WP Guardian is a paid add-on for the WP Toolkit in Plesk.
It works on the Plesk Web Pro and Web Host editions.
WP Guardian keeps an eye on your WordPress sites, checking for weak settings, outdated plugins, and known vulnerabilities. When it finds something, it alerts you and offers a simple one-click fix. It also uses trusted intelligence like Patchstack to block threats early.
The virtual patching protects your site even when you cannot update straight away, and it does this with zero code changes. It is a straightforward way for new and experienced users to stay on top of WordPress security.
Log in to your Plesk Dashboard, go to WordPress Toolkit, select the desired domain from the list to open its panel, enable the Vulnerability Protection slider.

If you activate the Vulnerability Protection slider in Plesk WordPress Toolkit for the first time after purchasing a WP Guardian license, you'll most probably see this error message at the top of your screen:

The fix is simple, please have a look at the screenshots below:


Since the service plan is not "Custom", we can adjust the plan directly!
The change will apply to all the domains using the "WordPress-Plan" service plan!


Setting the value to 0 disables vulnerability protection for all WordPress sites under that service plan. (and causing the activation error above)
Setting it to a specific number or Unlimited allows that many (or all) WordPress installations on subscriptions using the plan to use WP Guardian.
If the subscription uses a "Custom" plan, or if you only want to enable WP Guardian for one subscription:



Switch back to Power User view. (if needed)
The Vulnerability Protection slider in WordPress Toolkit will now activate successfully