WPGuard watches every WordPress site you manage โ logins, plugins, file changes, hidden malware โ and alerts you within minutes, with one-click quarantine instead of a 2am SSH session.
A lightweight mu-plugin reports to your dashboard โ it never accepts inbound connections, and the dashboard never touches your site's admin credentials.
One PHP file in mu-plugins. No Composer dependencies, PHP 7.4+ compatible, under 64MB memory on every check-in.
Every request is Ed25519-signed with a timestamp and nonce. Replays and unsigned traffic get a silent 404, not a 401.
New admin user, hidden plugin, bot-UA login from 3 IPs at once โ critical events reach you in under a minute across email, Slack, or Telegram.
Core, plugin, and theme files checked against official checksums daily โ plus regex signatures for obfuscated payloads and webshells.
Plugins are compared from disk AND from get_plugins() โ the exact mismatch a self-hiding plugin depends on to stay invisible.
Move a malicious plugin to a deny-all folder instantly โ never deleted, always restorable, always logged in an immutable audit trail.
A stolen editor password was escalated to admin and used from three IPs simultaneously, each posing as Googlebot. A fake plugin hid itself from the admin plugin list using a filter hook, injecting an obfuscated script that pulled its payload address from a public blockchain โ designed specifically to evade static malware scanners.
Set your own price per client site โ WPGuard bills you once per workspace, you bill your clients however you already do.
Start monitoring your sites โ