From the outside you can’t tell whether a plugin needs an important update, whether system files have been modified, or whether a backup even exists. WM Guard reads exactly these things – directly on your server – and shows them in plain language under Settings WM Guard.
WM Guard’s site assessment works without an account or a connection to Witte Marketing. Optional Witte Marketing services are activated only by explicit user action. Optional online diagnostics use WordPress.org APIs only after an administrator actively enables them in Settings, as documented below. WM Guard turns technical WordPress checks into a clear overview of your site’s condition and the issues that deserve your attention.
What WM Guard checks
Principles
Extra protection (optional)
On request, WM Guard can switch on individual protections: make username enumeration harder (block the REST users list and the ?author query for anonymous visitors), disable XML-RPC, lock the backend file editor, and neutralize login messages. All are off by default, work purely at runtime through WordPress filters – no file is changed – and each can be switched off again at any time.
Optional: the free Web Check by Witte Marketing
On request – and only after an explicit action – you can additionally request a free external analysis of your site (loading time, findability, accessibility, legal notice requirements) and have the detailed report sent to you by email. Optionally you can also enable ongoing monitoring by Witte Marketing. Without these actions, no site data is sent to Witte Marketing. WordPress.org queries are separate optional online diagnostics requiring their own opt-in.
WM Guard has optional WordPress.org online diagnostics and optional services by Witte Marketing (Werner Witte, Ampfing, Germany). It also offers an independently clickable vulnerability lookup and, if you enable online diagnostics, DNS and own-site HTTP checks. Witte Marketing is contacted only after the explicit actions described below.
1. Free external analysis
When you click “Get free external analysis”, the address and name of this site plus the installed WM Guard version are sent to https://witte.marketing/wp-json/wm-webcheck/v1/agent/analyze so the publicly reachable homepage can be checked from the outside and the result shown here.
2. Request the detailed report
When you submit the report form, the address of this site, the contact name and email address you entered, your consent flag, and the consent-text version are sent to https://witte.marketing/wp-json/wm-webcheck/v1/agent/report to deliver the report to you by email (with a confirmation link, double opt-in).
3. Enable ongoing monitoring
When you enable monitoring, the address and name of this site, the WM Guard endpoint, an access key, and the installed WM Guard version are sent to https://witte.marketing/wp-json/wm-webcheck/v1/agent/connect. After that, Witte Marketing may retrieve the technical overview shown above. The access key is accepted only through the X-WM-Agent-Key request header, not as a URL parameter. If an optional Witte Marketing workflow needs the current consent text and it is not already available from the previous response, WM Guard may read it from https://witte.marketing/wp-json/wm-webcheck/v1/agent/consent after that workflow has been initiated by the administrator.
4. Show external monitoring
If a connection exists, WM Guard retrieves the monitoring data (uptime, outages, server response time, page performance, SSL/domain expiry) from https://witte.marketing/wp-json/wm-webcheck/v1/agent/monitoring when you open its page, and displays it. Only the address of this site and the access key are sent. Without an existing connection, nothing is retrieved.
In no case are content, usernames, passwords, database credentials or full logs transmitted. You can end an activation again at any time.
Provider and legal information:
5. Official WordPress.org APIs (optional online diagnostics, off by default)
Only after you enable “Allow optional online diagnostics” under Settings WM Guard Settings, WM Guard may query WordPress.org when you open its page or during an enabled notification run. For core-file integrity, WM Guard queries https://api.wordpress.org/core/checksums/1.0/ and sends the installed WordPress version and package locale. For the removed/unmaintained-plugin check, WM Guard queries https://api.wordpress.org/plugins/info/1.2/ and sends the plugin identifier (slug). These checks are cached (core checksums: 12 hours; plugin-directory result: 24 hours) and use a neutral WM Guard/<version> user agent so the site’s address is not included in the HTTP user agent. WM Guard does not run these WordPress.org checks or schedule directory queries before the opt-in. You can turn it off again at any time; pending directory jobs and their cached results are removed. No separate outbound connectivity request is sent; reachability is inferred from WordPress’ existing update state.
Provider: WordPress.org – privacy policy: https://wordpress.org/about/privacy/
Additional online diagnostics under the same opt-in
With this setting enabled, WM Guard can query public SPF and DMARC DNS TXT records for the domain of the site, and send HTTP GET/POST requests to its own site URL for maintenance-mode, REST and loopback checks. DNS lookups necessarily reveal the queried domain to the configured DNS resolver. The self-requests contact the website server and can appear in its access logs. Results are cached. Without opt-in, these checks are unavailable rather than reported as successful. This option does not activate any Witte Marketing service.
6. Known-vulnerability check (wpvulnerability.net)
Independently of Witte Marketing, you can click “Check for security vulnerabilities now” in the “Known security vulnerabilities” area. WM Guard then queries the free, public vulnerability database wpvulnerability.net for each installed plugin (https://www.wpvulnerability.net/plugin/<plugin-identifier>/). Only the identifier (the directory name) of each plugin is transmitted – no version numbers, not the address of your site, and no personal data; the comparison against your installed versions happens locally afterwards. In its default state, and without this click, nothing is queried. No access key is required.
Provider: wpvulnerability.net – website and terms of use: https://www.wpvulnerability.net/