Guardian Gaze Security – AI Based Malware Scanner, Firewall and Login Protection
Guardian Gaze is a research-driven WordPress security plugin built by RedSecLabs to help website owners, developers, and agencies find and remove malware, hidden backdoors, injected database content, and unauthorized file changes — without slowing down your site. Unlike scanners that only check files, Guardian Gaze inspects both your WordPress files and your database, so malicious code hidden inside posts, options, postmeta, or comments doesn’t go unnoticed. Scanning works immediately after activation — there’s no mandatory account, license key, or registration wall blocking you from your first scan. Guardian Gaze focuses on: • WordPress malware and hidden backdoor scanning (core, plugins, themes, uploads) • Database malware scanning (options, posts, postmeta, comments) • File integrity monitoring for unauthorized changes • IP management, country blocking, and traffic filtering • Scheduled, automated scanning with email reports • Clear, centralized visibility into your site’s security posture Detection logic is backed by an ongoing threat intelligence feed. Guardian Gaze can run entirely with the malware definitions bundled in the plugin — optionally linking your site to our server keeps those definitions up to date automatically. Linking is free and takes seconds, but it is never required to scan. Why Guardian Gaze? • Scan first, decide later. No forced registration screen standing between you and a scan. • Database-aware. Most free scanners only check files. Guardian Gaze also scans wp_options, wp_posts, wp_postmeta, and wp_comments for injected iframes, base64 payloads, spam links, and eval()-based backdoors. • Lightweight by design. Scans are structured to avoid heavy resource usage on shared and managed hosting. • Built by security researchers. RedSecLabs maintains the detection patterns and threat intelligence behind Guardian Gaze. Key Features WordPress Malware & Backdoor Scanner A built-in scanner that checks WordPress core files, plugins, themes, and the uploads directory for suspicious or unauthorized code. • Full site, core-only, plugins-only, themes-only, or uploads-only scan modes • Detects modified or infected files and known malware/backdoor signatures • Highlights changes to WordPress core, plugin, or theme files • No registration required — scan immediately after activation • Designed for continuous monitoring, not just one-time checks Database Malware Scanner Scans your WordPress database directly for injected malicious content that file-only scanners miss. • Checks wp_options, wp_posts, wp_postmeta, and wp_comments • Flags hidden iframes, base64-encoded payloads, spam links, JavaScript redirects, and eval()/backdoor-style code • Severity-rated results (critical, high, medium, low) • One-click cleanup of flagged database records File Integrity Monitoring Tracks file changes across your WordPress installation over time. • Detects modified, newly added, or infected files • Highlights changes in WordPress core, plugin, or theme integrity • Lets you review findings before taking action IP Management & Firewall-Style Traffic Filtering Manage and reduce unwanted or abusive traffic at the IP level. • Manually block or allow specific IP addresses • Country-level blocking for geographic traffic filtering • Reduce bot noise, vulnerability scanners, and probing traffic Ideal for sites experiencing repeated probing or targeted attacks. Scheduled Scanning Automate malware scans and stay ahead of threats. • Daily or weekly scan schedules • Configure scan recipients and email reports • Review results from your dashboard or by email Security Notifications Get emailed the moment something worth knowing about happens, instead of having to check the dashboard. • Alert when an administrator account logs in • Alert when a plugin, theme, or WordPress core update becomes available (sent once per new version, no duplicates) • Set a custom alert recipient, or use the site admin email Central Security Dashboard One place to see your site’s current security posture: • Latest malware and database scan results • Site health overview (WordPress, PHP, plugin, and theme status) • Blocked and flagged IP addresses • Overall security score with a letter grade Continuous Threat Intelligence Updates Guardian Gaze ships with a bundled set of malware definitions, so scanning works out of the box. Optionally link your site to the Guardian Gaze Security Intelligence API to keep those definitions current automatically as new threats emerge. Privacy & Data Use Guardian Gaze only calls external services for functionality you’re actually using, such as fetching updated malware definitions or optional geolocation lookups. • No unnecessary data collection • No passwords or sensitive post/page content transmitted • Secure WordPress-native API communication (HTTPS) • Optional features (linking, geolocation) can be skipped or disabled • Only the security metadata required for the feature you’re using is processed Full details are listed under “External Services Used” below, as required for the WordPress.org plugin directory. Premium Add-On (Optional) Guardian Gaze is fully usable on its own — scanning, database malware detection, file integrity monitoring, IP management, and scheduled scans all work without upgrading. For teams who want additional hardening and automation, the separately-installed Guardian Gaze Premium add-on unlocks: • 🔒 AI/LLM-Assisted Backdoor Analysis — contextual AI review of suspicious files flagged during a scan, in addition to pattern-based detection • 🔒 Real-Time File Monitor — SHA-256 baseline snapshots that flag any file change the moment it happens • 🔒 Two-Factor Authentication (2FA) — TOTP support for Google Authenticator, Authy, 1Password, and similar apps • 🔒 Google reCAPTCHA Login Protection — reCAPTCHA v2 or v3 on the login form • 🔒 Brute-Force Login Lockout — automatic IP lockout after repeated failed login attempts • 🔒 One-Click Security Hardening — toggle common WordPress hardening rules without editing code • 🔒 Security Audit Log — a permanent log of important admin actions and events • 🔒 File Quarantine & Restore — isolate infected files safely, then restore or delete them Premium requires the free Guardian Gaze plugin to be active and is available at guardiangaze.com. External Services Used Guardian Gaze connects to the following services to provide security features and functionality: 1. Guardian Gaze API – wp-api.guardiangaze.com Used for license validation, malware pattern updates, threat intelligence updates, and optional email reporting. Data Sent: • Admin email • Site URL • API key • Plugin version and definitions version • IP addresses (for global blocking features) • Scan report data (if email reporting is enabled) Terms of Service: https://www.guardiangaze.com/terms-of-service/ Privacy Policy: https://www.guardiangaze.com/privacy-policy/ 2. Guardian Gaze API – www.guardiangaze.com Used for plugin registration. Data Sent: • Site URL Terms of Service: https://www.guardiangaze.com/terms-of-service/ Privacy Policy: https://www.guardiangaze.com/privacy-policy/ 3. WordPress.org API – api.wordpress.org Used for WordPress core file integrity checks and version validation. Data Sent: • WordPress version • Locale / language Terms of Service: https://wordpress.org/about/privacy/ Privacy Policy: https://wordpress.org/about/privacy/ 4. Guardian Gaze Country API – wp-api.guardiangaze.com/country.php Used for IP address geolocation. Data Sent: • Visitor IP address Terms of Service: https://www.guardiangaze.com/terms-of-service/ Privacy Policy: https://www.guardiangaze.com/privacy-policy/ Important Notes • All API calls use WordPress wp_remote_get() and wp_remote_post() • Data is transferred over HTTPS whenever available • No user passwords or sensitive content is collected or transmitted • Geolocation lookups are cached to limit external requests • Registering/linking your site is optional and only affects how current your malware definitions are — it does not gate scanning itself About RedSecLabs RedSecLabs is a cybersecurity company focused on threat research, detection engineering, and building defensive tools for real-world scenarios. Guardian Gaze reflects this philosophy by offering a transparent, research-backed WordPress security plugin built for long-term reliability and practical protection.
Top keywords
- wordpress21×1.82%
- gaze18×1.56%
- guardian18×1.56%
- guardian gaze18×1.56%
- malware14×1.21%
- security13×1.12%
- scan11×0.95%
- site11×0.95%
- com10×0.87%
- guardiangaze10×0.87%
- guardiangaze com10×0.87%
- https10×0.87%
SecuPress with Simple SSL – Simple and Performant Security
Test it now! You can test SecuPress Free now. YOU MADE IT, WE KEEP IT SAFE! The most advanced WordPress Protection on the market. SecuPress is focused on WordPress attacks and Malwares, not just “usual web protections” like many. Protect your WordPress with malware scans ; block bots & suspicious IPs. Get a complete WordPress security toolkit for free or as a pro plugin. SecuPress is GDPR compliant. What’s the difference between free and pro version? If you are proactive, our free WordPress security plugin is a great choice! No time to activate weekly scans? Then SecuPress pro is the way to go. Our plugin takes care of everything with automated tasks. Here are some of our most popular features: Brute Force Login Protection Password Spraying Protection Firewall features Security alerts (1) Malware Scanner (1) Block country by geolocation (1) We have included some features you won’t find in most WordPress security plugins: Protection of Security Keys Block visits from Bad Bots Vulnerable Plugins & Themes detection (1) Security Reports in PDF format (1) You can check out Frequently Asked Questions or get in touch with our support. Want to know all about SecuPress? You can read our documentation here: docs.secupress.me. How will you know it works? Well, we have a dedicated security scanner that will give you a clear security grade and report for your website. This way, you’ll know exactly what to fix. WordPress Features Security Audit SecuPress is the only plugin with a full scanner able to fix the issues for you. And when it requires a decision from you, it will ask you before proceeding. With this feature, you can check 35 security points in 5 minutes and let us take care of the rest. Once done, you get a security grade that gives you a clear idea of what your security level is. You can export this analysis in PDF format to share with others (clients or colleagues) (1). Users & Login This feature is the easiest way to make sure your users’ data is protected and to keep their accounts from being compromised. With this feature you can limit the number of bad login attempts, ban non-existing usernames login attempts and set a non-login time slot. SecuPress also makes sure you control the sessions of your users. SecuPress also adds a 2FA (Two Factor Authentication) because it’s almost a mandatory feature when it comes to WordPress security! The plugin also gives you greater user and password control as you can set: Password lifetimes for your users. Enforce strong password use. Forbid the use of vague usernames like www or admin. Tired of bots finding your WordPress login page? Finally, don’t let bots find your login page, just move it with the famous Move Login plugin, now included in SecuPress. Plugins and Themes SecuPress helps you detect themes and plugins that are vulnerable or that have been tampered with to include malicious code. If you install one of these, your security module will send out an email alert and give you a warning in WordPress. SecuPress takes security further by limiting plugin activation, deactivation, installation and removal in your production (live) website. Plugin and theme uploads via .zip files will be on lockdown as well to block off this easy hacking route. WordPress Core SecuPress reinforces the WordPress Core to keep it safe. The security plugin optimizes what’s under the hood to secure the config file by setting the proper parameters. Sensitive Data SecuPress secures content in many ways: The plugin secures WordPress Endpoints and APIs by blocking bad requests for XML-RPC or REST API. It blocks bad bots with its Robots Blackhole feature. It provides an anti-hotlink feature to preserve your bandwidth. The plugin packs 7 anti-disclose security modules to make sure no precious information is available to hackers in your PHP or WordPress itself. Profile and SecuPress settings pages are password protected to keep sensitive information away from prying eyes. Firewall SecuPress is one of the most efficient WordPress bouncer you’ll ever see! The plugin blocks malicious incoming requests. It blocks bad User Agents (no bad crawlers allowed). Bad requests methods also get the boot in a single click. URLs are kept in check: no bad URL contents. SQL injection scanners are kept out as well. Brute force attempts are stopped in their tracks. GeoIP Blocking by country gives you more control over your traffic. Malware Scan SecuPress has a unique malware scan developed by our security experts. It hunts down bad files and provides you with an easy step-by-step report that lets you take action. It looks into: Bad files in your FTP. Your uploads folder for dangerous files. Potential phishing attempts via index.php loads. Backups We know firsthand how painful it is to pick up the pieces after an attack damages your WordPress. SecuPress preserves your data to help you avoid lost content or settings if your website comes under attack. The plugin backs up your database and files and lets you download them to guarantee you peace of mind. Anti Spam Did you know that 60% of the traffic on the Internet is generated by bots? Most of them happen to be spam bots. We developed our own anti-spam system that works quietly in the background. Just activate it and enjoy a spam free experience. Alerts Alerts are an essential tool when your website is under attack. When something important happens on your website, SecuPress will send you an alert via email. We’re working on alerts via SMS, Slack & Twitter as well. You also receive a daily report that provides a debrief of the attempted attack and all the activities blocked by SecuPress. Scheduled Security Tasks SecuPress can run 3 separate scheduled tasks for you. It’s like having a security patrol on your WordPress. Scheduled Scanner: SecuPress scans your website to detect any issues. After the scan is complete, you get a report in your inbox outlining any actions you have to take to protect your website. Scheduled Backup: our team knows that everyone at one time or another forgets to back things up. We made it an automatic task to help ensure you always can recover from an attack with your content safe. Scheduled Malware Scan: this security feature scans your website at regular intervals to hunt down any malware that may have gotten into your WordPress. Logs SecuPress will keep a log of important security activities and 404 pages triggered by users, bots or even Chuck Norris. This lets you keep an eye on what’s going on in your WordPress at any time. You can also control banned IPs from this option. (1) Available in the Pro Version. (SecuPress est une extension de sécurité WordPress française) TODO Create a trust score for each non WP file and displays it Create a “suspicious” status for alerts Revamp alerts Revamp logs Add http logs PHP 8.O min replace %s by ###USERNAME### in emails .htaccess scanner login rest disclose scanner give possibility to rename logins target=”_blank” on doc links AI Scanner Improve malware scanner, again