{"id":358071,"date":"2026-08-30T10:22:48","date_gmt":"2026-08-30T10:22:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/guardlms\/"},"modified":"2026-08-30T18:10:41","modified_gmt":"2026-08-30T18:10:41","slug":"guardlms","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/guardlms\/","author":23554230,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.2.2","stable_tag":"0.2.2","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"GuardLMS","header_author":"LdesignMedia","header_description":"Reports this site's WordPress core, plugin, theme and environment inventory to GuardLMS for CVE and security monitoring.","assets_banners_color":"12223a","last_updated":"2026-08-30 18:10:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/guardlms.com","header_author_uri":"https:\/\/ldesignmedia.nl","rating":0,"author_block_rating":0,"active_installs":0,"downloads":38,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.2.2":{"tag":"0.2.2","author":"luukverhoeven","date":"2026-08-30 18:10:41","revision":3672972}},"upgrade_notice":{"0.2.0":"<p>Adds optional real-time JavaScript error monitoring for your visitors&#039; browsers. Off by\ndefault; no action is required to keep 0.1.0 behaviour.<\/p>","0.1.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3672369,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3672369,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3672369,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3672369,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3672369,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.2.2"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[250388,5603,600,6460],"plugin_category":[54],"plugin_contributors":[278298],"plugin_business_model":[],"class_list":["post-358071","plugin","type-plugin","status-publish","hentry","plugin_tags-cve","plugin_tags-monitoring","plugin_tags-security","plugin_tags-vulnerability","plugin_category-security-and-spam-protection","plugin_contributors-luukverhoeven","plugin_committers-luukverhoeven"],"banners":{"banner":"https:\/\/ps.w.org\/guardlms\/assets\/banner-772x250.png?rev=3672369","banner_2x":"https:\/\/ps.w.org\/guardlms\/assets\/banner-1544x500.png?rev=3672369","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/guardlms\/assets\/icon.svg?rev=3672369","icon":"https:\/\/ps.w.org\/guardlms\/assets\/icon.svg?rev=3672369","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>GuardLMS keeps your WordPress installation under continuous vulnerability monitoring. Once\nconfigured, the plugin sends a daily snapshot of your site's software inventory to the GuardLMS\nservice (<a href=\"https:\/\/dashboard.guardlms.com\">dashboard.guardlms.com<\/a>), where it is matched against a database of known CVEs\naffecting WordPress core, plugins, and themes. If a vulnerable component is detected, it is\nsurfaced in your GuardLMS dashboard so you can patch or remove it before it is exploited.<\/p>\n\n<p><strong>What the plugin does<\/strong><\/p>\n\n<ul>\n<li>Collects the installed WordPress core version, the full plugin inventory (including\nmust-use plugins and drop-ins) with slugs, names, versions and active state, and the active\ntheme inventory with slugs, names and versions.<\/li>\n<li>Collects basic server and PHP environment details (operating system, hostname, web server\nsignature, PHP version, SAPI, memory\/execution limits, and loaded extensions) to help GuardLMS\nassess environment-specific risk.<\/li>\n<li>Pushes this snapshot to GuardLMS once a day via a background (WP-Cron) task, and on demand\nwhenever you click \"Push now\" in the plugin settings.<\/li>\n<li>Renders a <code>&lt;meta name=\"guardlms-verification\"&gt;<\/code> tag in your site's <code>&lt;head&gt;<\/code> so GuardLMS can\nverify that you own the site. The token is installed by the connect flow.<\/li>\n<li>Optionally includes a small, non-secret set of configuration flags (<code>WP_DEBUG<\/code>,\n  force_ssl_admin, <code>users_can_register<\/code>, <code>default_role<\/code>, <code>blog_public<\/code>) when you explicitly\nopt in, disabled by default.<\/li>\n<\/ul>\n\n<p>Setup is one click: \"Connect to GuardLMS\" sends you to GuardLMS to confirm, then installs the\npush key and verifies ownership automatically. No API key to copy.<\/p>\n\n<p><strong>Source code and issues<\/strong><\/p>\n\n<p>Development happens in the open on <a href=\"https:\/\/github.com\/LdesignMedia\/wordpress-guardlms\">GitHub<\/a>.\nReport bugs, suggest improvements or send a pull request there.<\/p>\n\n<h4>Third Party Services<\/h4>\n\n<p>This plugin relies on a third-party service, <strong>GuardLMS<\/strong> (<a href=\"https:\/\/dashboard.guardlms.com\">dashboard.guardlms.com<\/a>), to\nperform CVE and vulnerability monitoring for your site. This section discloses exactly what is\nshared with that service, in line with the WordPress.org plugin guidelines.<\/p>\n\n<p><strong>What is sent to GuardLMS:<\/strong><\/p>\n\n<ul>\n<li>Your WordPress core version number.<\/li>\n<li>Your installed plugin and theme slugs, versions, and active\/inactive state (including\nmust-use plugins and drop-ins).<\/li>\n<li>Basic server details: operating system, hostname, and web server software string.<\/li>\n<li>Basic PHP environment details: PHP version, SAPI, memory limit, max execution time, upload\nand post size limits, timezone, and the list of loaded PHP extensions.<\/li>\n<li>Optionally, if you explicitly enable \"Include configuration\" in the plugin settings, a small\nallowlist of non-secret configuration flags (<code>WP_DEBUG<\/code>, <code>force_ssl_admin<\/code>,\n  users_can_register, <code>default_role<\/code>, <code>blog_public<\/code>).<\/li>\n<li>Your site URL, used by GuardLMS to identify which registered website the data belongs to.<\/li>\n<\/ul>\n\n<p><strong>What is never sent:<\/strong> no personal data, no user data, no post\/page content, no database\ncontents, and no secrets or credentials of any kind. The GuardLMS API key you configure is used\nonly to authenticate the outgoing push request to GuardLMS and is never included in the\ntransmitted payload.<\/p>\n\n<p><strong>When data is sent:<\/strong> once daily via a scheduled background task, and immediately whenever you\nclick \"Push now\" on the plugin settings page.<\/p>\n\n<p><strong>Real-time monitoring (optional, off by default).<\/strong> If you switch on \"Real-time monitoring\" in\nthe plugin settings, the plugin additionally loads a GuardLMS JavaScript file on your public\npages, which reports JavaScript errors from your visitors' browsers directly to GuardLMS. This\nis a separate opt-in and nothing is loaded or sent while it is switched off.<\/p>\n\n<ul>\n<li><strong>What the script sends:<\/strong> the error message and stack trace, the page URL and referrer, the\nbrowser user agent and viewport size, and an anonymous per-session identifier. If you also\nswitch on the optional analytics checkbox, it sends page-view events too.<\/li>\n<li><strong>What the script never sends:<\/strong> GuardLMS is never told which user is logged in \u2014 the plugin\nnever identifies a visitor to the service. The script does not record clicks, keystrokes or\nform input, and does not collect the visitor's IP address. Security tokens in URLs\n(<code>_wpnonce<\/code>, <code>sesskey<\/code>, <code>token<\/code>, <code>apiKey<\/code>, <code>authorization<\/code>, <code>password<\/code>, <code>secret<\/code>) are replaced\nwith <code>[REDACTED]<\/code> before anything leaves the browser.<\/li>\n<li><strong>Where it is loaded:<\/strong> public front-end pages only. Never in wp-admin and never on the login\nscreen.<\/li>\n<\/ul>\n\n<p>By installing and configuring this plugin, you agree to GuardLMS's own Terms of Service and\nPrivacy Policy, which govern how GuardLMS itself handles the data described above:<\/p>\n\n<ul>\n<li><a href=\"https:\/\/guardlms.com\/terms\">Terms of Service<\/a><\/li>\n<li><a href=\"https:\/\/guardlms.com\/privacy\">Privacy Policy<\/a><\/li>\n<\/ul>\n\n<p>If you do not wish to use this third-party service, do not enter a GuardLMS API key, or\ndeactivate\/uninstall the plugin \u2014 no data is sent to GuardLMS while the plugin is disabled or\nunconfigured.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>guardlms<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install the plugin\nthrough the WordPress Plugins screen directly.<\/li>\n<li>Activate the plugin through the \"Plugins\" screen in WordPress.<\/li>\n<li>Go to <strong>Settings \u2192 GuardLMS<\/strong>.<\/li>\n<li>Click \"Connect to GuardLMS\". You are sent to GuardLMS to sign in or create a free account and\nconfirm the connection, then returned to your site.<\/li>\n<li>That is it. The site is registered, ownership is verified automatically, the push key is\ninstalled and the first inventory push is queued.<\/li>\n<\/ol>\n\n<p>Advanced settings (base URL, push path, API key, verification token, manual push) are hidden on\npurpose so a working connection cannot be broken by accident. Support and self-hosted setups can\nreach them at <code>\/wp-admin\/options-general.php?page=guardlms&amp;advanced=1<\/code>, or pin them in\n    wp-config.php with <code>GUARDLMS_PUSH_KEY<\/code>, <code>GUARDLMS_BASEURL<\/code> and <code>GUARDLMS_PUSHPATH<\/code>.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20send%20any%20personal%20or%20user%20data%20to%20guardlms%3F\"><h3>Does this plugin send any personal or user data to GuardLMS?<\/h3><\/dt>\n<dd><p>The daily inventory push sends none: GuardLMS receives only your WordPress core version,\nplugin\/theme inventory, and server\/PHP environment details as described in the \"Third Party\nServices\" section above. No posts, pages, users, or database content are ever transmitted.<\/p>\n\n<p>If you switch on the optional real-time monitoring, the GuardLMS script running in your\nvisitors' browsers additionally sends page URLs, referrers, user agents and error stack traces.\nGuardLMS is never told which user is logged in, and the script neither records what a visitor\nclicked or typed nor collects their IP address. Read the \"Real-time monitoring\" bullets in the\n\"Third Party Services\" section before switching it on, and mention it in your own privacy\npolicy if your jurisdiction requires it.<\/p><\/dd>\n<dt id=\"how%20do%20i%20turn%20on%20real-time%20error%20monitoring%3F\"><h3>How do I turn on real-time error monitoring?<\/h3><\/dt>\n<dd><p>Connect the site, then tick \"Report JavaScript errors from visitors' browsers to GuardLMS\"\nunder Settings -&gt; GuardLMS and save. There is no key to copy. Use \"Send a test error\" to\nconfirm it is working \u2014 it reports back in your own browser, and tells you if another plugin is\ndeferring or blocking the script.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20guardlms%20account%3F\"><h3>Do I need a GuardLMS account?<\/h3><\/dt>\n<dd><p>Yes. You need a GuardLMS account. A free account is enough.\n<a href=\"https:\/\/dashboard.guardlms.com\">Register at dashboard.guardlms.com<\/a>, or create one during the\nconnect flow.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20don%27t%20connect%20the%20site%3F\"><h3>What happens if I don't connect the site?<\/h3><\/dt>\n<dd><p>The plugin stays inactive: no data is collected or sent, and the daily push is skipped until you\nclick \"Connect to GuardLMS\".<\/p><\/dd>\n<dt id=\"why%20did%20my%20push%20key%20stop%20working%20after%20i%20cloned%20or%20moved%20my%20site%3F\"><h3>Why did my push key stop working after I cloned or moved my site?<\/h3><\/dt>\n<dd><p>GuardLMS ties a push key to the site URL it was issued for. If the plugin detects that your\nsite's URL has changed since the key was saved (for example after cloning to a staging\nenvironment), it automatically clears the stored key so the clone cannot push data as if it\nwere the original site. Click \"Connect to GuardLMS\" again to reconnect the new URL.<\/p><\/dd>\n<dt id=\"where%20can%20i%20report%20a%20bug%20or%20contribute%3F\"><h3>Where can I report a bug or contribute?<\/h3><\/dt>\n<dd><p>The plugin is developed on <a href=\"https:\/\/github.com\/LdesignMedia\/wordpress-guardlms\">GitHub<\/a>. Open an\nissue there for bugs and feature requests, or send a pull request.<\/p><\/dd>\n<dt id=\"how%20often%20is%20data%20sent%3F\"><h3>How often is data sent?<\/h3><\/dt>\n<dd><p>Once a day via WP-Cron, plus on demand with \"Push now\" in the advanced view.<\/p><\/dd>\n<dt id=\"is%20my%20guardlms%20api%20key%20stored%20securely%3F\"><h3>Is my GuardLMS API key stored securely?<\/h3><\/dt>\n<dd><p>The API key is stored in a dedicated, non-autoloaded WordPress option and is never included in\noutgoing payload data. You may alternatively define <code>GUARDLMS_PUSH_KEY<\/code> as a constant in\n    wp-config.php, which takes precedence over the stored key and keeps it out of the database\nentirely.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.2.2<\/h4>\n\n<ul>\n<li>Settings screen styling and the \"Replace SDK key\" confirmation are now a\nstylesheet and script enqueued on the plugin screen only, instead of inline\nstyles and an inline event handler.<\/li>\n<li>Admin notices about a changed site URL or an expiring key are shown only to\nadministrators, are dismissible, and link straight to the Reconnect button.<\/li>\n<\/ul>\n\n<h4>0.2.1<\/h4>\n\n<ul>\n<li>Fixed the default GuardLMS endpoint: the plugin now talks to\nhttps:\/\/dashboard.guardlms.com. Earlier releases shipped https:\/\/app.guardlms.com,\na host that was never put into service, so connecting and the daily push failed on\nthe default configuration. Sites that kept the old default are moved over\nautomatically; a custom (self-hosted) base URL is left untouched.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>Added optional real-time monitoring: a GuardLMS script on your public pages reports\nJavaScript errors from visitors' browsers, with optional page-view analytics. Off by\ndefault; switch it on under Settings -&gt; GuardLMS. No key to copy \u2014 connecting the site\ninstalls it, and sites connected before this release fetch it the first time the settings\npage is opened.<\/li>\n<li>Added \"Send a test error\", which reports back in your own browser and tells you when another\nplugin is deferring or blocking the script.<\/li>\n<li>Added \"Replace SDK key\" for rotating the real-time credential. Nothing rotates automatically.<\/li>\n<li>The plugin refuses to load the script when it already knows the data would be rejected (no\nactive subscription, or real-time monitoring switched off in the GuardLMS dashboard) and says\nwhich one it is, rather than reporting \"on\" and collecting nothing.<\/li>\n<li>Disconnecting now revokes the real-time credential at GuardLMS before clearing the local key.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial Phase 1 release: daily\/on-demand inventory push (core, plugins, themes,\nserver\/PHP environment) to GuardLMS using a manually issued API key, settings page,\nkey-expiry warning, clone\/URL guard, and optional pasted-token ownership verification meta\ntag.<\/li>\n<\/ul>","raw_excerpt":"Reports your WordPress core, plugin and theme inventory to GuardLMS daily so known CVEs affecting your site are detected automatically.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/358071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=358071"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/luukverhoeven"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=358071"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=358071"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=358071"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=358071"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=358071"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=358071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}