{"id":356193,"date":"2026-08-29T14:16:17","date_gmt":"2026-08-29T14:16:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/storeguard-compromise-detection-for-woocommerce\/"},"modified":"2026-08-29T14:16:08","modified_gmt":"2026-08-29T14:16:08","slug":"decaguard-compromise-detection-for-woocommerce","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/decaguard-compromise-detection-for-woocommerce\/","author":23550366,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.2.0","stable_tag":"0.2.0","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"DecaGuard \u2014 Compromise Detection for WooCommerce","header_author":"deca1992","header_description":"Detects signs of compromise on a WooCommerce store and explains them in plain English. Observation only \u2014 it never blocks, deletes, or repairs anything.","assets_banners_color":"1a1966","last_updated":"2026-08-29 14:16:08","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/profiles.wordpress.org\/deca1992\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":55,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.2.0":{"tag":"0.2.0","author":"deca1992","date":"2026-08-29 14:16:08","revision":3671612}},"upgrade_notice":{"0.1.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3671606,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3671606,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3671606,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3671606,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3671606,"resolution":"1","location":"assets","locale":"","width":1280,"height":1075},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3671606,"resolution":"2","location":"assets","locale":"","width":1280,"height":1000}},"screenshots":{"1":"The DecaGuard screen: findings in plain English, worst first, each with a\none-click \"This was me\".","2":"Settings: choose where warnings go and how often your shop is checked."}},"plugin_section":[],"plugin_tags":[282,168808,237413,600,286],"plugin_category":[45,54],"plugin_contributors":[278193],"plugin_business_model":[],"class_list":["post-356193","plugin","type-plugin","status-publish","hentry","plugin_tags-ecommerce","plugin_tags-file-integrity","plugin_tags-malware-detection","plugin_tags-security","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-deca1992","plugin_committers-deca1992"],"banners":{"banner":"https:\/\/ps.w.org\/decaguard-compromise-detection-for-woocommerce\/assets\/banner-772x250.png?rev=3671606","banner_2x":"https:\/\/ps.w.org\/decaguard-compromise-detection-for-woocommerce\/assets\/banner-1544x500.png?rev=3671606","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/decaguard-compromise-detection-for-woocommerce\/assets\/icon-128x128.png?rev=3671606","icon_2x":"https:\/\/ps.w.org\/decaguard-compromise-detection-for-woocommerce\/assets\/icon-256x256.png?rev=3671606","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/decaguard-compromise-detection-for-woocommerce\/assets\/screenshot-1.png?rev=3671606","caption":"The DecaGuard screen: findings in plain English, worst first, each with a\none-click \"This was me\"."},{"src":"https:\/\/ps.w.org\/decaguard-compromise-detection-for-woocommerce\/assets\/screenshot-2.png?rev=3671606","caption":"Settings: choose where warnings go and how often your shop is checked."}],"raw_content":"<!--section=description-->\n<p>Most shop owners find out they have been hacked when their payment provider tells\nthem, or when a customer complains about a fraudulent charge. By then the damage\nis done.<\/p>\n\n<p>DecaGuard learns what your shop normally looks like, then watches for anything\nthat changes without your say-so: files appearing where files should not appear,\nnew administrator accounts, hidden add-ons, settings that quietly gained code in\nthem, and outside companies that started running code on your pages.<\/p>\n\n<p>When it finds something, it explains what happened in ordinary language \u2014 what\nthe risk is to your money and your customers, and what to do next. If the change\nwas you, one click marks it as expected and you never hear about it again.<\/p>\n\n<h4>It watches. It does not touch anything.<\/h4>\n\n<p>DecaGuard never blocks, deletes, quarantines, modifies, or repairs anything on\nyour shop. It is not a firewall, it does not sit between your customers and your\npages, and it never touches your checkout, your payment gateway callbacks, or the\nWooCommerce API.<\/p>\n\n<p>This is deliberate. Real compromises leave several ways back in. Automated\ncleanup either misses one \u2014 leaving you confidently reinfected \u2014 or deletes\nsomething your shop needs and takes it offline. Both are worse than a clear\nwarning and a decision you make yourself.<\/p>\n\n<h4>What it looks at<\/h4>\n\n<ul>\n<li><strong>Your files.<\/strong> Program files appearing in your uploads folder, code hidden\ninside images, changes to WordPress's own files (checked against the official\npublished list), and changes to your main settings file.<\/li>\n<li><strong>Your database.<\/strong> Web addresses hidden in your shop's settings, scheduled\ntasks that no add-on owns, and tasks that quietly fetch instructions from\noutside.<\/li>\n<li><strong>Your accounts.<\/strong> New administrators, accounts that gained powers they did not\nhave, and \u2014 importantly \u2014 accounts or add-ons that have been hidden from your\nown lists. Nothing legitimate hides from you.<\/li>\n<li><strong>Code running on your pages.<\/strong> Which outside companies run code on your shop,\nwhen one of them quietly changes what it sends you, and web addresses that are\nnear-identical imitations of ones you trust.<\/li>\n<\/ul>\n\n<h4>Built to be quiet<\/h4>\n\n<p>A security tool that cries wolf gets switched off, and then it protects nobody.\nDecaGuard spends its first two days simply learning your shop and raising\nnothing at all. It knows that add-on updates change files constantly, that\npayment gateways send odd-looking data, and that bulk imports look like attacks.\nFindings are graded, and anything you confirm as expected stays quiet for good.<\/p>\n\n<h4>What this plugin sends outside your site<\/h4>\n\n<p>DecaGuard makes a small number of outbound requests, all of them listed here:<\/p>\n\n<ol>\n<li><strong>api.wordpress.org<\/strong> \u2014 downloads the official checksum list for your exact\nWordPress version, so modified core files can be spotted. No information about\nyour site is sent; only the version number and language are in the request.<\/li>\n<li><strong>Your own shop's public pages<\/strong> \u2014 the plugin requests your homepage, cart page\nand one product page, exactly as a visitor's browser would, to see what code\nruns on them. These requests never leave your own server.<\/li>\n<li><p><strong>Files your pages already load from other companies<\/strong> \u2014 if one of your pages\nloads a file from, say, a payment provider or a chat widget, the plugin\ndownloads that same file and compares it with what it saw last time. This is\nwhat lets it tell you when a company you rely on quietly changes the code it\nruns on your shop, which is how several large 2026 attacks worked.<\/p>\n\n<p>The request is anonymous: it identifies the plugin and nothing else. Your\naddress, your shop's name, your customers and your orders are not part of it,\nand no data is sent anywhere \u2014 the plugin only downloads. Only addresses that\nalready appear in your own pages are ever requested.<\/p>\n\n<p>If you would rather it did not, switch off <strong>Outside code<\/strong> under\nDecaGuard \u2192 Settings. Every other check carries on working.\nNo customer data, order data, or personal information ever leaves your site.<\/p><\/li>\n<\/ol>\n\n<!--section=installation-->\n<ol>\n<li>In your WordPress admin, go to Plugins \u2192 Add New and search for \"DecaGuard\".<\/li>\n<li>Click Install Now, then Activate.<\/li>\n<li>Open <strong>DecaGuard \u2192 Settings<\/strong>, enter the address you want warnings sent to,\nand tick \"Send me a summary of anything found\". Anything urgent or important\nis emailed the moment it appears; everything else arrives in a daily summary.<\/li>\n<\/ol>\n\n<p>That is all. DecaGuard begins learning your shop straight away.<\/p>\n\n<p>For the first two days it watches quietly and raises nothing, so it can learn what\nis normal on your shop before it starts telling you about changes. After that,\nanything it finds appears on the <strong>DecaGuard<\/strong> screen.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20slow%20my%20shop%20down%3F\"><h3>Will this slow my shop down?<\/h3><\/dt>\n<dd><p>No. DecaGuard adds nothing at all to the pages your customers see. All the work\nhappens in the background, in small pieces, and pauses itself so it never hogs\nyour hosting.<\/p><\/dd>\n<dt id=\"will%20it%20break%20my%20shop%3F\"><h3>Will it break my shop?<\/h3><\/dt>\n<dd><p>It cannot. DecaGuard only looks \u2014 it never changes, deletes, or blocks anything.\nIt also never goes near your checkout or your payment gateway.<\/p><\/dd>\n<dt id=\"it%20says%20a%20new%20add-on%20appeared%2C%20but%20that%20was%20me.\"><h3>It says a new add-on appeared, but that was me.<\/h3><\/dt>\n<dd><p>Then click \"This was me\". It records that, and you will not be asked about that\none again.<\/p><\/dd>\n<dt id=\"why%20did%20it%20not%20tell%20me%20anything%20for%20the%20first%20two%20days%3F\"><h3>Why did it not tell me anything for the first two days?<\/h3><\/dt>\n<dd><p>Because it was learning. Every shop is different, and a tool that starts shouting\nbefore it knows what is normal on yours is a tool that gets switched off. After\ntwo days it has a picture of your shop and will tell you when that picture\nchanges.<\/p><\/dd>\n<dt id=\"i%20already%20run%20another%20security%20plugin.%20is%20that%20a%20problem%3F\"><h3>I already run another security plugin. Is that a problem?<\/h3><\/dt>\n<dd><p>No, but you may hear about the same thing twice, once from each. DecaGuard\nnotices when another security plugin is active and mentions it on the dashboard.<\/p><\/dd>\n<dt id=\"does%20it%20clean%20up%20an%20infection%3F\"><h3>Does it clean up an infection?<\/h3><\/dt>\n<dd><p>No, deliberately. Attacks usually leave several ways back in, and automatic\ncleanup either misses one or deletes something your shop needs. DecaGuard tells\nyou what it found and what to do about it, and leaves the decision to you and your\ndeveloper.<\/p><\/dd>\n<dt id=\"does%20it%20work%20without%20woocommerce%3F\"><h3>Does it work without WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. The checks all work on any WordPress site. The cart and product page checks\nsimply do not run when WooCommerce is not installed.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>Instant email now covers every urgent and important finding for everyone.<\/li>\n<li>Prefixed all classes, options, tables and scheduled tasks to avoid collisions.<\/li>\n<li>Uses the WordPress path APIs throughout, fixing a case where a wp-config.php\nlocated above the site root was never checked.<\/li>\n<li>Removed the site address from requests for third-party files, and added a\nsetting to switch those requests off entirely.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<li>File, database, account and page-code monitoring.<\/li>\n<li>Severity grading with a false-positive exclusions layer.<\/li>\n<li>Two-day learning period on activation.<\/li>\n<li>Dashboard with one-click confirmation, instant email on urgent findings, and a\ndaily summary email.<\/li>\n<\/ul>","raw_excerpt":"Tells you in plain English when something changes on your shop that you did not change. Watches only \u2014 it never blocks, deletes, or repairs anything.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/356193","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=356193"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/deca1992"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=356193"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=356193"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=356193"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=356193"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=356193"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=356193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}