Most shop owners find out they have been hacked when their payment provider tells
them, or when a customer complains about a fraudulent charge. By then the damage
is done.
DecaGuard learns what your shop normally looks like, then watches for anything
that changes without your say-so: files appearing where files should not appear,
new administrator accounts, hidden add-ons, settings that quietly gained code in
them, and outside companies that started running code on your pages.
When it finds something, it explains what happened in ordinary language — what
the risk is to your money and your customers, and what to do next. If the change
was you, one click marks it as expected and you never hear about it again.
DecaGuard never blocks, deletes, quarantines, modifies, or repairs anything on
your shop. It is not a firewall, it does not sit between your customers and your
pages, and it never touches your checkout, your payment gateway callbacks, or the
WooCommerce API.
This is deliberate. Real compromises leave several ways back in. Automated
cleanup either misses one — leaving you confidently reinfected — or deletes
something your shop needs and takes it offline. Both are worse than a clear
warning and a decision you make yourself.
A security tool that cries wolf gets switched off, and then it protects nobody.
DecaGuard spends its first two days simply learning your shop and raising
nothing at all. It knows that add-on updates change files constantly, that
payment gateways send odd-looking data, and that bulk imports look like attacks.
Findings are graded, and anything you confirm as expected stays quiet for good.
DecaGuard makes a small number of outbound requests, all of them listed here:
Files your pages already load from other companies — if one of your pages
loads a file from, say, a payment provider or a chat widget, the plugin
downloads that same file and compares it with what it saw last time. This is
what lets it tell you when a company you rely on quietly changes the code it
runs on your shop, which is how several large 2026 attacks worked.
The request is anonymous: it identifies the plugin and nothing else. Your
address, your shop’s name, your customers and your orders are not part of it,
and no data is sent anywhere — the plugin only downloads. Only addresses that
already appear in your own pages are ever requested.
If you would rather it did not, switch off Outside code under
DecaGuard Settings. Every other check carries on working.
No customer data, order data, or personal information ever leaves your site.