Prof Designs Guardian
Secure lightweight WordPress monitoring and automatic maintenance system built around MU plugins.
by Prof Designs · github.com/prof-designs/prof-designs-guardian · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/prof-designs/prof-designs-guardian/archive/refs/heads/main.zipLightweight WordPress monitoring and maintenance plugin.
Features
- Automatic WordPress core updates
- Automatic plugin updates
- Automatic theme updates
- Fatal PHP error monitoring
- Website health checks
- Health endpoint with monitor-friendly HTTP status (200/503)
- Smart email notifications
- Anti-flood protection
- File editor protection (blocks theme/plugin editors)
- Plugin/theme installation lockdown (optional)
- Upload security hardening
- Malicious file upload prevention
- MU plugin compatible
- Secure local-first architecture
Philosophy
Guardian is designed around a simple principle:
- no remote control
- no external dependencies
- no unnecessary noise
If the website works correctly, Guardian stays silent. If problems appear, Guardian notifies administrators intelligently.
Optional wp-config.php Settings
By default (no configuration needed):
- Auto-updates: ENABLED
- Manual changes: BLOCKED
- Email alerts: sent to site admin email
To customize, add these constants to wp-config.php:
// Custom email for priority support alerts (optional)
// Default: site admin email from Settings → General
define('PROFDESIGNS_GUARDIAN_EMAIL', 'alerts@example.com');
// To DISABLE plugin/theme modification lock (when you need to install/update manually):
// Default: true (locked for security)
define('PROFDESIGNS_GUARDIAN_LOCK_MODS', false);
// To DISABLE automatic updates (not recommended):
// Default: true (auto-updates enabled)
define('PROFDESIGNS_GUARDIAN_AUTO_UPDATES', false);
Security Protection Levels:
- File editing - Always blocked (theme/plugin editors disabled)
- Plugin/Theme modifications - Blocked by default via
PROFDESIGNS_GUARDIAN_LOCK_MODS - Automatic updates - Enabled by default via
PROFDESIGNS_GUARDIAN_AUTO_UPDATES; runs at filter priority 999 to override any per-plugin/theme opt-outs
Configuration Scenarios:
-
Maximum Security (Default)
// No constants needed - both default to true // - Auto-updates: ENABLED // - Manual changes: BLOCKED -
Disable Auto-Updates, Keep Security
define('PROFDESIGNS_GUARDIAN_AUTO_UPDATES', false); // - Auto-updates: DISABLED // - Manual changes: BLOCKED (you'll need LOCK_MODS=false to update manually) -
Allow Manual Changes, Keep Auto-Updates
define('PROFDESIGNS_GUARDIAN_LOCK_MODS', false); // - Auto-updates: ENABLED // - Manual changes: ALLOWED -
Disable Everything
define('PROFDESIGNS_GUARDIAN_AUTO_UPDATES', false); define('PROFDESIGNS_GUARDIAN_LOCK_MODS', false); // - Auto-updates: DISABLED // - Manual changes: ALLOWED
When PROFDESIGNS_GUARDIAN_LOCK_MODS is true (default), no admin user can:
- Install plugins from repository or upload .zip files
- Install or upload themes
- Delete plugins or themes
- Manually update plugins or themes via admin dashboard
Admins can still deactivate active plugins for recovery/troubleshooting.
When locked, the UI elements for these actions are automatically hidden to avoid confusion.
This provides the same protection as DISALLOW_FILE_MODS but can be temporarily disabled for maintenance without deactivating the plugin.
Temporarily Enable Manual Changes
When you need to manually install/update plugins or themes:
- Add to
wp-config.php:define('PROFDESIGNS_GUARDIAN_LOCK_MODS', false); - Perform your maintenance work
- Remove the line or set it back to
true
The changes take effect automatically on the next admin page load. No need to deactivate the plugin.
Installation as Must-Use Plugin
To ensure Guardian is always active and cannot be accidentally deactivated, install it as a Must-Use (MU) plugin.
Steps:
- Upload the
prof-designs-guardianfolder towp-content/mu-plugins/ - Upload the
prof-designs-guardian-loader.phpfile towp-content/mu-plugins/ - (Optional) Run
composer install --no-devfor optimized autoloading
Note: Composer is optional. The plugin includes a fallback autoloader that works without Composer.
The loader file is included in the plugin package for convenience.
Architecture
Guardian uses a modern Laravel/Sage-inspired architecture with:
- Service Providers: Modular bootstrapping of features
- Dependency Injection: Container-based service resolution (use closures for complex dependencies)
- PSR-4 Autoloading: Modern namespace-based class loading
- Application Container: Centralized service management
- Single Responsibility: Each service handles one specific concern
- Health Endpoint:
/wp-json/prof-guardian/v1/health(authenticated administrators only) Returns HTTP200when healthy, HTTP503when unhealthy.
For Developers
If you're extending Guardian or integrating it with other plugins:
// Access the application container
$app = guardian();
// Resolve services
$security = $app->make(\ProfDesigns\Guardian\Services\SecurityService::class);
$mailer = $app->make(\ProfDesigns\Guardian\Services\MailerService::class);
// Register custom services
$app->singleton(MyCustomService::class, function ($app) {
return new MyCustomService($app->make(SomeDependency::class));
});