Aegisify company logo

How does Scan Metadata (Type, File Count, Suspect Count) work in Aegisify Shield Security, and what should administrators verify?

Technical summary

How does Scan Metadata (Type, File Count, Suspect Count) work in Aegisify Shield Security, and what should administrators verify? protects authentication and account-lifecycle flows through rate limits, unknown-username handling, registration defenses, administrator controls, lockouts, and recovery-aware enforcement. This article is grounded in the supplied Aegisify Shield Security 7.4.5 plugin package. It documents current behavior and defaults rather than relying on older FAQ wording.

Where administrators configure or verify it

Primary wp-admin path: wp-admin → Aegisify Shield → Hardening / Configurations. Exact controls can be distributed across the related tab/page when the feature is composed of multiple engines.

Current 7.4.5 defaults and related controls

The table below lists settings in the supplied current source that are directly related to this topic. The current default/bound/status shown is code-derived. Where the product does not define a named Medium preset, the shipped default is documented as the baseline operating point rather than inventing a value.

Setting Current default / bound / status Why this default How to tune safely
file_integrity.auto_scan_frequency weekly “weekly” is the exact shipped value in the current version. It is preserved as the baseline because the plugin code defines it as the default rather than deriving it from the old FAQ text. Keep the shipped value unless a documented site requirement calls for a different mode or identifier. Validate the change in the feature’s logs/status view and roll back if behavior becomes less reliable.
file_integrity.scan_history_limit 10 “10” is the exact shipped value in the current version. It is preserved as the baseline because the plugin code defines it as the default rather than deriving it from the old FAQ text. Keep the shipped value unless a documented site requirement calls for a different mode or identifier. Validate the change in the feature’s logs/status view and roll back if behavior becomes less reliable.
file_integrity.scan_mode light “light” is the exact shipped value in the current version. It is preserved as the baseline because the plugin code defines it as the default rather than deriving it from the old FAQ text. Keep the shipped value unless a documented site requirement calls for a different mode or identifier. Validate the change in the feature’s logs/status view and roll back if behavior becomes less reliable.
malware.auto_scan yes Enabled in the shipped baseline as the product’s current safe operating choice for this control. ON activates the behavior; OFF removes that specific behavior. Use OFF only when the control is intentionally unnecessary, another trusted layer owns the function, or a compatibility investigation proves the control is involved. Re-enable after testing when protection is still required.
malware.scan_dirs ["plugins","themes"] “['plugins', 'themes']” is the exact shipped value in the current version. It is preserved as the baseline because the plugin code defines it as the default rather than deriving it from the old FAQ text. Keep the shipped value unless a documented site requirement calls for a different mode or identifier. Validate the change in the feature’s logs/status view and roll back if behavior becomes less reliable.
malware.scan_profile balanced “balanced” is the shipped baseline and is the closest current code-defined baseline/medium operating point. Use stricter behavior only after reviewing site-specific evidence. Treat the shipped value as the baseline/medium operating point. A stricter profile generally increases sensitivity and may increase false positives or workload; a more permissive profile generally reduces intervention but can allow more unwanted activity.
malware.allowlist_hashes [] Blank or empty by default because this value depends on the site, organization, route, identity source, recipient, API credential, or exception policy. Configure it only with verified site-specific data. Supply only validated site-specific values. Leaving it blank/empty means no custom value, exception, recipient, credential, route, or policy has been asserted by default.
malware.custom_directories [] Blank or empty by default because this value depends on the site, organization, route, identity source, recipient, API credential, or exception policy. Configure it only with verified site-specific data. Supply only validated site-specific values. Leaving it blank/empty means no custom value, exception, recipient, credential, route, or policy has been asserted by default.

Adjustment strategy

Change one control at a time, save it through the product UI, reproduce the legitimate and malicious/test flow, and review the product log/status surface. For enforcement controls, use Monitor/Observe first when normal behavior is uncertain; move to Block only after the signal is reliable. For thresholds, do not jump directly from the default to an extreme unless an active incident requires emergency containment and a recovery path exists.

Operational guidance

When a file alert appears, verify the path, change source, checksum/signature evidence, and recent deployment history before treating the change as malicious. Maintenance, cache, backup, and log files can create high-volume legitimate change patterns.

Technical keywords

Aegisify Shield Security, 7.4.5, count, file, metadata, scan, suspect, type, file_integrity, auto_scan_frequency, scan_history_limit, scan_mode, malware, auto_scan, scan_dirs, scan_profile

Source baseline

Verified package: Aegisify Shield Security 7.4.5. Primary source files: includes/configuration/class-as-configuration-schema.php; includes/modules/class-as-module-login-guard.php; includes/modules/login_guard/class-as-login-guard-user-protection.php; includes/admin_pages/hardening/class-as-page-hardening-tab-endpoint-protection.php; includes/modules/class-as-module-hardening.php; includes/admin_pages/class-as-page-db-tools.php. If a future plugin version changes these settings, support should re-read the installed version rather than carry these defaults forward automatically.

2025-12-13T22:35:28+00:00December 13th, 2025||

Find this article interesting, please share.