Karetaker Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Karetaker is a watchtower, not a wall.
It notices the changes that usually mean compromise (file and option integrity, privilege changes, uploads surprises, cron drift), watches for one-checkbox business catastrophes (search engines off, mail failing, no administrators, invalid admin email), can apply a small set of opt-in hardening toggles with clear receipts, and emails the site owner only for act-now events.
It is deliberately not:
- a WAF or request firewall
- a malware signature scanner
- a login lockout / hide-login product by default
- a writer of
wp-config.php,.htaccess, or server config
Visibility is pull (Karetaker admin screen, WP-CLI, optional signed REST status). Notification is push (email on ACT-severity events). Hardening is off until you turn each toggle on.
An optional agency status endpoint (/wp-json/karetaker/v1/status) is off until you generate a token. The token never grants remote control — status only.
Kill switch: define KARETAKER_DISABLE as true, or place an empty file at wp-content/karetaker-disable. Uninstall removes the plugin’s table, options, and scheduled hooks.
Screenshots
Overview — product intro, last scan, Guard flags, and event counts.
Activity — the events log with Log/Watch/Act-now labels and readable context.
Harden — opt-in toggles with Desired vs Live now receipts.
Settings — alert email, trusted proxies, ACT webhook, and agency token controls.

