Now monitoring WordPress sites in real time

Catch a compromised site before your client does.

WPGuard watches every WordPress site you manage โ€” logins, plugins, file changes, hidden malware โ€” and alerts you within minutes, with one-click quarantine instead of a 2am SSH session.

No credit card required ยท Signed agent, zero admin-password access to your sites
5 minagent check-in interval
Ed25519signed, per-site key pairs
7allow-listed remote actions โ€” never eval or shell
Quarantinenever delete โ€” always reversible
How it works

One small agent. Full visibility.

A lightweight mu-plugin reports to your dashboard โ€” it never accepts inbound connections, and the dashboard never touches your site's admin credentials.

๐Ÿ”Œ

Drop-in agent

One PHP file in mu-plugins. No Composer dependencies, PHP 7.4+ compatible, under 64MB memory on every check-in.

๐Ÿ“ก

Signed check-ins

Every request is Ed25519-signed with a timestamp and nonce. Replays and unsigned traffic get a silent 404, not a 401.

๐Ÿšจ

Real-time alerts

New admin user, hidden plugin, bot-UA login from 3 IPs at once โ€” critical events reach you in under a minute across email, Slack, or Telegram.

๐Ÿงฌ

File integrity

Core, plugin, and theme files checked against official checksums daily โ€” plus regex signatures for obfuscated payloads and webshells.

๐Ÿ—‚

Disk vs. database

Plugins are compared from disk AND from get_plugins() โ€” the exact mismatch a self-hiding plugin depends on to stay invisible.

โธ

One-click quarantine

Move a malicious plugin to a deny-all folder instantly โ€” never deleted, always restorable, always logged in an immutable audit trail.

Why we built this

This happened to a real client site.

A stolen editor password was escalated to admin and used from three IPs simultaneously, each posing as Googlebot. A fake plugin hid itself from the admin plugin list using a filter hook, injecting an obfuscated script that pulled its payload address from a public blockchain โ€” designed specifically to evade static malware scanners.

  • Compromised credentials used from multiple IPs within the same minute
  • A plugin invisible in wp-admin, but present on disk
  • An obfuscated script fetching its command server from a smart contract
  • No alert, no log, no way to know โ€” until it was too late

Every site. One dashboard. Priced per site.

Set your own price per client site โ€” WPGuard bills you once per workspace, you bill your clients however you already do.

Start monitoring your sites โ†’