Stalza

False positives

What to do when a finding looks wrong.

Integrity

  • Theme or custom plugin edits flag as baseline.changed after the first scan — Accept if you made the change.
  • Premium plugins without WordPress.org checksums are baselined, not checksum-verified. Treat unexpected baseline diffs seriously.
  • After updating Stalza Security itself, the plugin may silently refresh its own baseline for the new version.

Malware

Heuristic hits can fire on unusual but legitimate code (obfuscated loaders, ionCube, aggressive minifiers). Open the path, compare to a clean copy from the vendor, then Ignore or restore.

Vulnerabilities

Matches come from advisory data for the installed slug+version. If you already patched and still see a hit, refresh the match (Pro: hourly; Free: daily after opt-in) or confirm the version string WordPress reports.

Login Protection

Shared office IPs or reverse proxies can look like brute force. Add legitimate IPs to the allowlist and unlock from the Login tab (or via recovery steps in Locked out).