Security

A complete record of your
security posture.

Configuration drift is a silent threat. An admin role added here, a security setting changed there — small changes accumulate into significant vulnerabilities. BlockForge takes regular security snapshots of your WordPress configuration, tracking users, roles, permissions, and settings over time.

How configuration drift creates security gaps.

WordPress configurations change constantly — users are added, plugins adjust settings, permissions shift. Without a systematic way to track these changes, small deviations compound into serious security issues.

Configuration Drift

Small changes accumulate over time into significant security gaps. A debug mode left enabled, a file permission loosened temporarily, a security header removed during troubleshooting — each one widens your attack surface incrementally.

Unknown Privilege Escalation

Someone added an admin account two months ago — who authorized it? Without historical snapshots, there is no way to know when a user was added, who added them, or whether they should still have access.

No Audit Baseline

Without regular snapshots, you can't prove compliance or detect unauthorized changes. When a client asks "has anything changed since the last audit?" you need evidence, not guesswork.

Snapshot, compare, detect drift — automatically.

BlockForge periodically captures a complete snapshot of your WordPress configuration — users, roles, permissions, active plugins, theme settings, security-relevant options, and database configuration. Each snapshot is compared against the previous one, and any changes are highlighted in a clear side-by-side diff view. Drift detection alerts notify you when security-critical settings change unexpectedly.

  • Automated configuration recording
  • User and role tracking
  • Permission change detection
  • Side-by-side comparison views
  • Scheduled snapshot frequency
  • Drift detection alerts

Snapshot Comparison

5 CHANGES

March 2, 2026

March 9, 2026

User Added Alert

-

temp_admin

Administrator

Plugin Activated

Inactive

debug-bar

Active

Setting Changed

WP_DEBUG

false

WP_DEBUG

true

Unchanged

users_can_register

disabled

users_can_register

disabled

Weekly snapshot comparison 5 changes · 1 alert · 42 stable

Key capabilities.

Full configuration lifecycle management — from automated snapshots to drift detection and compliance reporting across all your WordPress installations.

Configuration Recording

Captures a complete snapshot of your WordPress configuration — wp-config.php settings, database options, .htaccess rules, active plugins, theme settings, and security-relevant PHP configurations. Every detail is recorded.

User Tracking

Track every user account across all sites — when they were created, their roles, last login, and any privilege changes. Detect unauthorized admin accounts, dormant users, and unexpected role escalations automatically.

Permission Monitoring

Monitor file permissions, directory permissions, and WordPress capability assignments. Detect when permissions are loosened beyond safe defaults or when new capabilities are assigned to existing roles.

Comparison Views

Side-by-side snapshot comparison shows exactly what changed between any two points in time. Color-coded diffs make it easy to spot additions, modifications, and removals at a glance across all configuration areas.

Scheduled Snapshots

Configure snapshot frequency per site — daily, weekly, or after significant events like plugin updates. Snapshots are lightweight and stored efficiently, building a complete timeline of your security configuration history.

Drift Alerts

Automatic alerts when security-critical settings drift from their expected values. Define your security baseline once and get notified whenever a site deviates — whether it's a new admin user, a disabled security feature, or a changed permission.

Related security features.

Security snapshots complement vulnerability scanning, file integrity monitoring, and malware detection for a complete security strategy across all your WordPress sites.

Track every configuration change. Automatically.

Start monitoring your WordPress configuration today. Free plan includes 3 sites.