disclosure policy.
Corporate details
- RedSecLabs Ltd · Registered in England and Wales
- Registered office: London, United Kingdom
- Founded 2026
Both started as incident work, not a roadmap
RedSecLabs is a security research practice with a background in offensive security and incident response. GuardianGaze Limited is its product subsidiary, registered in England and Wales.
The WordPress plugin exists because of a pattern that kept recurring in cleanup work: a site would be cleaned thoroughly at the filesystem level, declared clean by several scanners, and reinfected within days. The payload had been in the database the whole time: a serialised value in wp_options, a fake transient, a hook that rewrote the files on the next page load. That is why database scanning is in the free plugin rather than behind a licence.
The enterprise platform exists because vendor security questionnaires kept describing organisations that looked entirely different from outside. A supplier would return a confident document while their actual external surface carried expired certificates, exposed management interfaces and mail records that let anyone send as them.
What gets built, and more often what gets refused
Coming from incident response rather than compliance tooling changes what you consider important. Severity ordering follows what actually gets exploited rather than what scores highest on a generic scale, and detection is built around the malware that has not been catalogued yet, because that is what is on the site nobody caught.
It also changes what we decline to claim. A team that has run incident response knows exactly what an external assessment cannot see, which is why the enterprise product states its blind spots on every module page rather than blurring them, and why the plugin's pages say plainly that some compromises sit outside what any WordPress plugin can reach.
The commercial expression of that is which parts are free. Detection is free and complete on the WordPress side (all four layers, including the database) because a scanner that will not tell you what is wrong without payment is not a scanner. What costs money is prevention, response, and the reasoning layer.
Where findings go when they are novel
Detection improves from samples, and the most valuable samples come from real compromises rather than from a corpus. Findings escalated by Agency customers reach the research team directly rather than a support tier, and genuinely novel samples end up improving detection for every user of the free plugin as well.
That loop is deliberate. The people who write a detection are the people who hear when it produces a false positive, and accuracy comes from that feedback rather than from a QA stage added afterwards.
It is also why we would rather have a corrected claim than a comfortable one. We have already removed a claim about a competitor's database scanning that our own research showed was inaccurate, and we would rather do that than defend it.
Common questions
What is the relationship between GuardianGaze and RedSecLabs?
GuardianGaze Limited is a London company registered in England and Wales and a subsidiary of RedSecLabs, a security research practice with a background in offensive security and incident response.
Why is database scanning free?
Because the pattern that led to the plugin was sites being cleaned at the filesystem level, declared clean, and reinfected within days from a payload in wp_options. A scanner that cannot see that is answering half the question.
Who works on the products?
Four functions (research, platform engineering, product, and customer engineering) each shipping end to end. The person who writes a detection hears when it produces a false positive.
Can customers reach the research team?
Agency licences carry an escalation path to the research team for critical findings, rather than routing accuracy questions through a support tier.
Where are you based?
London. GuardianGaze Limited is registered in England and Wales.

