{"id":253211,"date":"2025-12-06T14:59:29","date_gmt":"2025-12-06T14:59:29","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/guardian-gaze-wp\/"},"modified":"2026-07-28T11:37:07","modified_gmt":"2026-07-28T11:37:07","slug":"guardian-gaze","status":"publish","type":"plugin","link":"https:\/\/ug.wordpress.org\/plugins\/guardian-gaze\/","author":23369648,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.4.0","stable_tag":"2.4.0","tested":"7.0.2","requires":"5.3","requires_php":"7.0","requires_plugins":null,"header_name":"Guardian Gaze","header_author":"Redsec Labs","header_description":"Safeguard your WordPress website from evolving malware, brute force attacks, and zero-day vulnerabilities","assets_banners_color":"383b4a","last_updated":"2026-07-28 11:37:07","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.redseclabs.com","header_plugin_uri":"https:\/\/www.guardiangaze.com","header_author_uri":"https:\/\/www.redseclabs.com\/","rating":5,"author_block_rating":0,"active_installs":10,"downloads":1558,"num_ratings":4,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.3.0":{"tag":"1.3.0","author":"redseclabs","date":"2025-12-06 15:07:41"},"1.4.0":{"tag":"1.4.0","author":"redseclabs","date":"2025-12-06 15:18:15"},"2.0.0":{"tag":"2.0.0","author":"redseclabs","date":"2025-12-24 13:25:41"},"2.0.1":{"tag":"2.0.1","author":"redseclabs","date":"2025-12-25 07:45:11"},"2.0.2":{"tag":"2.0.2","author":"redseclabs","date":"2025-12-25 08:24:25"},"2.0.3":{"tag":"2.0.3","author":"redseclabs","date":"2025-12-27 16:11:18"},"2.0.4":{"tag":"2.0.4","author":"redseclabs","date":"2025-12-31 14:49:00"},"2.0.5":{"tag":"2.0.5","author":"redseclabs","date":"2026-01-01 10:03:17"},"2.0.6":{"tag":"2.0.6","author":"redseclabs","date":"2026-01-01 12:48:13"},"2.0.7":{"tag":"2.0.7","author":"redseclabs","date":"2026-01-21 05:31:48"},"2.1.0":{"tag":"2.1.0","author":"redseclabs","date":"2026-01-16 15:21:43"},"2.1.1":{"tag":"2.1.1","author":"redseclabs","date":"2026-01-21 05:33:00"},"2.1.2":{"tag":"2.1.2","author":"redseclabs","date":"2026-01-27 13:18:29"},"2.1.3":{"tag":"2.1.3","author":"redseclabs","date":"2026-01-27 13:18:29"},"2.2.0":{"tag":"2.2.0","author":"redseclabs","date":"2026-02-05 16:20:57"},"2.2.1":{"tag":"2.2.1","author":"redseclabs","date":"2026-02-24 11:07:32"},"2.2.2":{"tag":"2.2.2","author":"redseclabs","date":"2026-03-05 11:44:56"},"2.2.3":{"tag":"2.2.3","author":"redseclabs","date":"2026-03-05 11:49:57"},"2.2.4":{"tag":"2.2.4","author":"redseclabs","date":"2026-03-12 20:14:43"},"2.2.5":{"tag":"2.2.5","author":"redseclabs","date":"2026-03-12 21:59:34"},"2.2.6":{"tag":"2.2.6","author":"redseclabs","date":"2026-03-20 14:59:54"},"2.2.7":{"tag":"2.2.7","author":"redseclabs","date":"2026-04-08 08:55:13"},"2.2.8":{"tag":"2.2.8","author":"redseclabs","date":"2026-05-01 09:40:28"},"2.2.9":{"tag":"2.2.9","author":"redseclabs","date":"2026-07-27 20:48:22"},"2.4.0":{"tag":"2.4.0","author":"redseclabs","date":"2026-07-28 11:37:07"}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":4},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3464419,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3464419,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3464419,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3464419,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.3.0","1.4.0","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.1.0","2.1.1","2.1.2","2.1.3","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9","2.4.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3501440,"resolution":"1","location":"assets","locale":"","width":1334,"height":586},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3501440,"resolution":"2","location":"assets","locale":"","width":1331,"height":559},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3501440,"resolution":"3","location":"assets","locale":"","width":1331,"height":624},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3501440,"resolution":"4","location":"assets","locale":"","width":1330,"height":803},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3501440,"resolution":"5","location":"assets","locale":"","width":1328,"height":733}},"screenshots":{"1":"Guardian Gaze - Dashboard Overview","2":"Malware Scan Results","3":"Database Malware Scanner Results","4":"IP Management Panel","5":"Scheduled Scanning Configuration","6":"File Integrity Monitoring"}},"plugin_section":[],"plugin_tags":[261061,1174,15756,55021,600],"plugin_category":[54],"plugin_contributors":[251784],"plugin_business_model":[],"class_list":["post-253211","plugin","type-plugin","status-publish","hentry","plugin_tags-backdoor-scanner","plugin_tags-firewall","plugin_tags-login-protection","plugin_tags-malware-scanner","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-redseclabs","plugin_committers-redseclabs"],"banners":{"banner":"https:\/\/ps.w.org\/guardian-gaze\/assets\/banner-772x250.png?rev=3464419","banner_2x":"https:\/\/ps.w.org\/guardian-gaze\/assets\/banner-1544x500.png?rev=3464419","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/guardian-gaze\/assets\/icon-128x128.png?rev=3464419","icon_2x":"https:\/\/ps.w.org\/guardian-gaze\/assets\/icon-256x256.png?rev=3464419","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/guardian-gaze\/assets\/screenshot-1.png?rev=3501440","caption":"Guardian Gaze - Dashboard Overview"},{"src":"https:\/\/ps.w.org\/guardian-gaze\/assets\/screenshot-2.png?rev=3501440","caption":"Malware Scan Results"},{"src":"https:\/\/ps.w.org\/guardian-gaze\/assets\/screenshot-3.png?rev=3501440","caption":"Database Malware Scanner Results"},{"src":"https:\/\/ps.w.org\/guardian-gaze\/assets\/screenshot-4.png?rev=3501440","caption":"IP Management Panel"},{"src":"https:\/\/ps.w.org\/guardian-gaze\/assets\/screenshot-5.png?rev=3501440","caption":"Scheduled Scanning Configuration"}],"raw_content":"<!--section=description-->\n<p>Guardian Gaze is a research-driven WordPress security plugin built by <a href=\"https:\/\/www.redseclabs.com\">RedSecLabs<\/a> to help website owners, developers, and agencies find and remove malware, hidden backdoors, injected database content, and unauthorized file changes \u2014 without slowing down your site.<\/p>\n\n<p>Unlike scanners that only check files, Guardian Gaze inspects <strong>both your WordPress files and your database<\/strong>, so malicious code hidden inside posts, options, postmeta, or comments doesn't go unnoticed. Scanning works immediately after activation \u2014 there's no mandatory account, license key, or registration wall blocking you from your first scan.<\/p>\n\n<p><strong>Guardian Gaze focuses on:<\/strong>\n\u2022 WordPress malware and hidden backdoor scanning (core, plugins, themes, uploads)\n\u2022 Database malware scanning (options, posts, postmeta, comments)\n\u2022 File integrity monitoring for unauthorized changes\n\u2022 IP management, country blocking, and traffic filtering\n\u2022 Scheduled, automated scanning with email reports\n\u2022 Clear, centralized visibility into your site's security posture<\/p>\n\n<p>Detection logic is backed by an ongoing threat intelligence feed. Guardian Gaze can run entirely with the malware definitions bundled in the plugin \u2014 optionally linking your site to our server keeps those definitions up to date automatically. Linking is free and takes seconds, but it is never required to scan.<\/p>\n\n<h4>Why Guardian Gaze?<\/h4>\n\n<p>\u2022 <strong>Scan first, decide later.<\/strong> No forced registration screen standing between you and a scan.\n\u2022 <strong>Database-aware.<\/strong> Most free scanners only check files. Guardian Gaze also scans wp_options, wp_posts, wp_postmeta, and wp_comments for injected iframes, base64 payloads, spam links, and eval()-based backdoors.\n\u2022 <strong>Lightweight by design.<\/strong> Scans are structured to avoid heavy resource usage on shared and managed hosting.\n\u2022 <strong>Built by security researchers.<\/strong> RedSecLabs maintains the detection patterns and threat intelligence behind Guardian Gaze.<\/p>\n\n<h3>Key Features<\/h3>\n\n<p><strong><a href=\"https:\/\/www.guardiangaze.com\/wp\/documentation\/malware-scan\">WordPress Malware &amp; Backdoor Scanner<\/a><\/strong>\nA built-in scanner that checks WordPress core files, plugins, themes, and the uploads directory for suspicious or unauthorized code.\n\u2022 Full site, core-only, plugins-only, themes-only, or uploads-only scan modes\n\u2022 Detects modified or infected files and known malware\/backdoor signatures\n\u2022 Highlights changes to WordPress core, plugin, or theme files\n\u2022 No registration required \u2014 scan immediately after activation\n\u2022 Designed for continuous monitoring, not just one-time checks<\/p>\n\n<p><strong>Database Malware Scanner<\/strong>\nScans your WordPress database directly for injected malicious content that file-only scanners miss.\n\u2022 Checks wp_options, wp_posts, wp_postmeta, and wp_comments\n\u2022 Flags hidden iframes, base64-encoded payloads, spam links, JavaScript redirects, and eval()\/backdoor-style code\n\u2022 Severity-rated results (critical, high, medium, low)\n\u2022 One-click cleanup of flagged database records<\/p>\n\n<p><strong><a href=\"https:\/\/www.guardiangaze.com\/wp\/documentation\/file-integrity\">File Integrity Monitoring<\/a><\/strong>\nTracks file changes across your WordPress installation over time.\n\u2022 Detects modified, newly added, or infected files\n\u2022 Highlights changes in WordPress core, plugin, or theme integrity\n\u2022 Lets you review findings before taking action<\/p>\n\n<p><strong><a href=\"https:\/\/www.guardiangaze.com\/wp\/documentation\/ip-management\">IP Management &amp; Firewall-Style Traffic Filtering<\/a><\/strong>\nManage and reduce unwanted or abusive traffic at the IP level.\n\u2022 Manually block or allow specific IP addresses\n\u2022 Country-level blocking for geographic traffic filtering\n\u2022 Reduce bot noise, vulnerability scanners, and probing traffic\nIdeal for sites experiencing repeated probing or targeted attacks.<\/p>\n\n<p><strong><a href=\"https:\/\/www.guardiangaze.com\/wp\/documentation\/scheduled-scanning\">Scheduled Scanning<\/a><\/strong>\nAutomate malware scans and stay ahead of threats.\n\u2022 Daily or weekly scan schedules\n\u2022 Configure scan recipients and email reports\n\u2022 Review results from your dashboard or by email<\/p>\n\n<p><strong><a href=\"https:\/\/www.guardiangaze.com\/wp\/documentation\">Central Security Dashboard<\/a><\/strong>\nOne place to see your site's current security posture:\n\u2022 Latest malware and database scan results\n\u2022 Site health overview (WordPress, PHP, plugin, and theme status)\n\u2022 Blocked and flagged IP addresses\n\u2022 Overall security score with a letter grade<\/p>\n\n<p><strong>Continuous Threat Intelligence Updates<\/strong>\nGuardian Gaze ships with a bundled set of malware definitions, so scanning works out of the box. Optionally link your site to the Guardian Gaze Security Intelligence API to keep those definitions current automatically as new threats emerge.<\/p>\n\n<p><strong>Privacy &amp; Data Use<\/strong>\nGuardian Gaze only calls external services for functionality you're actually using, such as fetching updated malware definitions or optional geolocation lookups.\n\u2022 No unnecessary data collection\n\u2022 No passwords or sensitive post\/page content transmitted\n\u2022 Secure WordPress-native API communication (HTTPS)\n\u2022 Optional features (linking, geolocation) can be skipped or disabled\n\u2022 Only the security metadata required for the feature you're using is processed<\/p>\n\n<p>Full details are listed under \"External Services Used\" below, as required for the WordPress.org plugin directory.<\/p>\n\n<h3>Premium Add-On (Optional)<\/h3>\n\n<p>Guardian Gaze is fully usable on its own \u2014 scanning, database malware detection, file integrity monitoring, IP management, and scheduled scans all work without upgrading. For teams who want additional hardening and automation, the separately-installed <strong><a href=\"https:\/\/guardiangaze.com\/wp\/subscription\/\">Guardian Gaze Premium<\/a><\/strong> add-on unlocks:<\/p>\n\n<p>\u2022 \ud83d\udd12 <strong>AI\/LLM-Assisted Backdoor Analysis<\/strong> \u2014 contextual AI review of suspicious files flagged during a scan, in addition to pattern-based detection\n\u2022 \ud83d\udd12 <strong>Real-Time File Monitor<\/strong> \u2014 SHA-256 baseline snapshots that flag any file change the moment it happens\n\u2022 \ud83d\udd12 <strong>Two-Factor Authentication (2FA)<\/strong> \u2014 TOTP support for Google Authenticator, Authy, 1Password, and similar apps\n\u2022 \ud83d\udd12 <strong>Google reCAPTCHA Login Protection<\/strong> \u2014 reCAPTCHA v2 or v3 on the login form\n\u2022 \ud83d\udd12 <strong>Brute-Force Login Lockout<\/strong> \u2014 automatic IP lockout after repeated failed login attempts\n\u2022 \ud83d\udd12 <strong>One-Click Security Hardening<\/strong> \u2014 toggle common WordPress hardening rules without editing code\n\u2022 \ud83d\udd12 <strong>Security Audit Log<\/strong> \u2014 a rolling log of important admin actions and events\n\u2022 \ud83d\udd12 <strong>File Quarantine &amp; Restore<\/strong> \u2014 isolate infected files safely, then restore or delete them\n\u2022 \ud83d\udd12 <strong>Email Security Notifications<\/strong> \u2014 real-time alerts for scan results and security events<\/p>\n\n<p>Premium requires the free Guardian Gaze plugin to be active and is available at <a href=\"https:\/\/guardiangaze.com\/wp\/subscription\/\">guardiangaze.com<\/a>.<\/p>\n\n<h3>External Services Used<\/h3>\n\n<p>Guardian Gaze connects to the following services to provide security features and functionality:<\/p>\n\n<h4>1. Guardian Gaze API \u2013 wp-api.guardiangaze.com<\/h4>\n\n<p>Used for license validation, malware pattern updates, threat intelligence updates, and optional email reporting.\nData Sent:\n\u2022 Admin email\n\u2022 Site URL\n\u2022 API key\n\u2022 Plugin version and definitions version\n\u2022 IP addresses (for global blocking features)\n\u2022 Scan report data (if email reporting is enabled)\nTerms of Service: https:\/\/www.guardiangaze.com\/terms-of-service\/\nPrivacy Policy: https:\/\/www.guardiangaze.com\/privacy-policy\/<\/p>\n\n<h4>2. Guardian Gaze API \u2013 www.guardiangaze.com<\/h4>\n\n<p>Used for plugin registration.\nData Sent:\n\u2022 Site URL\nTerms of Service: https:\/\/www.guardiangaze.com\/terms-of-service\/\nPrivacy Policy: https:\/\/www.guardiangaze.com\/privacy-policy\/<\/p>\n\n<h4>3. WordPress.org API \u2013 api.wordpress.org<\/h4>\n\n<p>Used for WordPress core file integrity checks and version validation.\nData Sent:\n\u2022 WordPress version\n\u2022 Locale \/ language\nTerms of Service: https:\/\/wordpress.org\/about\/privacy\/\nPrivacy Policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<h4>4. Guardian Gaze Country API \u2013 wp-api.guardiangaze.com\/country.php<\/h4>\n\n<p>Used for IP address geolocation.\nData Sent:\n\u2022 Visitor IP address\nTerms of Service: https:\/\/www.guardiangaze.com\/terms-of-service\/\nPrivacy Policy: https:\/\/www.guardiangaze.com\/privacy-policy\/<\/p>\n\n<p><strong>Important Notes<\/strong>\n\u2022 All API calls use WordPress wp_remote_get() and wp_remote_post()\n\u2022 Data is transferred over HTTPS whenever available\n\u2022 No user passwords or sensitive content is collected or transmitted\n\u2022 Geolocation lookups are cached to limit external requests\n\u2022 Registering\/linking your site is optional and only affects how current your malware definitions are \u2014 it does not gate scanning itself<\/p>\n\n<h3>About RedSecLabs<\/h3>\n\n<p><a href=\"https:\/\/www.redseclabs.com\">RedSecLabs<\/a> is a cybersecurity company focused on threat research, detection engineering, and building defensive tools for real-world scenarios.\nGuardian Gaze reflects this philosophy by offering a transparent, research-backed WordPress security plugin built for long-term reliability and practical protection.<\/p>\n\n<!--section=installation-->\n<h4>From your WordPress dashboard<\/h4>\n\n<ol>\n<li>Go to Plugins \u2192 Add New.<\/li>\n<li>Search for \"Guardian Gaze\".<\/li>\n<li>Click Install Now, then Activate.<\/li>\n<li>Go to Guardian Gaze \u2192 Malware Scan and click Start Scan \u2014 no registration required.<\/li>\n<\/ol>\n\n<h4>Manual upload<\/h4>\n\n<ol>\n<li>Download the plugin zip file.<\/li>\n<li>Go to Plugins \u2192 Add New \u2192 Upload Plugin in your WordPress dashboard.<\/li>\n<li>Select the zip file and click Install Now, then Activate.<\/li>\n<li>Go to Guardian Gaze \u2192 Malware Scan and click Start Scan.<\/li>\n<\/ol>\n\n<h4>Optional: link your site<\/h4>\n\n<p>Linking your site (Guardian Gaze \u2192 Malware Scan \u2192 Link Website) is free and optional. It keeps your malware definitions up to date automatically; it is never required to run a scan.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20to%20register%20or%20link%20my%20site%20to%20start%20scanning%3F\"><h3>Do I need to register or link my site to start scanning?<\/h3><\/dt>\n<dd><p>No. You can run a malware scan, a database scan, or a file integrity check immediately after activating the plugin \u2014 there is no registration wall. Linking your site (free, optional) simply keeps your malware definitions up to date automatically; scanning works with the bundled definitions either way.<\/p><\/dd>\n<dt id=\"does%20guardian%20gaze%20scan%20my%20database%2C%20or%20just%20files%3F\"><h3>Does Guardian Gaze scan my database, or just files?<\/h3><\/dt>\n<dd><p>Both. The built-in Database Malware Scanner checks wp_options, wp_posts, wp_postmeta, and wp_comments for injected iframes, base64-encoded payloads, spam links, and backdoor-style code \u2014 content that a file-only scanner would never see. File scanning covers WordPress core, plugins, themes, and uploads.<\/p><\/dd>\n<dt id=\"what%20differentiates%20guardian%20gaze%20from%20other%20wordpress%20security%20plugins%3F\"><h3>What differentiates Guardian Gaze from other WordPress security plugins?<\/h3><\/dt>\n<dd><p>Guardian Gaze combines file-based and database-based malware scanning in one plugin, without requiring registration before you can scan. Built by RedSecLabs, it focuses on research-driven detection engineering, continuous monitoring, and performance-conscious design \u2014 practical WordPress security without aggressive lockouts or unnecessary system overhead.<\/p><\/dd>\n<dt id=\"how%20does%20the%20guardian%20gaze%20wordpress%20malware%20scanner%20work%3F\"><h3>How does the Guardian Gaze WordPress malware scanner work?<\/h3><\/dt>\n<dd><p>Guardian Gaze scans WordPress core files, plugins, and themes for unauthorized changes and known malware\/backdoor patterns, and separately scans your database tables for injected malicious content. It monitors file integrity and highlights suspicious modifications inside your WordPress installation so you can review them before taking action.<\/p><\/dd>\n<dt id=\"how%20does%20guardian%20gaze%20protect%20wordpress%20sites%20from%20attackers%3F\"><h3>How does Guardian Gaze protect WordPress sites from attackers?<\/h3><\/dt>\n<dd><p>The free plugin provides:\n\u2022 File-based malware and backdoor pattern scanning\n\u2022 Database malware scanning\n\u2022 File integrity monitoring\n\u2022 IP management and country-level traffic filtering\n\u2022 Scheduled scanning with email reports\nThe optional Premium add-on layers on AI-assisted analysis, 2FA, reCAPTCHA, brute-force lockout, and automated hardening \u2014 see \"Premium Add-On\" above.<\/p><\/dd>\n<dt id=\"what%20login%20and%20traffic%20protection%20is%20included%20in%20the%20free%20plugin%3F\"><h3>What login and traffic protection is included in the free plugin?<\/h3><\/dt>\n<dd><p>The free plugin includes IP management: you can manually block or allow specific IP addresses and apply country-level blocking to cut down on probing, bot traffic, and repeated attack attempts, including against your login page. Advanced login security \u2014 two-factor authentication, Google reCAPTCHA, and automatic brute-force lockout \u2014 is available through the optional Premium add-on.<\/p><\/dd>\n<dt id=\"how%20will%20i%20be%20alerted%20if%20my%20site%20has%20a%20security%20problem%3F\"><h3>How will I be alerted if my site has a security problem?<\/h3><\/dt>\n<dd><p>Scheduled scans can email you a report on a daily or weekly basis. Scan results, including any threats found, are also always visible in the Guardian Gaze dashboard.<\/p><\/dd>\n<dt id=\"do%20i%20still%20need%20guardian%20gaze%20if%20i%20use%20cloudflare%20or%20another%20cloud%20firewall%3F\"><h3>Do I still need Guardian Gaze if I use Cloudflare or another cloud firewall?<\/h3><\/dt>\n<dd><p>Yes. Cloud-based firewalls like Cloudflare filter network-level traffic and block certain attack patterns, but they cannot see inside your WordPress files or database. They do not scan your WordPress core, plugins, themes, or database tables for malware, hidden backdoors, or unauthorized modifications. Guardian Gaze operates inside your WordPress environment, providing application-level and database-level detection that infrastructure-level firewalls cannot.<\/p><\/dd>\n<dt id=\"will%20guardian%20gaze%20slow%20down%20my%20wordpress%20website%3F\"><h3>Will Guardian Gaze slow down my WordPress website?<\/h3><\/dt>\n<dd><p>Guardian Gaze is designed to be lightweight and performance-conscious. Scans are structured to reduce unnecessary resource usage while still providing thorough file and database coverage.<\/p><\/dd>\n<dt id=\"what%20if%20my%20wordpress%20site%20has%20already%20been%20hacked%3F\"><h3>What if my WordPress site has already been hacked?<\/h3><\/dt>\n<dd><p>Guardian Gaze can detect modified core files, suspicious code, injected database content, and potential backdoors on already-compromised sites. Scan results help identify infection points across both files and the database so you can review and remediate them.<\/p><\/dd>\n<dt id=\"does%20guardian%20gaze%20collect%20personal%20or%20sensitive%20data%3F\"><h3>Does Guardian Gaze collect personal or sensitive data?<\/h3><\/dt>\n<dd><p>No. Guardian Gaze does not collect passwords or sensitive post content. Only limited security-related metadata required for the feature you're using is processed, and optional services (linking, geolocation) can be skipped entirely. See \"External Services Used\" above for full details.<\/p><\/dd>\n<dt id=\"is%20guardian%20gaze%20suitable%20for%20developers%20and%20agencies%3F\"><h3>Is Guardian Gaze suitable for developers and agencies?<\/h3><\/dt>\n<dd><p>Yes. File integrity monitoring, database scanning, IP management, and a centralized dashboard make it straightforward to keep an eye on multiple WordPress installations. The optional Premium add-on adds audit logging and file quarantine for teams managing client sites.<\/p><\/dd>\n<dt id=\"what%27s%20the%20difference%20between%20guardian%20gaze%20free%20and%20premium%3F\"><h3>What's the difference between Guardian Gaze Free and Premium?<\/h3><\/dt>\n<dd><p>Guardian Gaze Free covers file and database malware scanning, file integrity monitoring, IP management, and scheduled scanning \u2014 fully functional on its own. The optional <a href=\"https:\/\/guardiangaze.com\/wp\/subscription\/\">Premium add-on<\/a> adds AI-assisted backdoor analysis, real-time file monitoring, 2FA, reCAPTCHA, brute-force lockout, one-click hardening, an audit log, file quarantine, and email notifications.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.4.0<\/h4>\n\n<ul>\n<li>Added Database Malware Scanner \u2014 scans wp_options, wp_posts, wp_postmeta, and wp_comments for injected code, hidden iframes, spam links, and obfuscated payloads, with one-click cleanup of flagged records.<\/li>\n<li>Scanning no longer requires linking your site first \u2014 the Malware Scan page is usable immediately; linking is now optional and only needed to receive the latest threat definitions.<\/li>\n<\/ul>\n\n<h4>2.2.9<\/h4>\n\n<ul>\n<li>Added new feature to scan updated files.<\/li>\n<li>Support for WordPress up to 7.0.<\/li>\n<\/ul>\n\n<h4>2.2.8<\/h4>\n\n<ul>\n<li>Added new feature to scan updated files.<\/li>\n<li>Support for php 7.0.<\/li>\n<li>Support for WordPress 4.7.<\/li>\n<\/ul>\n\n<h4>2.2.7<\/h4>\n\n<ul>\n<li>Improved IP management admin UI with cleaner tab navigation, toggle switches, and country blocking controls.<\/li>\n<li>Added loading states and success\/error feedback on IP whitelist, blacklist, and country blocking toggles.<\/li>\n<li>Replaced country blocking radio inputs with accessible toggle sliders.<\/li>\n<li>Added toast notifications for all IP management actions.<\/li>\n<li>Fixed country blocking toggle not saving correctly.<\/li>\n<li>Fixed external service links in readme not rendering correctly on WordPress.org.<\/li>\n<li>Resolved WordPress Plugin Check compliance issues across multiple files.<\/li>\n<li>Fixed unprefixed PHP variables in dashboard display causing Plugin Check warnings.<\/li>\n<li>Fixed incorrect use of esc_html_e() on SVG attribute values.<\/li>\n<li>Fixed direct database queries missing caching or proper phpcs annotations.<\/li>\n<li>Fixed %i placeholder incompatibility with WordPress 4.7 minimum requirement.<\/li>\n<li>Secured scheduler display file inclusion against arbitrary path injection.<\/li>\n<li>Premium plugin now enqueues its own CSS and JS via admin_enqueue_scripts instead of inline styles.<\/li>\n<\/ul>\n\n<h4>2.2.6<\/h4>\n\n<ul>\n<li>Fixed bug in file integrity monitoring.<\/li>\n<li>Fixed bug in login security.<\/li>\n<li>Fixed bug in IP management.<\/li>\n<\/ul>\n\n<h4>2.2.5<\/h4>\n\n<p>Fixed bugs<\/p>\n\n<h4>2.2.4<\/h4>\n\n<ul>\n<li>Fixed bug in file integrity monitoring.<\/li>\n<li>Fixed bug in login security.<\/li>\n<li>Fixed bug in IP management.<\/li>\n<li>Removed google recaptcha integration.<\/li>\n<li>Removed country request data from dashboard.<\/li>\n<li>Removed 2FA authentication for Login security.<\/li>\n<\/ul>\n\n<h4>2.2.3<\/h4>\n\n<ul>\n<li>2FA authentication added for Login security.<\/li>\n<li>Added new feature to scan updated files.<\/li>\n<li>Google recaptcha integration.<\/li>\n<li>Fixed bug in file integrity monitoring.<\/li>\n<\/ul>\n\n<h4>2.2.2<\/h4>\n\n<ul>\n<li>2FA authentication added for Login security.<\/li>\n<li>Added new feature to scan updated files.<\/li>\n<li>Goolge recaptcha integration.<\/li>\n<li>Fixed bug in file integrity monitoring.<\/li>\n<\/ul>\n\n<h4>2.2.1<\/h4>\n\n<ul>\n<li>Added new feature to scan updated files.<\/li>\n<li>Support for php 7.0.<\/li>\n<li>Support for WordPress 4.7.<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>Added new feature to scan updated files.<\/li>\n<\/ul>\n\n<h4>2.1.3<\/h4>\n\n<ul>\n<li>Fixed bugs.<\/li>\n<\/ul>\n\n<h4>2.1.2<\/h4>\n\n<ul>\n<li>Fixed bug in file integrity monitoring.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Added new feature to scan updated files.<\/li>\n<\/ul>\n\n<h4>2.0.8<\/h4>\n\n<ul>\n<li>Fixed security keys regeneration creating too many backups.<\/li>\n<\/ul>\n\n<h4>2.0.7<\/h4>\n\n<ul>\n<li>Fixed bugs email report delivery.<\/li>\n<\/ul>\n\n<h4>2.0.6<\/h4>\n\n<ul>\n<li>Fixed bug in file integrity monitoring.<\/li>\n<\/ul>\n\n<h4>2.0.5<\/h4>\n\n<ul>\n<li>Added AI scan feature.<\/li>\n<\/ul>\n\n<h4>2.0.4<\/h4>\n\n<ul>\n<li>Fixed bug in file integrity monitoring.<\/li>\n<\/ul>\n\n<h4>2.0.2<\/h4>\n\n<ul>\n<li>Fixed bug in file integrity monitoring.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<\/ul>","raw_excerpt":"WordPress malware scanner and firewall that detects, blocks, and helps you remove malware, hidden backdoors, and brute-force attacks.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/253211","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=253211"}],"author":[{"embeddable":true,"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/redseclabs"}],"wp:attachment":[{"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=253211"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=253211"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=253211"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=253211"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=253211"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ug.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=253211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}