Karetaker is a
watchtower, not a wall.
Most security plugins either shout at you all day or quietly lock you out of your own
site. Karetaker does neither. It watches the handful of changes that actually mean
something went wrong, keeps a readable record, and emails you only when a human needs
to act.
What it watches
- Scripts: new external JavaScript domains after a local baseline (home, and cart/checkout when WooCommerce is active)
- Search engine cloaking: once a day, compares your home page as a visitor and as Googlebot, and flags hidden spam links
- Integrity: core and plugin file changes, checked against published WordPress.org checksums
- Options: changes to the settings that matter, plus curated suspicious option names and unusual new autoload names
- Privileges: role and capability changes, new administrators, user promotions
- Uploads: files appearing in
wp-content/uploads that do not belong there
- Cron drift: scheduled tasks that vanish, stall, or appear from nowhere
- Plugin risk: closed or abandoned plugins on WordPress.org, and plugins whose listed owner changed
- Optional vulnerability lookup: when you enable it, active plugin versions are checked against public WPVulnerability data (off by default)
One-checkbox catastrophes
The quiet business killers that no scanner reports, because technically nothing is "hacked":
- Search engine visibility switched off
- Site email failing to send
- No administrators left on the site
- Invalid or unreachable admin email
Opt-in hardening, with receipts
A small set of hardening toggles, every one of them
off until you turn it on, and
every one reversible from Karetaker → Protection. Each toggle shows
Desired next to
Live now, so you always see what is actually in effect rather than what was merely
requested.
How it reaches you
- Visibility is pull: the Karetaker admin screen and WP-CLI
- Notification is push: email to the site owner, on ACT-severity events only
- Optional Slack / Telegram / Discord / Microsoft Teams: webhooks or Bot API, off until you turn them on
- Optional weekly summary: one short email on Monday mornings, off until you turn it on
- Pause alerts for an hour while you work on the site; one catch-up email afterwards if something needed you
- Your data, your file: download the activity log as CSV at any time
- Hardening is off until each toggle is switched on
Who it is for
- Site owners who want to know their site is fine without reading a dashboard every morning
- Freelancers and agencies handing a site over to a client, who still need to know if something breaks later
It is deliberately not
- A WAF or request firewall
- A malware signature scanner
- A login lockout or hide-login product by default
- A writer of
wp-config.php, .htaccess, or server config
Kill switch
Define
KARETAKER_DISABLE as true in
wp-config.php, or place an empty file at
wp-content/karetaker-disable. The plugin then boots nothing. Uninstall removes the
plugin's table, options, and scheduled hooks.
Open source
Karetaker is GPL, built by
Team Krikir. It does not phone
home, load third-party scripts, or show ads. Issues and pull requests are welcome.
Credits
Karetaker ships no third-party code, fonts or images. It relies on these projects and services,
and thanks them:
WordPress is a registered trademark of the WordPress Foundation. Microsoft and Microsoft Teams
are trademarks of the Microsoft group of companies. Slack is a trademark of Slack Technologies, LLC.
Discord is a trademark of Discord Inc.
Google and Googlebot are trademarks of Google LLC. Telegram and all other trademarks are the property of their
respective owners. Karetaker is an independent project by Team Krikir. It is not created,
endorsed, sponsored or certified by any of these companies; their names are used only to
describe the services Karetaker can connect to.
1.1.2
- An .htaccess or .user.ini under uploads whose rules only restrict, like the one plugins write to protect their own upload folders, is no longer reported as a problem.
- Fixed a repeating alert: marking a changed uploads config as expected did not update the baseline, so the same file was reported again on the next scan.
- A scan that ran out of time no longer replaces the baseline with the part of the folder it reached, which made untouched files look new.
- A file rewritten with the same contents is no longer treated as a change.
- Config files under uploads are no longer reported a second time as executable code.
- The setup screen now sits in the middle of the page.
1.1.1
- Developer: filters for the navigation label and the footer version text, so add-ons can name their screens.
1.1.0
- Advanced mode is gone. Agency tools (issue tracking with owners, detailed monitoring, incident cases, client reports, role access and the read-only API) are no longer part of Karetaker.
- Settings now holds the vulnerability lookup switch, how many events to keep, trusted proxies, a test alert button and email previews.
- Protection has "Sign out all administrators" for when you think someone else is logged in.
- Activity has a Download CSV button.
- Developer: new filters karetaker_settings_defaults and karetaker_admin_setting.
1.0.2
- Developer: an extension API (actions, filters and a JavaScript bridge) so add-ons can extend Karetaker without editing it.
- Tidier stylesheet comments.
1.0.1
- New email design for alerts, the weekly summary, the pause summary and test emails, matching the admin screens.
- Clearer subjects that lead with the status and name the site, for example "Act now: A must-use plugin file changed · example.com".
- Every email now has a readable plain-text version and a readable technical details table instead of raw data.
- The logo no longer breaks in email clients or when SMTP plugins are active.
- Summaries group repeated events into one line with a count.
- Preview any email from Advanced mode → Incidents → Alert routing.
1.0.0
First public release.
- Sixty-second setup: where to send alerts, what kind of site this is, a first check, and three safe protections.
- Home: plain-language status, a to-do card for anything that needs you, and the twelve checks Karetaker runs.
- Watches: critical files, WordPress core and plugin files against official checksums, administrators (including accounts hidden from the Users screen), plugin risk signals from WordPress.org, must-use plugins, the uploads folder, scheduled tasks, option names, external script domains, what search engines see, failed logins, search visibility and email delivery.
- Activity: everything Karetaker recorded, kept in your own database.
- Protection: seven optional protections that cannot lock you out. Karetaker never edits wp-config.php or .htaccess.
- Alerts by email, and optionally Telegram, Slack, Discord, Microsoft Teams or your own webhook, with a weekly summary and a one-hour pause while you work.
- Advanced mode for agencies and developers: issue tracking with owners, detailed monitoring, incident cases with a response checklist, client reports, CSV/JSON/ZIP exports, role permissions and read-only API tokens.
- WP-CLI commands and an emergency off switch.