{"id":317823,"date":"2026-08-25T17:59:49","date_gmt":"2026-08-25T17:59:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/tailwatch\/"},"modified":"2026-08-25T23:29:44","modified_gmt":"2026-08-25T23:29:44","slug":"tailwatch","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/tailwatch\/","author":23440004,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.1","stable_tag":"1.0.1","tested":"7.1","requires":"6.3","requires_php":"7.4","requires_plugins":null,"header_name":"Tailwatch","header_author":"WP Tailwatch","header_description":"WordPress security with backups, monitoring, SSL tracking, file integrity checks, and event-based push notifications.","assets_banners_color":"babdbe","last_updated":"2026-08-25 23:29:44","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wptailwatch.com\/?utm_source=wp-plugins&utm_medium=wp-dash&utm_campaign=free&utm_content=plugin_uri","header_author_uri":"https:\/\/wptailwatch.com\/?utm_source=wp-plugins&utm_medium=wp-dash&utm_campaign=free&utm_content=author_uri","rating":0,"author_block_rating":0,"active_installs":0,"downloads":84,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"wptailwatch","date":"2026-08-25 17:59:23"},"1.0.1":{"tag":"1.0.1","author":"wptailwatch","date":"2026-08-25 23:29:44"}},"upgrade_notice":{"1.0.1":"<p>Update adding new features like to connect with web-dashboard and mobile app, one-click login, recovery mode, SMTP testing, GeoLite2 integration, and plugin\/theme rollback, plus Login Defender fixes and WordPress 7.1 support.<\/p>","1.0.0":"<p>Initial public release of Tailwatch.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3665797,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3665797,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3665797,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3665797,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3665797,"resolution":"1","location":"assets","locale":"","width":1907,"height":862},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3665797,"resolution":"2","location":"assets","locale":"","width":1915,"height":857},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3665797,"resolution":"3","location":"assets","locale":"","width":1915,"height":862},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3665797,"resolution":"4","location":"assets","locale":"","width":1915,"height":865},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3665797,"resolution":"5","location":"assets","locale":"","width":1912,"height":857},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3665797,"resolution":"6","location":"assets","locale":"","width":1907,"height":857},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3665797,"resolution":"7","location":"assets","locale":"","width":1907,"height":861},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3665797,"resolution":"8","location":"assets","locale":"","width":1906,"height":857}},"screenshots":{"1":"Features Overview","2":"Real-time Notification Settings","3":"Updates &amp; Rollback (Real-time Notifications)","4":"Dashboard Overview","5":"Backup Vault","6":"Malware Guard","7":"System Settings","8":"Connect License"}},"plugin_section":[],"plugin_tags":[8534,151,5603,600,1536],"plugin_category":[54,59],"plugin_contributors":[277461],"plugin_business_model":[],"class_list":["post-317823","plugin","type-plugin","status-publish","hentry","plugin_tags-audit-log","plugin_tags-backup","plugin_tags-monitoring","plugin_tags-security","plugin_tags-ssl","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-wptailwatch","plugin_committers-wptailwatch"],"banners":{"banner":"https:\/\/ps.w.org\/tailwatch\/assets\/banner-772x250.png?rev=3665797","banner_2x":"https:\/\/ps.w.org\/tailwatch\/assets\/banner-1544x500.png?rev=3665797","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/tailwatch\/assets\/icon-128x128.png?rev=3665797","icon_2x":"https:\/\/ps.w.org\/tailwatch\/assets\/icon-256x256.png?rev=3665797","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/tailwatch\/assets\/screenshot-1.png?rev=3665797","caption":"Features Overview"},{"src":"https:\/\/ps.w.org\/tailwatch\/assets\/screenshot-2.png?rev=3665797","caption":"Real-time Notification Settings"},{"src":"https:\/\/ps.w.org\/tailwatch\/assets\/screenshot-3.png?rev=3665797","caption":"Updates &amp; Rollback (Real-time Notifications)"},{"src":"https:\/\/ps.w.org\/tailwatch\/assets\/screenshot-4.png?rev=3665797","caption":"Dashboard Overview"},{"src":"https:\/\/ps.w.org\/tailwatch\/assets\/screenshot-5.png?rev=3665797","caption":"Backup Vault"},{"src":"https:\/\/ps.w.org\/tailwatch\/assets\/screenshot-6.png?rev=3665797","caption":"Malware Guard"},{"src":"https:\/\/ps.w.org\/tailwatch\/assets\/screenshot-7.png?rev=3665797","caption":"System Settings"},{"src":"https:\/\/ps.w.org\/tailwatch\/assets\/screenshot-8.png?rev=3665797","caption":"Connect License"}],"raw_content":"<!--section=description-->\n<p>Tailwatch is a WordPress security and site management plugin that gives you real-time visibility into what is happening on your website.<\/p>\n\n<p>It combines security, monitoring, and backups into one lightweight system, managed from your WordPress dashboard. Optionally connect a free Tailwatch account to receive event-based push notifications so you stay informed wherever you are.<\/p>\n\n<h4>Core Features<\/h4>\n\n<ul>\n<li>Activity Logs (logins, failed logins, registrations, password resets)<\/li>\n<li>HTTP Error Logs (4xx \/ 5xx monitoring)<\/li>\n<li>Email \/ SMTP Logging with custom SMTP server support<\/li>\n<li>Security Hardening Audit<\/li>\n<li>File &amp; Permission Protection<\/li>\n<li>Smart SSL Monitoring &amp; Expiry Alerts<\/li>\n<li>File Integrity Monitoring (baseline + change detection)<\/li>\n<li>Full Site Backups (files and database)<\/li>\n<li>Search &amp; Replace (safe database-wide updates with serialized data handling)<\/li>\n<li>Content Restrictions (browser-level protection controls like copy\/inspect restrictions)<\/li>\n<li>Database Optimization Tools<\/li>\n<li>Broken Link Scanner<\/li>\n<li>Cron Job Manager<\/li>\n<li>301 Redirect Manager<\/li>\n<li>User Management (create, edit, delete users and manage roles)<\/li>\n<li>Login Defender (IP-based brute-force protection: failed-login throttling, automatic temporary lockouts, configurable retention)<\/li>\n<li>Geo-blocking (allow\/block individual IPs or IP ranges; whitelist trusted IPs to bypass restrictions)<\/li>\n<li>Username Hardening (audits for common high-risk usernames such as admin and administrator)<\/li>\n<li>Process Monitoring &amp; Recovery (detect stuck long-running tasks and re-schedule them)<\/li>\n<li>Disk Space Monitoring<\/li>\n<li>Event-based Push Notifications<\/li>\n<\/ul>\n\n<h4>Notifications<\/h4>\n\n<p>Once connected to a free Tailwatch account, your site can send event-based push notifications for:<\/p>\n\n<ul>\n<li>Login activity (logins, failed logins, registrations, password resets)<\/li>\n<li>Backup completion and backup failures<\/li>\n<li>File integrity changes (added, modified, deleted files)<\/li>\n<li>SSL expiry alerts and certificate status changes<\/li>\n<li>Security Hardening Audit results (scan completed, issues detected)<\/li>\n<li>Security feature configuration changes<\/li>\n<li>Search &amp; Replace completion results<\/li>\n<li>HTTP error spikes (4xx \/ 5xx monitoring)<\/li>\n<li>Database optimization results<\/li>\n<li>Broken link scan results<\/li>\n<li>Cron job failures<\/li>\n<li>Email delivery (success or failed)<\/li>\n<li>Login Defender events (IPs blocked after repeated failed logins, brute-force attempts detected)<\/li>\n<\/ul>\n\n<p>Notifications are delivered to the Tailwatch mobile app using Firebase Cloud Messaging (FCM), routed through api.wptailwatch.com (the plugin does not contact Firebase directly).<\/p>\n\n<h4>Tailwatch Pro<\/h4>\n\n<p>Tailwatch Pro extends the free version with:<\/p>\n\n<ul>\n<li>Malware Guard (cloud malware scanning, suspicious file detection, cleanup, and push alerts for risk-detection events)<\/li>\n<li>Country blocking (allow or block visitors by country, applied to login forms or your entire site)<\/li>\n<li>Role-based Two-Factor Authentication (2FA)<\/li>\n<li>Advanced User Management (account-expiry rules, \"login as another user\", per-user 2FA status surfaced in the user list)<\/li>\n<li>Expanded notification credits<\/li>\n<li>Advanced scheduling controls for backups and maintenance tasks<\/li>\n<li>Priority support<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to several external services. Each service, the data sent, and the conditions under which the connection is made are listed below. Most connections only occur when the corresponding optional feature is enabled by the site administrator.<\/p>\n\n<h4>Tailwatch API (api.wptailwatch.com)<\/h4>\n\n<p>Used for license verification, push notification delivery, and optional deactivation feedback submission. License verification and push notification delivery are active only after you connect a free Tailwatch account from the plugin's License screen. The deactivation feedback submission is independent of any account connection and is sent only if you voluntarily submit it (see below).<\/p>\n\n<p>What is sent and when:\n- License verification: your anonymized Tailwatch user identifier and your site URL (query string), plus an <code>X-Tailwatch-Header-Key<\/code> request header containing the license credential issued when you connected your account. Sent on dashboard visits (throttled by a short server-side cache) and on demand when you click \"Verify License\". No system metadata is included in this request;\n- Recovery access provisioning: when you connect your account, the plugin generates a standard WordPress recovery-mode cookie for your own site and sends it to the Tailwatch service so the dashboard can help you regain access if your site later becomes unreachable (for example, a fatal error that prevents wp-admin from loading). This value is a single site-scoped recovery credential \u2014 the same kind WordPress itself issues for its built-in recovery mode \u2014 that grants recovery-mode access to your site and nothing more. It is transmitted only over the authenticated connect handshake and only after you choose to connect your account;\n- Mobile push notifications: anonymized user identifier, your site domain, and the notification type\/severity tag (the plugin no longer sends a pre-written title or body; the Tailwatch service composes those from the event context below, and the request goes to a single relay endpoint authenticated with a per-site routing token request header). When mobile notifications are enabled, an additional event-context payload is also stored on api.wptailwatch.com so the mobile app can render notification details when you tap a push. This event-context payload contains: the event name and feature, the action and any state-change narrative (before\/after) describing what occurred, the timestamp, the requesting admin's own forensic baseline (IP address and user agent at the time of the event), and per-event fields needed for the mobile app's detail view (for example, for Email \/ SMTP events the recipient address and subject line so the notification is actionable). It does NOT include message bodies, credentials, tokens, license keys, or any other secret. The event-context payload is held on api.wptailwatch.com only; it is NOT forwarded to Firebase Cloud Messaging (see below) \u2014 Firebase only ever receives the slim title\/body\/type payload.\n- Deactivation feedback: site domain, deactivation reason, plugin version, your \"keep data \/ delete data\" choice from the deactivation modal, and optional free-form comments \u2014 sent only if you voluntarily click \"Submit &amp; Deactivate\" (the \"Skip &amp; Deactivate\" button avoids any transmission).<\/p>\n\n<p>Service provider: WP Tailwatch\nPrivacy policy: https:\/\/wptailwatch.com\/privacy-policy\nTerms: https:\/\/wptailwatch.com\/terms-of-services<\/p>\n\n<h4>Tailwatch Dashboard (dashboard.wptailwatch.com)<\/h4>\n\n<p>The central web dashboard you use to connect your site and manage your account. The browser opens dashboard.wptailwatch.com only when you click \"Connect License\".<\/p>\n\n<p>What is sent: your site URL and environment type (staging or production) are passed via URL parameters when you initiate the connection flow. License information is retrieved and stored in your WordPress database after you log in to the dashboard.<\/p>\n\n<p>Service provider: WP Tailwatch\nPrivacy policy: https:\/\/wptailwatch.com\/privacy-policy\nTerms: https:\/\/wptailwatch.com\/terms-of-services<\/p>\n\n<h4>Firebase Cloud Messaging (fcm.googleapis.com)<\/h4>\n\n<p>Used to deliver mobile push notifications to your paired mobile devices. Only active when (a) you have connected a Tailwatch account, (b) you have enabled mobile notifications in plugin settings, and (c) you have toggled on the specific per-feature notification.<\/p>\n\n<p>What is sent: an anonymized device token and the notification payload (title, body, type tag) \u2014 routed via api.wptailwatch.com to Firebase Cloud Messaging for delivery to your paired device.<\/p>\n\n<p>Service provider: Google LLC\nPrivacy policy: https:\/\/firebase.google.com\/support\/privacy\nTerms: https:\/\/firebase.google.com\/terms<\/p>\n\n<h4>Smart SSL Monitoring \u2014 host certificate inspection<\/h4>\n\n<p>The Smart SSL feature opens a TLS connection (raw socket) to your own site's domain (derived from your WordPress Site Address \/ <code>home_url()<\/code>) to read its certificate metadata (issuer, validity dates, chain). It also issues an HTTP HEAD probe over plain HTTP to your own site to detect HTTP\u2192HTTPS redirection behaviour. Only your own site is contacted \u2014 Tailwatch does not connect to any third-party service for this purpose. Disable the Smart SSL feature in plugin settings if you do not want these requests issued.<\/p>\n\n<h4>Broken Link Checker \u2014 external URL scanning<\/h4>\n\n<p>The Broken Links scanner contacts URLs that you (or your site's authors) have placed in your post content, pages, term descriptions, user meta, and options. The plugin issues GET requests to those URLs to determine whether they return 4xx or 5xx errors. The set of URLs contacted is therefore controlled entirely by your own site content \u2014 Tailwatch does not maintain a list of external services for this purpose. Disable the Broken Links feature in plugin settings if you do not want these requests issued.<\/p>\n\n<h4>MaxMind GeoLite2 database download (download.maxmind.com)<\/h4>\n\n<p>The optional GeoIP integration downloads the MaxMind GeoLite2-Country database so the plugin can resolve visitor IP addresses to a country (used to display the country of an event in the Login Defender logs, and \u2014 with the Pro add-on \u2014 for country-based access rules). This connection is made ONLY when you have entered your own MaxMind license key on the Integrations screen, and ONLY on an explicit action you take: when you save the key, and when you click \"Check for updates\". There is no automatic, background, or scheduled download.<\/p>\n\n<p>What is sent: your MaxMind license key and the requested database edition (\"GeoLite2-Country\"), in a request to https:\/\/download.maxmind.com\/app\/geoip_download. The downloaded database file is stored inside your site's uploads directory. You must obtain your own (free) MaxMind account and license key; the GeoLite2 data is provided by MaxMind under the MaxMind GeoLite2 End User License Agreement. Remove the license key on the Integrations screen to delete the database and stop all such requests.<\/p>\n\n<p>Service provider: MaxMind, Inc.\nPrivacy policy: https:\/\/www.maxmind.com\/en\/privacy-policy\nGeoLite2 EULA: https:\/\/www.maxmind.com\/en\/geolite2\/eula<\/p>\n\n<h4>WordPress.org \u2014 plugin, theme, and core updates &amp; rollback<\/h4>\n\n<p>The optional Updates &amp; Rollback feature contacts WordPress.org to manage updates for your plugins, themes, and WordPress core. When you open the Updates screen it queries api.wordpress.org for available-update information and version lists (the same API WordPress core itself uses); when you update or roll back an item it downloads the official package from downloads.wordpress.org and installs it through WordPress's own upgrade routines (WP_Upgrader \/ Core_Upgrader). Only official WordPress.org packages are ever downloaded \u2014 no third-party source is contacted. These requests are made only when you open the Updates screen or explicitly click Update or Rollback. Disable the Updates &amp; Rollback feature in plugin settings if you do not want these requests issued.<\/p>\n\n<p>Service provider: WordPress.org (The WordPress Foundation)\nPrivacy policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<h3>Third-Party Libraries<\/h3>\n\n<h4>Bundled PHP libraries<\/h4>\n\n<p>Tailwatch bundles the following open-source PHP libraries. They run entirely on your server and are GPLv2-compatible.<\/p>\n\n<ul>\n<li>MaxMind GeoIP2 PHP API + MaxMind-DB Reader \u2014 reads a GeoLite2-Country database (which you either download on the Integrations screen using your own MaxMind license key, or upload manually to your site's uploads directory) to resolve visitor IPs to a country for the IP Management \/ Login Defender geolocation feature. Runs under the <code>Tailwatch\\Vendor\\MaxMind\\*<\/code> namespace. Source: https:\/\/github.com\/maxmind\/GeoIP2-php and https:\/\/github.com\/maxmind\/MaxMind-DB-Reader-php \u2014 License: Apache-2.0 (full text in <code>Vendor\/MaxMind\/LICENSE<\/code>)<\/li>\n<li>Firebase JWT (firebase\/php-jwt) \u2014 encodes and verifies the signed HS256 JSON Web Tokens that authenticate the Connect REST API (used by the mobile app and cloud dashboard). Runs under the <code>Tailwatch\\Vendor\\Firebase\\JWT\\*<\/code> namespace. Source: https:\/\/github.com\/firebase\/php-jwt \u2014 License: BSD-3-Clause (full text in <code>Vendor\/Firebase\/JWT\/LICENSE<\/code>)<\/li>\n<\/ul>\n\n<p>All server-side HTTP requests use WordPress core's built-in HTTP API (wp_remote_get \/ wp_remote_post \/ wp_remote_head). No external PHP HTTP client libraries (e.g. Guzzle) are bundled.<\/p>\n\n<h4>Bundled JavaScript libraries<\/h4>\n\n<p>The plugin's admin dashboard is a React single-page application. Its compiled bundle in <code>Admin\/View\/Static\/js\/<\/code> and <code>Admin\/View\/Static\/css\/<\/code> is built from the following open-source libraries, all of which are GPLv2-compatible:<\/p>\n\n<ul>\n<li>React + ReactDOM (UI framework) \u2014 https:\/\/react.dev \u2014 License: MIT<\/li>\n<li>Redux, Redux Toolkit, and React-Redux (state management) \u2014 https:\/\/redux.js.org \u2014 License: MIT<\/li>\n<li>React Router (react-router-dom) (client-side routing) \u2014 https:\/\/reactrouter.com \u2014 License: MIT<\/li>\n<li>React Hook Form (form state and validation) \u2014 https:\/\/react-hook-form.com \u2014 License: MIT<\/li>\n<li>Axios (HTTP client) \u2014 https:\/\/github.com\/axios\/axios \u2014 License: MIT<\/li>\n<li>SweetAlert2 (modal dialogs) \u2014 https:\/\/sweetalert2.github.io \u2014 License: MIT<\/li>\n<li>Recharts and react-d3-speedometer (charts and gauges) \u2014 https:\/\/recharts.org \u2014 License: MIT<\/li>\n<li>@tanstack\/react-virtual (long-list virtualization) \u2014 https:\/\/tanstack.com\/virtual \u2014 License: MIT<\/li>\n<li>react-loading-skeleton, react-top-loading-bar, and @ramonak\/react-progress-bar (loading indicators) \u2014 License: MIT<\/li>\n<li>react-hot-toast and react-toastify (toast notifications) \u2014 License: MIT<\/li>\n<li>react-tooltip (tooltips) \u2014 https:\/\/react-tooltip.com \u2014 License: MIT<\/li>\n<li>react-slick + slick-carousel (carousels) \u2014 https:\/\/react-slick.neostack.com \u2014 License: MIT<\/li>\n<li>lucide-react (License: ISC) and react-icons (License: MIT) \u2014 icon sets<\/li>\n<li>@uppy\/core (file selection) \u2014 https:\/\/uppy.io \u2014 License: MIT<\/li>\n<li>file-saver (client-side file downloads) \u2014 https:\/\/github.com\/eligrey\/FileSaver.js \u2014 License: MIT<\/li>\n<li>i18n-iso-countries and countries-list (country names and metadata for country name and flag display) \u2014 License: MIT<\/li>\n<li>DOMPurify (HTML sanitisation for user-supplied strings rendered in the dashboard) \u2014 https:\/\/github.com\/cure53\/DOMPurify \u2014 License: Apache-2.0 \/ MPL-2.0<\/li>\n<li>prop-types (runtime prop checks) \u2014 https:\/\/github.com\/facebook\/prop-types \u2014 License: MIT<\/li>\n<li>classnames (conditional CSS class-name joining) \u2014 https:\/\/github.com\/JedWatson\/classnames \u2014 License: MIT<\/li>\n<li>decimal.js-light (arbitrary-precision decimal math used by the charts) \u2014 https:\/\/github.com\/MikeMcl\/decimal.js-light \u2014 License: MIT<\/li>\n<li>Tailwind CSS (utility-first styling) \u2014 https:\/\/tailwindcss.com \u2014 License: MIT<\/li>\n<\/ul>\n\n<h4>Bundled font<\/h4>\n\n<ul>\n<li>Noto Color Emoji (flags-only subset) \u2014 a small subset containing only country-flag glyphs, bundled in <code>Admin\/View\/Static\/fonts\/<\/code> so country flag emoji render consistently across platforms, including Windows (whose system emoji font omits flag glyphs). Source: https:\/\/github.com\/googlefonts\/noto-emoji \u2014 License: SIL Open Font License 1.1 (full text in <code>Admin\/View\/Static\/fonts\/OFL.txt<\/code>).<\/li>\n<\/ul>\n\n<p>No JavaScript library is loaded from a remote CDN at runtime; the bundle is served entirely from the plugin directory.<\/p>\n\n<h3>Privacy Policy<\/h3>\n\n<p>Tailwatch stores all logs and operational data locally in your WordPress database (custom tables <code>{prefix}tw_settings<\/code>, <code>{prefix}tw_logs<\/code>, <code>{prefix}tw_filemon_baseline<\/code>, and <code>{prefix}tw_filemon_scans<\/code>) and on disk under <code>uploads\/tailwatch\/tailwatch-logs\/<\/code> (logs and generated data) and <code>wp-content\/tailwatch\/tailwatch-backup\/<\/code> (backup archives). Both directories are sealed with deny files (.htaccess, index.php, web.config) so their contents are not reachable over the web.<\/p>\n\n<p>Data stored locally:<\/p>\n\n<p>\u2013 <strong>Activity logs<\/strong> \u2014 login\/logout events, failed login attempts (including the username submitted and the originating IP address), registrations, password reset events\n\u2013 <strong>HTTP error logs<\/strong> \u2014 4xx \/ 5xx responses captured during the request lifecycle\n\u2013 <strong>Email logs<\/strong> \u2014 SMTP send results for outbound site mail\n\u2013 <strong>Backup metadata<\/strong> \u2014 backup catalogue entries (filenames, sizes, timestamps); the actual archives live in <code>wp-content\/tailwatch\/tailwatch-backup\/<\/code>\n\u2013 <strong>File integrity baselines<\/strong> \u2014 file path + hash snapshots used to detect added \/ modified \/ deleted files\n\u2013 <strong>Broken link \/ redirection records<\/strong> \u2014 URLs detected on your site and any redirects you have configured\n\u2013 <strong>System configuration data<\/strong> \u2014 every plugin feature toggle, schedule, and threshold lives in <code>{prefix}tw_settings<\/code>\n\u2013 <strong>Client IP addresses<\/strong> \u2014 captured for security-relevant events (failed logins, rate-limited requests, redirection hits) so the dashboard and audit trail can show where the event came from\n\u2013 <strong>Login Defender state<\/strong> \u2014 IP addresses temporarily locked out after repeated failed logins, throttling counters, and the per-IP activity history that drives the lockout decisions\n\u2013 <strong>Geo-blocking lists<\/strong> \u2014 IPs and IP ranges you have explicitly allow-listed or block-listed via the Geo-blocking screen, plus the timestamp and admin who created each rule\n\u2013 <strong>Visit \/ usage telemetry<\/strong> \u2014 a local-only counter in the <code>tailwatch_visit_data<\/code> option, used to drive in-dashboard onboarding hints; never transmitted<\/p>\n\n<p>No user data, logs, or PII is transmitted to external servers unless an optional feature is explicitly enabled by the site administrator. The full list of outbound transmissions is documented in the \"External Services\" section above.<\/p>\n\n<h3>Source Code<\/h3>\n\n<p>Tailwatch is 100% open source and distributed under GPL-2.0-or-later. The\ncomplete, human-readable source code \u2014 including the React source and the\nCreate React App \/ Webpack build tooling used to produce the admin dashboard\nbundle that ships with this plugin \u2014 is publicly available at:<\/p>\n\n<p>https:\/\/github.com\/tailwatch\/tailwatch<\/p>\n\n<p>The React source for the admin dashboard lives under <code>admin-app\/<\/code> in that\nrepository. To reproduce the compiled bundle that ships in this plugin, from\nthe repository root:<\/p>\n\n<pre><code>npm run build\n<\/code><\/pre>\n\n<p>That installs the pinned dependencies, builds the React app, and copies the\ncompiled bundle into <code>Admin\/View\/Static\/<\/code>. Prerequisites are Node.js 20 or\nlater and npm  &hellip;<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/tailwatch<\/code><\/li>\n<li>Activate it via the WordPress Plugins screen<\/li>\n<li>Open Tailwatch from the admin menu<\/li>\n<li>Optionally connect a free Tailwatch account for mobile notifications and dashboard access<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20tailwatch%20free%3F\"><h3>Is Tailwatch free?<\/h3><\/dt>\n<dd><p>Yes. Core features run locally on your WordPress site with no paid subscription required.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20account%3F\"><h3>Do I need an account?<\/h3><\/dt>\n<dd><p>No. An account is only required for optional features like push notifications and license\/account sync.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20site%3F\"><h3>Will it slow down my site?<\/h3><\/dt>\n<dd><p>No. Tailwatch uses lazy loading, caching, and scheduled background processing for performance efficiency.<\/p><\/dd>\n<dt id=\"does%20tailwatch%20send%20data%20externally%3F\"><h3>Does Tailwatch send data externally?<\/h3><\/dt>\n<dd><p>Only when you enable optional features such as:\n\u2013 Push notifications\n\u2013 License verification\n\u2013 Optional feedback submission<\/p>\n\n<p>Core features remain fully local. See the \"External Services\" section below for the full breakdown of each transmission.<\/p><\/dd>\n<dt id=\"can%20i%20disable%20features%3F\"><h3>Can I disable features?<\/h3><\/dt>\n<dd><p>Yes. Every module in Tailwatch can be individually enabled or disabled.<\/p><\/dd>\n<dt id=\"how%20does%20the%20one-click%20login%20link%20work%3F\"><h3>How does the one-click login link work?<\/h3><\/dt>\n<dd><p>When you request a login link from an already-authenticated Tailwatch session (the mobile app or the connected dashboard), the plugin issues a single-use link that expires within one hour and signs in only the administrator who requested it. The link is stored hashed, so a copy of your database reveals no usable link, and it is invalidated the moment it is opened. Because it is a passwordless login you start yourself, opening the link signs you straight in \u2014 like a password-reset link, it is an alternative to typing your password rather than a second prompt.<\/p><\/dd>\n<dt id=\"does%20tailwatch%20modify%20my%20site%27s%20.htaccess%20file%3F\"><h3>Does Tailwatch modify my site's .htaccess file?<\/h3><\/dt>\n<dd><p>The optional Performance Optimizer feature can add a \"Tailwatch Performance Settings\" block to your site's root .htaccess \u2014 but only if you apply PHP configuration settings from that feature and your server runs Apache with mod_php (the plugin probes for support first). It uses WordPress core's insert_with_markers() function, which scopes the change to a single BEGIN\/END marker block and preserves every other line in the file; the plugin never rewrites the whole file. After writing, it verifies your site still responds and automatically removes the block if anything fails. You can clear these settings at any time from the feature. Separately, Tailwatch writes deny files (.htaccess, index.php, web.config) inside its own storage folders under uploads\/tailwatch\/ and wp-content\/tailwatch\/ to keep their contents unreachable over the web; it does not modify .htaccess anywhere else.<\/p><\/dd>\n<dt id=\"does%20tailwatch%20change%20php%20settings%20during%20scans%3F\"><h3>Does Tailwatch change PHP settings during scans?<\/h3><\/dt>\n<dd><p>During a heavy operation you start \u2014 a malware scan, file-integrity check, hardening audit, or backup \u2014 Tailwatch may temporarily raise PHP limits (memory_limit, max_execution_time) for the duration of that request so the operation does not fail on constrained hosts. This is a runtime-only adjustment: nothing is written to any file, it never lowers a limit your host already sets higher, and it has no effect outside the running scan.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Connect a free Tailwatch (wptailwatch.com) account for web-dashboard and mobile app access with real-time push notifications, over a hardened REST connection with dedicated-key encryption.<\/li>\n<li>One-click administrator login links (single-use, hashed, expire within one hour) initiated from a connected Tailwatch session.<\/li>\n<li>Recovery Mode provisioning so you can regain access if your site becomes unreachable.<\/li>\n<li>SMTP test tool for verifying your outgoing email configuration.<\/li>\n<li>MaxMind GeoLite2 database integration (admin-initiated download) for country detection in logs and geo features.<\/li>\n<li>Plugin and theme update management with one-click rollback.<\/li>\n<li>Performance Optimizer that raises PHP limits during heavy operations, with optional .htaccess tuning.<\/li>\n<li>Setup now runs only after you choose to begin, and remembers your choice.<\/li>\n<li>Login Defender: trusted allow-list IPs and countries are consistently excluded from brute-force tracking while the allow-list is enabled.<\/li>\n<li>Feature backfill on update so newly added features appear on existing sites; incompatibility notices are limited to administrators.<\/li>\n<li>Tested up to WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>Activity monitoring system<\/li>\n<li>Error (HTTP 4xx \/ 5xx) logging<\/li>\n<li>File integrity monitoring<\/li>\n<li>SSL monitoring<\/li>\n<li>Backup system (files and database)<\/li>\n<li>Database optimization tools<\/li>\n<li>Cron job manager<\/li>\n<li>Login Defender (IP-based brute-force protection + lockouts)<\/li>\n<li>Geo-blocking (IP and IP-range allow\/block lists)<\/li>\n<li>Event-based push notifications<\/li>\n<\/ul>","raw_excerpt":"WordPress security with backups, monitoring, SSL tracking, file integrity checks, and event-based push notifications.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/317823","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=317823"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wptailwatch"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=317823"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=317823"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=317823"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=317823"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=317823"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=317823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}