Security monitoring
Watch header hardening, exposed-file and hijacking signals across your roster — and know what to do the moment one fires.
DeadWatch reads the security posture of every site: are the right headers set, is anything exposed that shouldn't be, and is the page being tampered with. It rolls up into a letter grade and surfaces individual events as they happen.

Read the hardening grade
- Go to Health & Hardening.
- Each site shows a Grade (A–F) and a Score, with WP Version status where WordPress monitoring is on.
- Filter by the Grade Distribution chips (A / B / C / D / F / Unknown) or by WP status to find the weakest sites first.
- Click Check All to queue a fresh pass across the roster.
You'll know it worked when… your roster trends toward A/B grades and no site sits at D/F.
If a site shows no hardening data, enable wordpress or headers monitoring on its Config tab.
Inspect one site's posture
- Open a site and go to the Security tab.
- Review:
- Security Headers and Missing Security Headers — what's set vs. what's absent
- Weak Configurations
- REST API Namespaces and Detected Extensions — the exposed surface
- Security Issues
- Hijacking Detection — redirect, cloaking, spam injection, and hidden-link signals
- The Security card in the Watch Tower (Overview) summarizes hardening %, missing-header count, and cloaking similarity.
Watch the integrity feed
Integrity Events is the cross-site stream of everything that fired in the last 7 days.
- Go to Integrity Events.
- Filter by pillar — DNS, TLS/SSL, WHOIS, WordPress, SEO, Keywords, Hijacking, Content, Assets, Links — and by status (Success / Warning / Error).
- Each row shows the site, the check type, the status, and details.
When a security signal fires
- See it early — add a Notifications rule for the security events:
hijacking.detected,forensics.threats_detected,forensics.integrity_failed,forensics.php_fatal, andforensics.updates_available. - Confirm it — open the site's Security tab and read the specific finding (which header is missing, what the hijacking detector saw). Automated checks are a strong signal, but verify a critical finding before acting.
- Act — set the missing header, remove the exposed file, or clean the injection; for a confirmed hijack, treat it as an incident (Convert to ticket from the incident) and rotate credentials.
- Re-check — click Check All on Health & Hardening (or Run all checks on the site) and confirm the grade recovers and the event clears.
You'll know it worked when… the finding drops off Integrity Events and the site's hardening grade climbs back up.
Next: Teams & client access → to give the right people the right view.