Component Trust Monitor

Know what is installed. Know what deserves review.

Watchdog Security Suite PRO reviews installed WordPress plugins and themes for abandonment, suspicious file changes, repository trust signals and known vulnerabilities—without automatically disabling or deleting components.

Review-first supply-chain monitoring
Known vulnerability checks
Rescue Center integration

Supply-chain visibility

A plugin can be legitimate and still become an operational risk.

Components change over time. A once-trusted plugin may become abandoned, disappear from a repository, accumulate suspicious file changes or remain installed at a version affected by a disclosed vulnerability.

Installed plugin and theme inventory

Build a structured view of installed components, versions, activity state and update context before deciding what needs attention.

  • Plugins and themes reviewed together
  • Version and activation context
  • Readable component-level recommendations

Abandonment and maintenance signals

Highlight components that appear unmaintained or require a closer manual review without declaring every older plugin malicious.

  • Long maintenance gaps
  • Repository lookup and closure context
  • Update availability shown as information, not panic

Suspicious file and path changes

Identify warning signs such as unexpected PHP files, unusual paths or meaningful file changes inside installed component directories.

  • Unexpected executable files
  • Suspicious paths and package changes
  • High-risk findings can be sent to Rescue Center

Known Vulnerability Monitor

Compare installed WordPress core, plugin and theme versions with Watchdog’s locally cached vulnerability intelligence.

  • Manual and scheduled checks
  • Version-range matching
  • Critical and high findings can sync to Rescue Center
Trust Review

Explain why a component deserves attention.

Component Trust uses risk signals and recommendations rather than presenting a binary trusted/untrusted label that ignores context.

!
High-risk actionable finding
Unexpected executable changes or serious trust signals require prompt investigation.
High risk

?
Manual review recommended
Maintenance, source or metadata signals need administrator judgement.
Review

i
Informational context
An available update or private source is not automatically treated as dangerous.
Context

No urgent warning found
The latest scan did not identify a high-risk component change.
Monitoring

Known Vulnerabilities

Match installed versions against affected ranges.

The vulnerability monitor downloads a normalized feed into a local cache, checks installed versions and presents only relevant findings for the current website.

V
Local vulnerability feed cache
Feed data is cached locally and refreshed on a controlled schedule.
Local cache

Daily and post-update checks
Watchdog schedules checks daily and after relevant plugin, theme or core changes.
Scheduled

!
Severity and affected-version context
Findings identify the installed component, severity and affected version relationship.
Evidence

R
Optional Rescue Center sync
Critical and high findings can enter the review and recovery workflow.
Review first

Review-first workflow

Move from inventory to evidence before changing a live website.

Component Trust is intentionally non-destructive. It does not disable updates, quarantine plugins automatically or claim that every premium or custom component is unsafe.

Build the component inventory

Watchdog records installed plugins and themes, versions, source context and the current state.

Evaluate trust signals

Maintenance history, repository availability, file changes, paths and vulnerability evidence are reviewed.

Explain the recommendation

Each review item shows the warning signals and the practical next step instead of a vague alert.

Use Rescue Center when needed

High-risk evidence can move into quarantine, clean-source repair or rollback-aware recovery workflows.

Risk language

Not every component warning means compromise.

Watchdog separates urgent evidence from maintenance concerns and useful context so administrators can prioritise correctly.

Monitoring
No urgent trust warning was identified in the latest review.

Information
An update, custom source or other context is visible but not treated as proof of danger.

Review needed
Maintenance, repository or change signals deserve administrator attention.

High risk
Strong evidence requires prompt review and may justify a Rescue Center action.

Private and premium plugins are not automatically unsafe.
When a component cannot be verified against WordPress.org, Watchdog reports the limitation and recommends keeping a trusted ZIP or baseline for recovery.

Repository verification

Compare public packages with a known source.

For eligible WordPress.org plugins and themes, Watchdog can connect component findings with repository comparison and clean-source repair options in Rescue Center.

1
Identify the installed package
Match the component type, slug and installed version.
Package

2
Compare with the repository release
Look for changed, missing or unexpected files where a clean package is available.
Compare

3
Preserve a rollback path
Clean-source repair preserves the previous file before replacement and verifies the new copy.
Rollback

Rescue Center connection

Review, quarantine or repair with evidence attached.

Component Trust does not become a destructive button. It connects serious findings with Watchdog’s safer recovery tools.

Q
Quarantine unexpected files
Move high-confidence extra files to protected quarantine after review.
Quarantine

R
Repair from a clean source
Replace eligible changed files from the matching repository package.
Repair

Restore a rollback copy
Recover the preserved previous file when a repair needs to be reversed.
Restore

Understand component risk

Review plugins and themes with evidence before making destructive changes.

Watchdog Security Suite PRO combines component inventory, trust signals, known vulnerability monitoring and Rescue Center workflows inside one defensive WordPress security suite.