{"id":367883,"date":"2026-09-24T06:53:47","date_gmt":"2026-09-24T06:53:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/wm-guard\/"},"modified":"2026-09-24T06:53:19","modified_gmt":"2026-09-24T06:53:19","slug":"wm-guard","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/wm-guard\/","author":23474845,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.2","requires":"6.7","requires_php":"8.1","requires_plugins":null,"header_name":"WM Guard","header_author":"WM Plugins","header_description":"Technical WordPress site checks for updates, file integrity, backups and security status in plain language.","assets_banners_color":"3348b6","last_updated":"2026-09-24 06:53:19","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/wm-plugins.de","rating":0,"author_block_rating":0,"active_installs":0,"downloads":33,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"wittemarketing","date":"2026-09-24 06:53:19","revision":3710678}},"upgrade_notice":{"1.0.0":"<p>Initial public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.jpg":{"filename":"icon-128x128.jpg","revision":3710692,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.jpg":{"filename":"icon-256x256.jpg","revision":3710692,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.jpg":{"filename":"banner-1544x500.jpg","revision":3710692,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":3710692,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[262246],"plugin_tags":[151,732,5603,600,2550],"plugin_category":[52,54,59],"plugin_contributors":[263518],"plugin_business_model":[],"class_list":["post-367883","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-backup","plugin_tags-maintenance","plugin_tags-monitoring","plugin_tags-security","plugin_tags-updates","plugin_category-performance","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-wittemarketing","plugin_committers-wittemarketing"],"banners":{"banner":"https:\/\/ps.w.org\/wm-guard\/assets\/banner-772x250.jpg?rev=3710692","banner_2x":"https:\/\/ps.w.org\/wm-guard\/assets\/banner-1544x500.jpg?rev=3710692","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/wm-guard\/assets\/icon-128x128.jpg?rev=3710692","icon_2x":"https:\/\/ps.w.org\/wm-guard\/assets\/icon-256x256.jpg?rev=3710692","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>From the outside you can't tell whether a plugin needs an important update, whether system files have been modified, or whether a backup even exists. <strong>WM Guard<\/strong> reads exactly these things \u2013 directly on your server \u2013 and shows them in plain language under <em>Settings \u2192 WM Guard<\/em>.<\/p>\n\n<p>WM Guard's site assessment works without an account or a connection to Witte Marketing. Optional Witte Marketing services are activated only by explicit user action. Optional online diagnostics use WordPress.org APIs only after an administrator actively enables them in Settings, as documented below. WM Guard turns technical WordPress checks into a clear overview of your site's condition and the issues that deserve your attention.<\/p>\n\n<p><strong>What WM Guard checks<\/strong><\/p>\n\n<ul>\n<li>PHP version including end of security support<\/li>\n<li>WordPress version and pending updates for plugins and themes<\/li>\n<li>Unmodified core files (checksum comparison against WordPress.org)<\/li>\n<li>Program files in the uploads folder \u2013 a typical hiding place for backdoors<\/li>\n<li>Backup: detected solution and age of the last backup<\/li>\n<li>Maintenance mode and search engine visibility<\/li>\n<li>Default user role and open self-registration<\/li>\n<li>The \"admin\" username, error display (debug), folder permissions<\/li>\n<li>System email addresses, database version, memory limit<\/li>\n<li>Email authentication of your domain: SPF record and DMARC policy (via DNS)<\/li>\n<li>Further condition checks in the spirit of WordPress Site Health: recommended PHP extensions, autoload data size, object cache, database character set, automatic plugin updates, WordPress memory limit<\/li>\n<li>Inactive plugins and themes, pretty permalinks<\/li>\n<li>Recommended, privacy-friendly plugins per category (statistics, spam protection, SMTP, activity log, text-to-speech)<\/li>\n<\/ul>\n\n<p><strong>Principles<\/strong><\/p>\n\n<ul>\n<li><strong>Never changes your files.<\/strong> The assessment only reads \u2013 it runs nothing and writes no files.<\/li>\n<li><strong>No automatic transfer to Witte Marketing.<\/strong> Site data is sent to Witte Marketing only after an explicit action (see \"External services\").<\/li>\n<li><strong>Online diagnostics require consent.<\/strong> Core checksum and plugin-directory checks use official WordPress.org APIs only after an administrator enables optional online diagnostics in Settings. They use a neutral WM Guard user agent and send only the WordPress version\/locale or plugin identifier required for the check \u2013 not your site's URL, content, usernames, passwords, or customer data.<\/li>\n<li><strong>No personal content is transmitted.<\/strong> The assessment does not transmit site content, usernames, passwords, database credentials, orders, or customer data to Witte Marketing.<\/li>\n<li><strong>Protection only on request.<\/strong> The optional extra protection is off by default, works purely at runtime, and can be switched off again at any time \u2013 it too changes no file.<\/li>\n<li><strong>Switch off any time.<\/strong> WM Guard can be deactivated at any time, and its own stored data is removed on uninstall.<\/li>\n<\/ul>\n\n<p><strong>Extra protection (optional)<\/strong><\/p>\n\n<p>On request, WM Guard can switch on individual protections: make username enumeration harder (block the REST users list and the ?author query for anonymous visitors), disable XML-RPC, lock the backend file editor, and neutralize login messages. All are off by default, work purely at runtime through WordPress filters \u2013 no file is changed \u2013 and each can be switched off again at any time.<\/p>\n\n<p><strong>Optional: the free Web Check by Witte Marketing<\/strong><\/p>\n\n<p>On request \u2013 and only after an explicit action \u2013 you can additionally request a free external analysis of your site (loading time, findability, accessibility, legal notice requirements) and have the detailed report sent to you by email. Optionally you can also enable ongoing monitoring by Witte Marketing. Without these actions, no site data is sent to Witte Marketing. WordPress.org queries are separate optional online diagnostics requiring their own opt-in.<\/p>\n\n<h3>External services<\/h3>\n\n<p>WM Guard has optional WordPress.org online diagnostics and optional services by Witte Marketing (Werner Witte, Ampfing, Germany). It also offers an independently clickable vulnerability lookup and, if you enable online diagnostics, DNS and own-site HTTP checks. Witte Marketing is contacted only after the explicit actions described below.<\/p>\n\n<p><strong>1. Free external analysis<\/strong>\nWhen you click \"Get free external analysis\", the address and name of this site plus the installed WM Guard version are sent to <code>https:\/\/witte.marketing\/wp-json\/wm-webcheck\/v1\/agent\/analyze<\/code> so the publicly reachable homepage can be checked from the outside and the result shown here.<\/p>\n\n<p><strong>2. Request the detailed report<\/strong>\nWhen you submit the report form, the address of this site, the contact name and email address you entered, your consent flag, and the consent-text version are sent to <code>https:\/\/witte.marketing\/wp-json\/wm-webcheck\/v1\/agent\/report<\/code> to deliver the report to you by email (with a confirmation link, double opt-in).<\/p>\n\n<p><strong>3. Enable ongoing monitoring<\/strong>\nWhen you enable monitoring, the address and name of this site, the WM Guard endpoint, an access key, and the installed WM Guard version are sent to <code>https:\/\/witte.marketing\/wp-json\/wm-webcheck\/v1\/agent\/connect<\/code>. After that, Witte Marketing may retrieve the technical overview shown above. The access key is accepted only through the <code>X-WM-Agent-Key<\/code> request header, not as a URL parameter. If an optional Witte Marketing workflow needs the current consent text and it is not already available from the previous response, WM Guard may read it from <code>https:\/\/witte.marketing\/wp-json\/wm-webcheck\/v1\/agent\/consent<\/code> after that workflow has been initiated by the administrator.<\/p>\n\n<p><strong>4. Show external monitoring<\/strong>\nIf a connection exists, WM Guard retrieves the monitoring data (uptime, outages, server response time, page performance, SSL\/domain expiry) from <code>https:\/\/witte.marketing\/wp-json\/wm-webcheck\/v1\/agent\/monitoring<\/code> when you open its page, and displays it. Only the address of this site and the access key are sent. Without an existing connection, nothing is retrieved.<\/p>\n\n<p>In no case are content, usernames, passwords, database credentials or full logs transmitted. You can end an activation again at any time.<\/p>\n\n<p>Provider and legal information:<\/p>\n\n<ul>\n<li>Privacy policy: https:\/\/witte.marketing\/datenschutz\/<\/li>\n<li>Legal notice: https:\/\/witte.marketing\/impressum\/<\/li>\n<li>Web Check service description: https:\/\/witte.marketing\/web-check\/<\/li>\n<\/ul>\n\n<p><strong>5. Official WordPress.org APIs (optional online diagnostics, off by default)<\/strong>\nOnly after you enable \"Allow optional online diagnostics\" under Settings \u2192 WM Guard \u2192 Settings, WM Guard may query WordPress.org when you open its page or during an enabled notification run. For core-file integrity, WM Guard queries <code>https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/code> and sends the installed WordPress version and package locale. For the removed\/unmaintained-plugin check, WM Guard queries <code>https:\/\/api.wordpress.org\/plugins\/info\/1.2\/<\/code> and sends the plugin identifier (slug). These checks are cached (core checksums: 12 hours; plugin-directory result: 24 hours) and use a neutral <code>WM Guard\/&lt;version&gt;<\/code> user agent so the site's address is not included in the HTTP user agent. WM Guard does not run these WordPress.org checks or schedule directory queries before the opt-in. You can turn it off again at any time; pending directory jobs and their cached results are removed. No separate outbound connectivity request is sent; reachability is inferred from WordPress' existing update state.<\/p>\n\n<p>Provider: WordPress.org \u2013 privacy policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<p><strong>Additional online diagnostics under the same opt-in<\/strong>\nWith this setting enabled, WM Guard can query public SPF and DMARC DNS TXT records for the domain of the site, and send HTTP GET\/POST requests to its own site URL for maintenance-mode, REST and loopback checks. DNS lookups necessarily reveal the queried domain to the configured DNS resolver. The self-requests contact the website server and can appear in its access logs. Results are cached. Without opt-in, these checks are unavailable rather than reported as successful. This option does not activate any Witte Marketing service.<\/p>\n\n<p><strong>6. Known-vulnerability check (wpvulnerability.net)<\/strong>\nIndependently of Witte Marketing, you can click \"Check for security vulnerabilities now\" in the \"Known security vulnerabilities\" area. WM Guard then queries the free, public vulnerability database wpvulnerability.net for each installed plugin (<code>https:\/\/www.wpvulnerability.net\/plugin\/&lt;plugin-identifier&gt;\/<\/code>). Only the identifier (the directory name) of each plugin is transmitted \u2013 no version numbers, not the address of your site, and no personal data; the comparison against your installed versions happens locally afterwards. In its default state, and without this click, nothing is queried. No access key is required.<\/p>\n\n<p>Provider: wpvulnerability.net \u2013 website and terms of use: https:\/\/www.wpvulnerability.net\/<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate the plugin.<\/li>\n<li>View local results under <strong>Settings \u2192 WM Guard<\/strong>. Optional: enable online diagnostics on the Settings tab to consent to documented network checks.<\/li>\n<li>Optional: request a free external analysis or enable ongoing monitoring.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20wm%20guard%20change%20my%20site%3F\"><h3>Can WM Guard change my site?<\/h3><\/dt>\n<dd><p>The assessment only reads and changes no file. In addition there are optional protections (extra protection): they are off by default, work only at runtime, and can be switched off again at any time \u2013 they too write or change no file.<\/p><\/dd>\n<dt id=\"is%20data%20transmitted%20automatically%3F\"><h3>Is data transmitted automatically?<\/h3><\/dt>\n<dd><p>No site data is sent to Witte Marketing unless you explicitly use one of the optional actions described under \"External services\". Optional WordPress.org, DNS and self-HTTP diagnostics are disabled until you actively enable them in Settings. The independent wpvulnerability.net lookup runs only when you click its button.<\/p><\/dd>\n<dt id=\"do%20i%20have%20to%20connect%20to%20witte%20marketing%20to%20use%20the%20plugin%3F\"><h3>Do I have to connect to Witte Marketing to use the plugin?<\/h3><\/dt>\n<dd><p>No. The technical overview works without a Witte Marketing account or connection. WordPress.org integrity and plugin-directory checks can be enabled separately under Settings \u2192 WM Guard \u2192 Settings. The Witte Marketing connection is a different optional add-on.<\/p><\/dd>\n<dt id=\"what%20if%20the%20access%20key%20falls%20into%20the%20wrong%20hands%3F\"><h3>What if the access key falls into the wrong hands?<\/h3><\/dt>\n<dd><p>Generate a new key under <em>Settings \u2192 WM Guard<\/em>. The previous one stops working immediately. Alternatively, block access completely or end the connection.<\/p><\/dd>\n<dt id=\"does%20wm%20guard%20promise%20security%3F\"><h3>Does WM Guard promise security?<\/h3><\/dt>\n<dd><p>No. It points out technical issues and helps with maintenance. Security is risk reduction, not a guarantee.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial public release of WM Guard.<\/li>\n<li>Read-only WordPress health and security assessment with plain-language findings.<\/li>\n<li>Checks WordPress, PHP, plugin and theme updates, core-file integrity, suspicious files, backup status, maintenance mode, permissions, configuration, email authentication and additional Site Health-style conditions.<\/li>\n<li>Optional runtime hardening for username enumeration, XML-RPC, the backend file editor and login messages.<\/li>\n<li>Optional known-vulnerability check via wpvulnerability.net, started only by explicit administrator action.<\/li>\n<li>Optional Witte Marketing Web Check and monitoring integration, activated only by explicit administrator action.<\/li>\n<li>External monitoring endpoint is locked by default; access keys are accepted only through the <code>X-WM-Agent-Key<\/code> request header.<\/li>\n<li>Optional WordPress.org, DNS and self-HTTP checks require explicit opt-in; WordPress.org requests use a neutral user agent and are documented under \"External services\".<\/li>\n<li>Includes malware-scan safeguards to prevent the scanner's own built-in web-shell signatures from triggering false positives.<\/li>\n<li>Daily notification processing is scheduled only when alarm or monthly-report notifications are enabled.<\/li>\n<li>Prepared for WordPress.org translation delivery through translate.wordpress.org; no bundled <code>.po<\/code> or <code>.mo<\/code> files are included.<\/li>\n<\/ul>","raw_excerpt":"Technical WordPress site checks for updates, file integrity, backups and security status in plain language.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/367883","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=367883"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wittemarketing"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=367883"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=367883"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=367883"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=367883"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=367883"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=367883"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}