{"id":369054,"date":"2026-09-15T19:04:17","date_gmt":"2026-09-15T19:04:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/karetaker\/"},"modified":"2026-09-17T16:07:47","modified_gmt":"2026-09-17T16:07:47","slug":"karetaker","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/karetaker\/","author":23562426,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.1","stable_tag":"1.1.1","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Karetaker","header_author":"Team Krikir","header_description":"Watches a WordPress site for the changes that indicate compromise, and tells the owner only when something needs them.","assets_banners_color":"686764","last_updated":"2026-09-17 16:07:47","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/karetaker\/","header_author_uri":"https:\/\/www.krikir.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":127,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.1":{"tag":"0.1.1","author":"krikir","date":"2026-09-15 19:03:55","revision":3697610},"0.1.3":{"tag":"0.1.3","author":"krikir","date":"2026-09-16 04:33:59","revision":3697901},"1.0.0":{"tag":"1.0.0","author":"krikir","date":"2026-09-16 21:52:11","revision":3699264},"1.0.1":{"tag":"1.0.1","author":"krikir","date":"2026-09-17 08:17:15","revision":3699777},"1.1.1":{"tag":"1.1.1","author":"krikir","date":"2026-09-17 16:07:47","revision":3700573}},"upgrade_notice":{"1.1.1":"<p>Small developer update. No visible changes.<\/p>","1.1.0":"<p>Advanced mode is removed. Every check, alert and protection stays; Settings gains privacy and data options.<\/p>","1.0.2":"<p>Maintenance release with extension hooks for developers. No visible changes.<\/p>","1.0.1":"<p>Clearer, better-looking alert and summary emails.<\/p>","1.0.0":"<p>First public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3697610,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3697610,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500-rtl.png":{"filename":"banner-1544x500-rtl.png","revision":3697610,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3697610,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250-rtl.png":{"filename":"banner-772x250-rtl.png","revision":3697610,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3697610,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.1","0.1.3","1.0.0","1.0.1","1.1.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3700573,"resolution":"1","location":"assets","locale":"","width":2256,"height":2486},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3700573,"resolution":"2","location":"assets","locale":"","width":2256,"height":1700},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3700573,"resolution":"3","location":"assets","locale":"","width":2256,"height":1340},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3700573,"resolution":"4","location":"assets","locale":"","width":2256,"height":2554},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3700573,"resolution":"5","location":"assets","locale":"","width":2256,"height":1908},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3700573,"resolution":"6","location":"assets","locale":"","width":2256,"height":3614},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3700573,"resolution":"7","location":"assets","locale":"","width":2256,"height":1040}},"screenshots":{"1":"Home when something needs you: a plain-language headline and a card per problem, each with \"Show me what to do\".","2":"Home when there is nothing urgent: worth a look, but it can wait.","3":"Home on a quiet week, because staying silent is the point.","4":"Activity: everything Karetaker recorded, grouped by day and written in plain words.","5":"Protection: optional protections you can switch on or off. None of them can lock you out.","6":"Settings: where alerts go, the weekly summary, a one-hour pause, site type, and privacy and data options.","7":"The one-minute setup that runs on first activation."}},"plugin_section":[],"plugin_tags":[8531,168808,31093,5603,600],"plugin_category":[54],"plugin_contributors":[280945],"plugin_business_model":[],"class_list":["post-369054","plugin","type-plugin","status-publish","hentry","plugin_tags-activity-log","plugin_tags-file-integrity","plugin_tags-hardening","plugin_tags-monitoring","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-krikir","plugin_committers-krikir"],"banners":{"banner":"https:\/\/ps.w.org\/karetaker\/assets\/banner-772x250.png?rev=3697610","banner_2x":"https:\/\/ps.w.org\/karetaker\/assets\/banner-1544x500.png?rev=3697610","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/karetaker\/assets\/icon-128x128.png?rev=3697610","icon_2x":"https:\/\/ps.w.org\/karetaker\/assets\/icon-256x256.png?rev=3697610","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/karetaker\/assets\/screenshot-1.png?rev=3700573","caption":"Home when something needs you: a plain-language headline and a card per problem, each with \"Show me what to do\"."},{"src":"https:\/\/ps.w.org\/karetaker\/assets\/screenshot-2.png?rev=3700573","caption":"Home when there is nothing urgent: worth a look, but it can wait."},{"src":"https:\/\/ps.w.org\/karetaker\/assets\/screenshot-3.png?rev=3700573","caption":"Home on a quiet week, because staying silent is the point."},{"src":"https:\/\/ps.w.org\/karetaker\/assets\/screenshot-4.png?rev=3700573","caption":"Activity: everything Karetaker recorded, grouped by day and written in plain words."},{"src":"https:\/\/ps.w.org\/karetaker\/assets\/screenshot-5.png?rev=3700573","caption":"Protection: optional protections you can switch on or off. None of them can lock you out."},{"src":"https:\/\/ps.w.org\/karetaker\/assets\/screenshot-6.png?rev=3700573","caption":"Settings: where alerts go, the weekly summary, a one-hour pause, site type, and privacy and data options."},{"src":"https:\/\/ps.w.org\/karetaker\/assets\/screenshot-7.png?rev=3700573","caption":"The one-minute setup that runs on first activation."}],"raw_content":"<!--section=description-->\n<p>Karetaker is a <strong>watchtower<\/strong>, not a wall.<\/p>\n\n<p>Most security plugins either shout at you all day or quietly lock you out of your own\nsite. Karetaker does neither. It watches the handful of changes that actually mean\nsomething went wrong, keeps a readable record, and emails you only when a human needs\nto act.<\/p>\n\n<h4>What it watches<\/h4>\n\n<ul>\n<li><strong>Scripts<\/strong>: new external JavaScript domains after a local baseline (home, and cart\/checkout when WooCommerce is active)<\/li>\n<li><strong>Search engine cloaking<\/strong>: once a day, compares your home page as a visitor and as Googlebot, and flags hidden spam links<\/li>\n<li><strong>Integrity<\/strong>: core and plugin file changes, checked against published WordPress.org checksums<\/li>\n<li><strong>Options<\/strong>: changes to the settings that matter, plus curated suspicious option names and unusual new autoload names<\/li>\n<li><strong>Privileges<\/strong>: role and capability changes, new administrators, user promotions<\/li>\n<li><strong>Uploads<\/strong>: files appearing in <code>wp-content\/uploads<\/code> that do not belong there<\/li>\n<li><strong>Cron drift<\/strong>: scheduled tasks that vanish, stall, or appear from nowhere<\/li>\n<li><strong>Plugin risk<\/strong>: closed or abandoned plugins on WordPress.org, and plugins whose listed owner changed<\/li>\n<li><strong>Optional vulnerability lookup<\/strong>: when you enable it, active plugin versions are checked against public WPVulnerability data (off by default)<\/li>\n<\/ul>\n\n<h4>One-checkbox catastrophes<\/h4>\n\n<p>The quiet business killers that no scanner reports, because technically nothing is \"hacked\":<\/p>\n\n<ul>\n<li>Search engine visibility switched off<\/li>\n<li>Site email failing to send<\/li>\n<li>No administrators left on the site<\/li>\n<li>Invalid or unreachable admin email<\/li>\n<\/ul>\n\n<h4>Opt-in hardening, with receipts<\/h4>\n\n<p>A small set of hardening toggles, every one of them <strong>off until you turn it on<\/strong>, and\nevery one reversible from Karetaker \u2192 Protection. Each toggle shows <em>Desired<\/em> next to\n<em>Live now<\/em>, so you always see what is actually in effect rather than what was merely\nrequested.<\/p>\n\n<h4>How it reaches you<\/h4>\n\n<ul>\n<li><strong>Visibility is pull<\/strong>: the Karetaker admin screen and WP-CLI<\/li>\n<li><strong>Notification is push<\/strong>: email to the site owner, on ACT-severity events only<\/li>\n<li><strong>Optional Slack \/ Telegram \/ Discord \/ Microsoft Teams<\/strong>: webhooks or Bot API, off until you turn them on<\/li>\n<li><strong>Optional weekly summary<\/strong>: one short email on Monday mornings, off until you turn it on<\/li>\n<li><strong>Pause alerts<\/strong> for an hour while you work on the site; one catch-up email afterwards if something needed you<\/li>\n<li><strong>Your data, your file<\/strong>: download the activity log as CSV at any time<\/li>\n<li><strong>Hardening is off<\/strong> until each toggle is switched on<\/li>\n<\/ul>\n\n<h4>Who it is for<\/h4>\n\n<ul>\n<li><strong>Site owners<\/strong> who want to know their site is fine without reading a dashboard every morning<\/li>\n<li><strong>Freelancers and agencies<\/strong> handing a site over to a client, who still need to know if something breaks later<\/li>\n<\/ul>\n\n<h4>It is deliberately not<\/h4>\n\n<ul>\n<li>A WAF or request firewall<\/li>\n<li>A malware signature scanner<\/li>\n<li>A login lockout or hide-login product by default<\/li>\n<li>A writer of <code>wp-config.php<\/code>, <code>.htaccess<\/code>, or server config<\/li>\n<\/ul>\n\n<h4>Kill switch<\/h4>\n\n<p>Define <code>KARETAKER_DISABLE<\/code> as true in <code>wp-config.php<\/code>, or place an empty file at\n    wp-content\/karetaker-disable. The plugin then boots nothing. Uninstall removes the\nplugin's table, options, and scheduled hooks.<\/p>\n\n<h4>Open source<\/h4>\n\n<p>Karetaker is GPL, built by <a href=\"https:\/\/www.krikir.com\/\">Team Krikir<\/a>. It does not phone\nhome, load third-party scripts, or show ads. Issues and pull requests are welcome.<\/p>\n\n<h4>Credits<\/h4>\n\n<p>Karetaker ships no third-party code, fonts or images. It relies on these projects and services,\nand thanks them:<\/p>\n\n<ul>\n<li><a href=\"https:\/\/wordpress.org\/\">WordPress<\/a> and the WordPress.org APIs for core and plugin checksums, plugin directory information, and security keys<\/li>\n<li><a href=\"https:\/\/www.wpvulnerability.com\/\">WPVulnerability<\/a> for the optional public vulnerability database (vulnerability details shown in Karetaker come from WPVulnerability and the sources it links to)<\/li>\n<li><a href=\"https:\/\/simpleicons.org\/\">Simple Icons<\/a> for the destination logos shown in Settings (CC0 1.0)<\/li>\n<li><a href=\"https:\/\/slack.com\/\">Slack<\/a> incoming webhooks, the <a href=\"https:\/\/telegram.org\/\">Telegram<\/a> Bot API, <a href=\"https:\/\/discord.com\/\">Discord<\/a> webhooks and <a href=\"https:\/\/www.microsoft.com\/microsoft-teams\/\">Microsoft Teams<\/a> workflows for the optional alert channels<\/li>\n<li><a href=\"https:\/\/github.com\/PHPCSStandards\/PHP_CodeSniffer\">PHP_CodeSniffer<\/a>, <a href=\"https:\/\/github.com\/WordPress\/WordPress-Coding-Standards\">WordPress Coding Standards<\/a> and <a href=\"https:\/\/github.com\/PHPCompatibility\/PHPCompatibilityWP\">PHPCompatibilityWP<\/a>, used during development only<\/li>\n<\/ul>\n\n<p>WordPress is a registered trademark of the WordPress Foundation. Microsoft and Microsoft Teams\nare trademarks of the Microsoft group of companies. Slack is a trademark of Slack Technologies, LLC.\nDiscord is a trademark of Discord Inc.\nGoogle and Googlebot are trademarks of Google LLC. Telegram and all other trademarks are the property of their\nrespective owners. Karetaker is an independent project by Team Krikir. It is not created,\nendorsed, sponsored or certified by any of these companies; their names are used only to\ndescribe the services Karetaker can connect to.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>karetaker<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the zip via Plugins \u2192 Add New \u2192 Upload.<\/li>\n<li>Activate through the Plugins screen.<\/li>\n<li>Open Karetaker in the admin sidebar. The one-minute setup asks where alerts go and what kind of site this is, runs a first check, and offers three safe protections.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20a%20firewall%3F\"><h3>Is this a firewall?<\/h3><\/dt>\n<dd><p>No. Karetaker watches and alerts. It does not filter HTTP traffic.<\/p><\/dd>\n<dt id=\"will%20it%20lock%20me%20out%20of%20wp-login%3F\"><h3>Will it lock me out of wp-login?<\/h3><\/dt>\n<dd><p>Not by default. There is no login lockout or renamed login URL in the default set.\nHardening toggles are opt-in and reversible from Karetaker \u2192 Protection.<\/p><\/dd>\n<dt id=\"how%20do%20i%20stop%20it%20immediately%3F\"><h3>How do I stop it immediately?<\/h3><\/dt>\n<dd><p>Define <code>KARETAKER_DISABLE<\/code> as true in <code>wp-config.php<\/code>, or create\n    wp-content\/karetaker-disable. The plugin then boots nothing.<\/p><\/dd>\n<dt id=\"what%20happened%20to%20advanced%20mode%3F\"><h3>What happened to Advanced mode?<\/h3><\/dt>\n<dd><p>Agency tools (issue tracking with owners, incident cases, client reports, role access and\nthe read-only API) are no longer part of Karetaker. Everything that watches your site,\nalerts you and protects it stays here and stays free: every check, every alert channel,\nthe weekly summary, all protections and the activity export.<\/p><\/dd>\n<dt id=\"does%20uninstall%20leave%20data%20behind%3F\"><h3>Does uninstall leave data behind?<\/h3><\/dt>\n<dd><p>No. Uninstall drops the events table, plugin options, and cron hooks.<\/p><\/dd>\n<dt id=\"what%20if%20i%20think%20the%20site%20was%20hacked%3F\"><h3>What if I think the site was hacked?<\/h3><\/dt>\n<dd><p>Run <code>wp karetaker incident<\/code>. That runs a deeper multi-pass scan and shows a checklist\n(admins, plugins, uploads PHP, integrity, Guard, passwords). If you think someone else is\nlogged in, use Karetaker \u2192 Protection \u2192 \"Sign out all administrators\". Karetaker does not\nclean malware or lock anyone out; it is a guided review, not a clean certificate.<\/p><\/dd>\n<dt id=\"can%20hosting%20providers%20use%20this%3F\"><h3>Can hosting providers use this?<\/h3><\/dt>\n<dd><p>Yes. Karetaker does not ship a WAF, does not lock logins by default, and does not write\nserver config. <code>wp karetaker status<\/code> prints the host safety profile as JSON, and Site\nHealth reports scan freshness, Guard flags, and the same profile. Kill switch: <code>KARETAKER_DISABLE<\/code> or <code>wp-content\/karetaker-disable<\/code>.<\/p><\/dd>\n<dt id=\"what%20data%20leaves%20the%20site%3F\"><h3>What data leaves the site?<\/h3><\/dt>\n<dd><p>By default, only integrity checks contact WordPress.org to fetch published core\/plugin\nchecksums (same family of APIs WordPress itself uses). Optional features you turn on\nyourself may also leave the site: ACT alert emails (to the address you choose), an ACT\nwebhook POST (to the URL you set), Slack Incoming Webhooks, Telegram Bot API, Discord and\nMicrosoft Teams webhook messages (when enabled), the weekly summary and end-of-pause emails\n(when enabled), and vulnerability lookup requests to wpvulnerability.net (plugin slug only,\nwhen enabled under Settings). The daily \"What Google sees\" check requests your own home\npage twice (once with a Googlebot user agent); it does not contact Google. Karetaker does not phone home to Team Krikir and does\nnot load third-party scripts or ads.<\/p>\n\n<p>When you enable those optional services, you also accept their terms:<\/p>\n\n<ul>\n<li>Slack: https:\/\/slack.com\/terms-of-service and https:\/\/slack.com\/privacy-policy<\/li>\n<li>Telegram: https:\/\/telegram.org\/tos\/bot-developers and https:\/\/telegram.org\/privacy<\/li>\n<li>Discord: https:\/\/discord.com\/terms and https:\/\/discord.com\/privacy<\/li>\n<li>Microsoft Teams: https:\/\/www.microsoft.com\/servicesagreement and https:\/\/privacy.microsoft.com\/privacystatement<\/li>\n<li>WPVulnerability: https:\/\/www.wpvulnerability.com\/ (public vulnerability database API)<\/li>\n<\/ul><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Developer: filters for the navigation label and the footer version text, so add-ons can name their screens.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Advanced mode is gone. Agency tools (issue tracking with owners, detailed monitoring, incident cases, client reports, role access and the read-only API) are no longer part of Karetaker.<\/li>\n<li>Settings now holds the vulnerability lookup switch, how many events to keep, trusted proxies, a test alert button and email previews.<\/li>\n<li>Protection has \"Sign out all administrators\" for when you think someone else is logged in.<\/li>\n<li>Activity has a Download CSV button.<\/li>\n<li>Developer: new filters karetaker_settings_defaults and karetaker_admin_setting.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Developer: an extension API (actions, filters and a JavaScript bridge) so add-ons can extend Karetaker without editing it.<\/li>\n<li>Tidier stylesheet comments.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>New email design for alerts, the weekly summary, the pause summary and test emails, matching the admin screens.<\/li>\n<li>Clearer subjects that lead with the status and name the site, for example \"Act now: A must-use plugin file changed \u00b7 example.com\".<\/li>\n<li>Every email now has a readable plain-text version and a readable technical details table instead of raw data.<\/li>\n<li>The logo no longer breaks in email clients or when SMTP plugins are active.<\/li>\n<li>Summaries group repeated events into one line with a count.<\/li>\n<li>Preview any email from Advanced mode \u2192 Incidents \u2192 Alert routing.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<p>First public release.<\/p>\n\n<ul>\n<li>Sixty-second setup: where to send alerts, what kind of site this is, a first check, and three safe protections.<\/li>\n<li>Home: plain-language status, a to-do card for anything that needs you, and the twelve checks Karetaker runs.<\/li>\n<li>Watches: critical files, WordPress core and plugin files against official checksums, administrators (including accounts hidden from the Users screen), plugin risk signals from WordPress.org, must-use plugins, the uploads folder, scheduled tasks, option names, external script domains, what search engines see, failed logins, search visibility and email delivery.<\/li>\n<li>Activity: everything Karetaker recorded, kept in your own database.<\/li>\n<li>Protection: seven optional protections that cannot lock you out. Karetaker never edits wp-config.php or .htaccess.<\/li>\n<li>Alerts by email, and optionally Telegram, Slack, Discord, Microsoft Teams or your own webhook, with a weekly summary and a one-hour pause while you work.<\/li>\n<li>Advanced mode for agencies and developers: issue tracking with owners, detailed monitoring, incident cases with a response checklist, client reports, CSV\/JSON\/ZIP exports, role permissions and read-only API tokens.<\/li>\n<li>WP-CLI commands and an emergency off switch.<\/li>\n<\/ul>","raw_excerpt":"Hacked-site alerts, file integrity, and new-admin watch for WordPress. A quiet watchtower, not a firewall.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/369054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=369054"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/krikir"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=369054"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=369054"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=369054"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=369054"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=369054"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=369054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}