Title: Karetaker
Author: Team Krikir
Published: <strong>September 15, 2026</strong>
Last modified: September 17, 2026

---

Search plugins

![](https://ps.w.org/karetaker/assets/banner-772x250.png?rev=3697610)

![](https://ps.w.org/karetaker/assets/icon-256x256.png?rev=3697610)

# Karetaker

 By [Team Krikir](https://profiles.wordpress.org/krikir/)

[Download](https://downloads.wordpress.org/plugin/karetaker.1.1.1.zip)

 * [Details](https://wordpress.org/plugins/karetaker/#description)
 * [Reviews](https://wordpress.org/plugins/karetaker/#reviews)
 *  [Installation](https://wordpress.org/plugins/karetaker/#installation)
 * [Development](https://wordpress.org/plugins/karetaker/#developers)

 [Support](https://wordpress.org/support/plugin/karetaker/)

## Description

Karetaker is a **watchtower**, not a wall.

Most security plugins either shout at you all day or quietly lock you out of your
own
 site. Karetaker does neither. It watches the handful of changes that actually
mean something went wrong, keeps a readable record, and emails you only when a human
needs to act.

#### What it watches

 * **Scripts**: new external JavaScript domains after a local baseline (home, and
   cart/checkout when WooCommerce is active)
 * **Search engine cloaking**: once a day, compares your home page as a visitor 
   and as Googlebot, and flags hidden spam links
 * **Integrity**: core and plugin file changes, checked against published WordPress.
   org checksums
 * **Options**: changes to the settings that matter, plus curated suspicious option
   names and unusual new autoload names
 * **Privileges**: role and capability changes, new administrators, user promotions
 * **Uploads**: files appearing in `wp-content/uploads` that do not belong there
 * **Cron drift**: scheduled tasks that vanish, stall, or appear from nowhere
 * **Plugin risk**: closed or abandoned plugins on WordPress.org, and plugins whose
   listed owner changed
 * **Optional vulnerability lookup**: when you enable it, active plugin versions
   are checked against public WPVulnerability data (off by default)

#### One-checkbox catastrophes

The quiet business killers that no scanner reports, because technically nothing 
is “hacked”:

 * Search engine visibility switched off
 * Site email failing to send
 * No administrators left on the site
 * Invalid or unreachable admin email

#### Opt-in hardening, with receipts

A small set of hardening toggles, every one of them **off until you turn it on**,
and
 every one reversible from Karetaker  Protection. Each toggle shows _Desired_
next to _Live now_, so you always see what is actually in effect rather than what
was merely requested.

#### How it reaches you

 * **Visibility is pull**: the Karetaker admin screen and WP-CLI
 * **Notification is push**: email to the site owner, on ACT-severity events only
 * **Optional Slack / Telegram / Discord / Microsoft Teams**: webhooks or Bot API,
   off until you turn them on
 * **Optional weekly summary**: one short email on Monday mornings, off until you
   turn it on
 * **Pause alerts** for an hour while you work on the site; one catch-up email afterwards
   if something needed you
 * **Your data, your file**: download the activity log as CSV at any time
 * **Hardening is off** until each toggle is switched on

#### Who it is for

 * **Site owners** who want to know their site is fine without reading a dashboard
   every morning
 * **Freelancers and agencies** handing a site over to a client, who still need 
   to know if something breaks later

#### It is deliberately not

 * A WAF or request firewall
 * A malware signature scanner
 * A login lockout or hide-login product by default
 * A writer of `wp-config.php`, `.htaccess`, or server config

#### Kill switch

Define `KARETAKER_DISABLE` as true in `wp-config.php`, or place an empty file at

wp-content/karetaker-disable. The plugin then boots nothing. Uninstall removes the
plugin’s table, options, and scheduled hooks.

#### Open source

Karetaker is GPL, built by [Team Krikir](https://www.krikir.com/). It does not phone

home, load third-party scripts, or show ads. Issues and pull requests are welcome.

#### Credits

Karetaker ships no third-party code, fonts or images. It relies on these projects
and services,
 and thanks them:

 * [WordPress](https://wordpress.org/) and the WordPress.org APIs for core and plugin
   checksums, plugin directory information, and security keys
 * [WPVulnerability](https://www.wpvulnerability.com/) for the optional public vulnerability
   database (vulnerability details shown in Karetaker come from WPVulnerability 
   and the sources it links to)
 * [Simple Icons](https://simpleicons.org/) for the destination logos shown in Settings(
   CC0 1.0)
 * [Slack](https://slack.com/) incoming webhooks, the [Telegram](https://telegram.org/)
   Bot API, [Discord](https://discord.com/) webhooks and [Microsoft Teams](https://www.microsoft.com/microsoft-teams/)
   workflows for the optional alert channels
 * [PHP_CodeSniffer](https://github.com/PHPCSStandards/PHP_CodeSniffer), [WordPress Coding Standards](https://github.com/WordPress/WordPress-Coding-Standards)
   and [PHPCompatibilityWP](https://github.com/PHPCompatibility/PHPCompatibilityWP),
   used during development only

WordPress is a registered trademark of the WordPress Foundation. Microsoft and Microsoft
Teams
 are trademarks of the Microsoft group of companies. Slack is a trademark 
of Slack Technologies, LLC. Discord is a trademark of Discord Inc. Google and Googlebot
are trademarks of Google LLC. Telegram and all other trademarks are the property
of their respective owners. Karetaker is an independent project by Team Krikir. 
It is not created, endorsed, sponsored or certified by any of these companies; their
names are used only to describe the services Karetaker can connect to.

## Screenshots

[⌊Home when something needs you: a plain-language headline and a card per problem,
each with "Show me what to do".⌉⌊Home when something needs you: a plain-language
headline and a card per problem, each with "Show me what to do".⌉[

Home when something needs you: a plain-language headline and a card per problem,
each with “Show me what to do”.

[⌊Home when there is nothing urgent: worth a look, but it can wait.⌉⌊Home when there
is nothing urgent: worth a look, but it can wait.⌉[

Home when there is nothing urgent: worth a look, but it can wait.

[⌊Home on a quiet week, because staying silent is the point.⌉⌊Home on a quiet week,
because staying silent is the point.⌉[

Home on a quiet week, because staying silent is the point.

[⌊Activity: everything Karetaker recorded, grouped by day and written in plain words.⌉⌊
Activity: everything Karetaker recorded, grouped by day and written in plain words
.⌉[

Activity: everything Karetaker recorded, grouped by day and written in plain words.

[⌊Protection: optional protections you can switch on or off. None of them can lock
you out.⌉⌊Protection: optional protections you can switch on or off. None of them
can lock you out.⌉[

Protection: optional protections you can switch on or off. None of them can lock
you out.

[⌊Settings: where alerts go, the weekly summary, a one-hour pause, site type, and
privacy and data options.⌉⌊Settings: where alerts go, the weekly summary, a one-
hour pause, site type, and privacy and data options.⌉[

Settings: where alerts go, the weekly summary, a one-hour pause, site type, and 
privacy and data options.

[⌊The one-minute setup that runs on first activation.⌉⌊The one-minute setup that
runs on first activation.⌉[

The one-minute setup that runs on first activation.

## Installation

 1. Upload the `karetaker` folder to `/wp-content/plugins/`, or install the zip via
    Plugins  Add New  Upload.
 2. Activate through the Plugins screen.
 3. Open Karetaker in the admin sidebar. The one-minute setup asks where alerts go 
    and what kind of site this is, runs a first check, and offers three safe protections.

## FAQ

### Is this a firewall?

No. Karetaker watches and alerts. It does not filter HTTP traffic.

### Will it lock me out of wp-login?

Not by default. There is no login lockout or renamed login URL in the default set.

Hardening toggles are opt-in and reversible from Karetaker  Protection.

### How do I stop it immediately?

Define `KARETAKER_DISABLE` as true in `wp-config.php`, or create
 wp-content/karetaker-
disable. The plugin then boots nothing.

### What happened to Advanced mode?

Agency tools (issue tracking with owners, incident cases, client reports, role access
and
 the read-only API) are no longer part of Karetaker. Everything that watches
your site, alerts you and protects it stays here and stays free: every check, every
alert channel, the weekly summary, all protections and the activity export.

### Does uninstall leave data behind?

No. Uninstall drops the events table, plugin options, and cron hooks.

### What if I think the site was hacked?

Run `wp karetaker incident`. That runs a deeper multi-pass scan and shows a checklist
(
admins, plugins, uploads PHP, integrity, Guard, passwords). If you think someone
else is logged in, use Karetaker  Protection  “Sign out all administrators”. Karetaker
does not clean malware or lock anyone out; it is a guided review, not a clean certificate.

### Can hosting providers use this?

Yes. Karetaker does not ship a WAF, does not lock logins by default, and does not
write
 server config. `wp karetaker status` prints the host safety profile as JSON,
and Site Health reports scan freshness, Guard flags, and the same profile. Kill 
switch: `KARETAKER_DISABLE` or `wp-content/karetaker-disable`.

### What data leaves the site?

By default, only integrity checks contact WordPress.org to fetch published core/
plugin
 checksums (same family of APIs WordPress itself uses). Optional features
you turn on yourself may also leave the site: ACT alert emails (to the address you
choose), an ACT webhook POST (to the URL you set), Slack Incoming Webhooks, Telegram
Bot API, Discord and Microsoft Teams webhook messages (when enabled), the weekly
summary and end-of-pause emails (when enabled), and vulnerability lookup requests
to wpvulnerability.net (plugin slug only, when enabled under Settings). The daily“
What Google sees” check requests your own home page twice (once with a Googlebot
user agent); it does not contact Google. Karetaker does not phone home to Team Krikir
and does not load third-party scripts or ads.

When you enable those optional services, you also accept their terms:

 * Slack: https://slack.com/terms-of-service and https://slack.com/privacy-policy
 * Telegram: https://telegram.org/tos/bot-developers and https://telegram.org/privacy
 * Discord: https://discord.com/terms and https://discord.com/privacy
 * Microsoft Teams: https://www.microsoft.com/servicesagreement and https://privacy.
   microsoft.com/privacystatement
 * WPVulnerability: https://www.wpvulnerability.com/ (public vulnerability database
   API)

## Reviews

![](https://secure.gravatar.com/avatar/3c5234f82bd9f2d1c9fde02e930ecf8f32e9f0ac785d2b023da8baa0ff4174db?
s=60&d=retro&r=g)

### 󠀁[Simple, Lightweight and Really Useful Security Monitoring Plugin](https://wordpress.org/support/topic/simple-lightweight-and-really-useful-security-monitoring-plugin/)󠁿

 [designerhitesh](https://profiles.wordpress.org/designerhitesh/) September 17, 
2026

Karetaker is a very useful plugin for keeping an eye on important changes happening
on a WordPress website. I especially like that it focuses on meaningful alerts instead
of constantly showing unnecessary security warnings. The activity log is easy to
understand, and the monitoring for file changes, user/role changes, uploads, cron
issues and other important site changes is very helpful. The optional protection
features are also a nice addition because they can be enabled when needed. Overall,
it feels lightweight, clean and practical, especially for freelancers and agencies
managing multiple WordPress websites. Great work by the Team Krikir team. Looking
forward to seeing how the plugin develops further.

 [ Read all 1 review ](https://wordpress.org/support/plugin/karetaker/reviews/)

## Contributors & Developers

“Karetaker” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ Team Krikir ](https://profiles.wordpress.org/krikir/)

[Translate “Karetaker” into your language.](https://translate.wordpress.org/projects/wp-plugins/karetaker)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/karetaker/), check 
out the [SVN repository](https://plugins.svn.wordpress.org/karetaker/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/karetaker/) by [RSS](https://plugins.trac.wordpress.org/log/karetaker/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.1

 * Developer: filters for the navigation label and the footer version text, so add-
   ons can name their screens.

#### 1.1.0

 * Advanced mode is gone. Agency tools (issue tracking with owners, detailed monitoring,
   incident cases, client reports, role access and the read-only API) are no longer
   part of Karetaker.
 * Settings now holds the vulnerability lookup switch, how many events to keep, 
   trusted proxies, a test alert button and email previews.
 * Protection has “Sign out all administrators” for when you think someone else 
   is logged in.
 * Activity has a Download CSV button.
 * Developer: new filters karetaker_settings_defaults and karetaker_admin_setting.

#### 1.0.2

 * Developer: an extension API (actions, filters and a JavaScript bridge) so add-
   ons can extend Karetaker without editing it.
 * Tidier stylesheet comments.

#### 1.0.1

 * New email design for alerts, the weekly summary, the pause summary and test emails,
   matching the admin screens.
 * Clearer subjects that lead with the status and name the site, for example “Act
   now: A must-use plugin file changed · example.com”.
 * Every email now has a readable plain-text version and a readable technical details
   table instead of raw data.
 * The logo no longer breaks in email clients or when SMTP plugins are active.
 * Summaries group repeated events into one line with a count.
 * Preview any email from Advanced mode  Incidents  Alert routing.

#### 1.0.0

First public release.

 * Sixty-second setup: where to send alerts, what kind of site this is, a first 
   check, and three safe protections.
 * Home: plain-language status, a to-do card for anything that needs you, and the
   twelve checks Karetaker runs.
 * Watches: critical files, WordPress core and plugin files against official checksums,
   administrators (including accounts hidden from the Users screen), plugin risk
   signals from WordPress.org, must-use plugins, the uploads folder, scheduled tasks,
   option names, external script domains, what search engines see, failed logins,
   search visibility and email delivery.
 * Activity: everything Karetaker recorded, kept in your own database.
 * Protection: seven optional protections that cannot lock you out. Karetaker never
   edits wp-config.php or .htaccess.
 * Alerts by email, and optionally Telegram, Slack, Discord, Microsoft Teams or 
   your own webhook, with a weekly summary and a one-hour pause while you work.
 * Advanced mode for agencies and developers: issue tracking with owners, detailed
   monitoring, incident cases with a response checklist, client reports, CSV/JSON/
   ZIP exports, role permissions and read-only API tokens.
 * WP-CLI commands and an emergency off switch.

## Meta

 *  Version **1.1.1**
 *  Last updated **4 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [Activity Log](https://wordpress.org/plugins/tags/activity-log/)[File Integrity](https://wordpress.org/plugins/tags/file-integrity/)
   [hardening](https://wordpress.org/plugins/tags/hardening/)[monitoring](https://wordpress.org/plugins/tags/monitoring/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/karetaker/advanced/)

## Ratings

 5 out of 5 stars.

 *  [  1 5-star review     ](https://wordpress.org/support/plugin/karetaker/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/karetaker/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/karetaker/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/karetaker/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/karetaker/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/karetaker/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/karetaker/reviews/)

## Contributors

 *   [ Team Krikir ](https://profiles.wordpress.org/krikir/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/karetaker/)