Description
SiteGuard Scanner is a companion plugin for the vulnerability diagnostic service provided by EG Secure Solutions. Installing it on a site that is under a diagnostic contract enables the following two features.
- Site ownership verification (authentication) — Lets the diagnostic service confirm that the target site is the one that is actually under a diagnostic contract.
- Installation inventory — Provides the diagnostic service with a list of the plugins and themes installed on the target site (name, version, and activation status).
How it communicates
The plugin only responds to signed requests sent by the diagnostic service. It never sends data to any external server on its own (it does not “phone home”).
- Authentication uses an HMAC-SHA256 signature based on a shared token. Each request includes a timestamp and a nonce (a single-use random value) to prevent replay attacks.
- Requests are received through the WordPress REST API endpoints
/wp-json/siteguard-scanner/v1/verifyand/wp-json/siteguard-scanner/v1/collect. - For environments where the REST API is disabled, a custom endpoint (
/?siteguard-scanner-request=verifyand/?siteguard-scanner-request=collect) is provided as a fallback.
Every endpoint responds only to requests carrying a valid signature. When signature verification fails, the plugin returns HTTP 401 and no information at all.
Data provided
When responding to collect, the plugin returns the following information to the diagnostic service:
- Site URL
- WordPress core version
- List of installed plugins (slug, name, version, activation status, network-activation status)
- List of installed themes (slug, name, version, activation status, network-enabled status)
No personal data, post content, or any other data beyond the above is collected or transmitted.
Multisite
On a multisite network, diagnostics are performed against the main (parent) site. Because plugin and theme files are shared across the entire network, collect returns the network-wide inventory of installed assets and correctly reports network-activated plugins via the network_active flag.
Screenshots

Installation
- In the WordPress admin, go to “Plugins” > “Add New”.
- Click “Upload Plugin” at the top of the screen and select the plugin ZIP to install it.
- After installation, activate the plugin.
- Open “Settings” > “SiteGuard Scanner” in the admin menu.
- Enter the 64-character token provided by the diagnostic service and save.
On a multisite network, set the token on the main site’s Settings screen.
FAQ
-
Does this plugin send data to an external service?
-
It does not send anything on its own. It only responds to signed requests from the diagnostic service.
-
I cannot save the token.
-
The token must be a 64-character lowercase hexadecimal string (0-9, a-f). Values that do not meet these conditions are rejected and not saved.
-
Can I use it even with the REST API disabled?
-
Yes. In environments where the REST API is disabled, the custom endpoint (
/?siteguard-scanner-request=...) is used automatically as a fallback. -
Does it work on multisite?
-
Yes. On multisite, diagnostics are performed against the main site, and the plugin provides the network-wide plugin and theme inventory.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“SiteGuard Scanner” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “SiteGuard Scanner” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.0
- First public release on the WordPress.org plugin directory.
- Renamed the plugin to SiteGuard Scanner (slug, endpoints, and identifiers).
- Added the WordPress core version to the collect response.
- Fixed multisite so that network-activated plugins and themes are reported correctly.
- Added network_active / network_enabled / is_multisite to the collect response.
- Internationalized the admin UI and bundled a Japanese translation.
- Prepared plugin headers and readme for the WordPress.org directory.
0.3.0
- Added a custom endpoint (
/?siteguard-scanner-request=verify|collect) as a fallback for environments where the REST API is disabled. - Unified the signature verification logic across the REST API and the custom endpoint.
0.2.0
- Implemented request authentication using HMAC-SHA256 signatures.
0.1.0
- Initial version.
