Pharos

A lighthouse does not block anything.
It watches, and it warns.

Pharos checks your WordPress site against WordPress.org’s own checksums and published security advisories, hardens what is weak, and shows you exactly what it verified.

3,337core files verified
15configuration checks
0data sent to us

It shows its working

Most security plugins tell you your site is fine. Pharos tells you 3,337 core files matched WordPress.org’s checksums and 8 components were checked against published advisories, with timestamps. A conclusion you cannot check is only an assertion.

It cannot lock you out

Nothing is written to wp-config.php and no server configuration is touched. Every protection is applied at runtime and stops the moment you deactivate the plugin. The most common way a security plugin ruins someone’s day is by editing files and locking the owner out of the screens they need to undo it. That is designed out.

It tells you what it will break, first

Disabling XML-RPC affects older Jetpack versions and some mobile publishing apps. Pharos says so before you press the button, not after.

What it is not

There is no firewall and no malware signature scanner. Those need a maintained ruleset to be worth anything, and a bad one is worse than none because it implies protection that is not there.

Pharos does assessment, hardening and remediation. If you want request filtering, put a WAF in front of your site — Pharos will detect it and tell you it is there.

Free, and honest about what comes later

The plugin is free and the features above stay free. A paid tier is planned that runs scans from our servers on a reliable schedule — WP-Cron only fires when your site gets traffic, so on a quiet site a “daily” scan can be days late — and alerts you when something changes.

Saying so here on day one so nobody is surprised by it later.