GARM is 100% PHP: it installs in two minutes on any hosting — managed, shared, VPS — with no shell access and no Python. It checks the integrity of core, plugins and themes against the official WordPress.org checksums: if the site was already infected, GARM sees it all the same.
Serious scanners require shell access — but 70% of WordPress hosting doesn’t have it. GARM covers exactly that space: pure PHP, integrity via official checksums, almost zero false positives.
It installs like any WordPress plugin, from the panel. No configuration after activation.
The plugin package, GPL-2.0. No dependencies to install.
In WP-admin: Plugins → Add new → Upload plugin, then Install and Activate.
The Garm menu appears. Go to Garm → Scan and click “Run scan now”.
GARM doesn’t scream. It quarantines the suspicious file, tells you exactly where it is and what it contains, and lets you decide the next step. No data leaves your server.
GARM Free is complete and free forever (GPL-2.0). Pro adds a managed feed and auto-remediation; the Third Sector rate is −40%.
GARM is the entry point. The WordPress line and the server line share the same AI and the same console.
Two minutes from the WordPress panel to know whether your site is clean. Open source, zero shell.
In 30 minutes: the monitors in real time, how the AI classifies an attack, and the timeline of a real automatic response.
We’ll write to you within the working day to set up the demo. Calmly, and with the numbers.