It shows its working
Most security plugins tell you your site is fine. Pharos tells you 3,337 core files matched WordPress.org’s checksums and 8 components were checked against published advisories, with timestamps. A conclusion you cannot check is only an assertion.
It cannot lock you out
Nothing is written to wp-config.php and no server configuration is touched. Every protection is applied at runtime and stops the moment you deactivate the plugin. The most common way a security plugin ruins someone’s day is by editing files and locking the owner out of the screens they need to undo it. That is designed out.
It tells you what it will break, first
Disabling XML-RPC affects older Jetpack versions and some mobile publishing apps. Pharos says so before you press the button, not after.
What it is not
There is no firewall and no malware signature scanner. Those need a maintained ruleset to be worth anything, and a bad one is worse than none because it implies protection that is not there.
Pharos does assessment, hardening and remediation. If you want request filtering, put a WAF in front of your site — Pharos will detect it and tell you it is there.
Free, and honest about what comes later
The plugin is free and the features above stay free. A paid tier is planned that runs scans from our servers on a reliable schedule — WP-Cron only fires when your site gets traffic, so on a quiet site a “daily” scan can be days late — and alerts you when something changes.
Saying so here on day one so nobody is surprised by it later.