5,233 GPL Products · Updated DailyPRO Versions Available · Instant Download
WM Guard 1.0.0 – WordPress Plugin

WM Guard

v1.0.0 Updated 2 days ago
Download WM Guard 1.0.0
Free download · version 1.0.0

Description

At a glance

WM Guard v1.0.0 is a free WordPress plugin with 10+ active installs, updated September 24, 2026, requires WordPress 6.7+ & PHP 8.1+. Download the latest GPL version below — free, with live demo included.

From the outside you can’t tell whether a plugin needs an important update, whether system files have been modified, or whether a backup even exists. WM Guard reads exactly these things – directly on your server – and shows them in plain language under Settings WM Guard.

WM Guard’s site assessment works without an account or a connection to Witte Marketing. Optional Witte Marketing services are activated only by explicit user action. Optional online diagnostics use WordPress.org APIs only after an administrator actively enables them in Settings, as documented below. WM Guard turns technical WordPress checks into a clear overview of your site’s condition and the issues that deserve your attention.

What WM Guard checks

  • PHP version including end of security support
  • WordPress version and pending updates for plugins and themes
  • Unmodified core files (checksum comparison against WordPress.org)
  • Program files in the uploads folder – a typical hiding place for backdoors
  • Backup: detected solution and age of the last backup
  • Maintenance mode and search engine visibility
  • Default user role and open self-registration
  • The “admin” username, error display (debug), folder permissions
  • System email addresses, database version, memory limit
  • Email authentication of your domain: SPF record and DMARC policy (via DNS)
  • Further condition checks in the spirit of WordPress Site Health: recommended PHP extensions, autoload data size, object cache, database character set, automatic plugin updates, WordPress memory limit
  • Inactive plugins and themes, pretty permalinks
  • Recommended, privacy-friendly plugins per category (statistics, spam protection, SMTP, activity log, text-to-speech)

Principles

  • Never changes your files. The assessment only reads – it runs nothing and writes no files.
  • No automatic transfer to Witte Marketing. Site data is sent to Witte Marketing only after an explicit action (see “External services”).
  • Online diagnostics require consent. Core checksum and plugin-directory checks use official WordPress.org APIs only after an administrator enables optional online diagnostics in Settings. They use a neutral WM Guard user agent and send only the WordPress version/locale or plugin identifier required for the check – not your site’s URL, content, usernames, passwords, or customer data.
  • No personal content is transmitted. The assessment does not transmit site content, usernames, passwords, database credentials, orders, or customer data to Witte Marketing.
  • Protection only on request. The optional extra protection is off by default, works purely at runtime, and can be switched off again at any time – it too changes no file.
  • Switch off any time. WM Guard can be deactivated at any time, and its own stored data is removed on uninstall.

Extra protection (optional)

On request, WM Guard can switch on individual protections: make username enumeration harder (block the REST users list and the ?author query for anonymous visitors), disable XML-RPC, lock the backend file editor, and neutralize login messages. All are off by default, work purely at runtime through WordPress filters – no file is changed – and each can be switched off again at any time.

Optional: the free Web Check by Witte Marketing

On request – and only after an explicit action – you can additionally request a free external analysis of your site (loading time, findability, accessibility, legal notice requirements) and have the detailed report sent to you by email. Optionally you can also enable ongoing monitoring by Witte Marketing. Without these actions, no site data is sent to Witte Marketing. WordPress.org queries are separate optional online diagnostics requiring their own opt-in.

External services

WM Guard has optional WordPress.org online diagnostics and optional services by Witte Marketing (Werner Witte, Ampfing, Germany). It also offers an independently clickable vulnerability lookup and, if you enable online diagnostics, DNS and own-site HTTP checks. Witte Marketing is contacted only after the explicit actions described below.

1. Free external analysis
When you click “Get free external analysis”, the address and name of this site plus the installed WM Guard version are sent to https://witte.marketing/wp-json/wm-webcheck/v1/agent/analyze so the publicly reachable homepage can be checked from the outside and the result shown here.

2. Request the detailed report
When you submit the report form, the address of this site, the contact name and email address you entered, your consent flag, and the consent-text version are sent to https://witte.marketing/wp-json/wm-webcheck/v1/agent/report to deliver the report to you by email (with a confirmation link, double opt-in).

3. Enable ongoing monitoring
When you enable monitoring, the address and name of this site, the WM Guard endpoint, an access key, and the installed WM Guard version are sent to https://witte.marketing/wp-json/wm-webcheck/v1/agent/connect. After that, Witte Marketing may retrieve the technical overview shown above. The access key is accepted only through the X-WM-Agent-Key request header, not as a URL parameter. If an optional Witte Marketing workflow needs the current consent text and it is not already available from the previous response, WM Guard may read it from https://witte.marketing/wp-json/wm-webcheck/v1/agent/consent after that workflow has been initiated by the administrator.

4. Show external monitoring
If a connection exists, WM Guard retrieves the monitoring data (uptime, outages, server response time, page performance, SSL/domain expiry) from https://witte.marketing/wp-json/wm-webcheck/v1/agent/monitoring when you open its page, and displays it. Only the address of this site and the access key are sent. Without an existing connection, nothing is retrieved.

In no case are content, usernames, passwords, database credentials or full logs transmitted. You can end an activation again at any time.

Provider and legal information:

  • Privacy policy: https://witte.marketing/datenschutz/
  • Legal notice: https://witte.marketing/impressum/
  • Web Check service description: https://witte.marketing/web-check/

5. Official WordPress.org APIs (optional online diagnostics, off by default)
Only after you enable “Allow optional online diagnostics” under Settings WM Guard Settings, WM Guard may query WordPress.org when you open its page or during an enabled notification run. For core-file integrity, WM Guard queries https://api.wordpress.org/core/checksums/1.0/ and sends the installed WordPress version and package locale. For the removed/unmaintained-plugin check, WM Guard queries https://api.wordpress.org/plugins/info/1.2/ and sends the plugin identifier (slug). These checks are cached (core checksums: 12 hours; plugin-directory result: 24 hours) and use a neutral WM Guard/<version> user agent so the site’s address is not included in the HTTP user agent. WM Guard does not run these WordPress.org checks or schedule directory queries before the opt-in. You can turn it off again at any time; pending directory jobs and their cached results are removed. No separate outbound connectivity request is sent; reachability is inferred from WordPress’ existing update state.

Provider: WordPress.org – privacy policy: https://wordpress.org/about/privacy/

Additional online diagnostics under the same opt-in
With this setting enabled, WM Guard can query public SPF and DMARC DNS TXT records for the domain of the site, and send HTTP GET/POST requests to its own site URL for maintenance-mode, REST and loopback checks. DNS lookups necessarily reveal the queried domain to the configured DNS resolver. The self-requests contact the website server and can appear in its access logs. Results are cached. Without opt-in, these checks are unavailable rather than reported as successful. This option does not activate any Witte Marketing service.

6. Known-vulnerability check (wpvulnerability.net)
Independently of Witte Marketing, you can click “Check for security vulnerabilities now” in the “Known security vulnerabilities” area. WM Guard then queries the free, public vulnerability database wpvulnerability.net for each installed plugin (https://www.wpvulnerability.net/plugin/<plugin-identifier>/). Only the identifier (the directory name) of each plugin is transmitted – no version numbers, not the address of your site, and no personal data; the comparison against your installed versions happens locally afterwards. In its default state, and without this click, nothing is queried. No access key is required.

Provider: wpvulnerability.net – website and terms of use: https://www.wpvulnerability.net/

Frequently asked questions

What do I get when I download WM Guard?

WM Guard 1.0.0 is the latest version. It is a WordPress plugin you can download here free of charge under the GPL license, with the complete feature set included and no trial limitations.

Does WM Guard cost anything?

No. WM Guard 1.0.0 is 100% free — the full GPL version, not a trial or demo. There are no download limits, no accounts to create, and no upsells during the download.

How do I install WM Guard 1.0.0?

Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.

What are the requirements for WM Guard?

WM Guard 1.0.0 requires WordPress 6.7 or higher and PHP 8.1 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.

When was WM Guard last updated?

Version 1.0.0 was last updated on September 24, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.

Is the WM Guard download safe?

The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.

Version: 1.0.0
Updated: October 1, 2026

Technical details

Version1.0.0
Last updatedSeptember 24, 2026
Active installs10+
Requires WordPress6.7 or higher
Requires PHP8.1 or higher
AuthorWitte Marketing
Tagsbackup, maintenance, monitoring, security, updates

Download WM Guard

Download WM Guard WP Plugin

Official Page ↗

Note: if the download does not start, disable your ad blocker and try again.

Leave a Comment