False positives
What to do when a finding looks wrong.
Integrity
- Theme or custom plugin edits flag as
baseline.changedafter the first scan — Accept if you made the change. - Premium plugins without WordPress.org checksums are baselined, not checksum-verified. Treat unexpected baseline diffs seriously.
- After updating Stalza Security itself, the plugin may silently refresh its own baseline for the new version.
Malware
Heuristic hits can fire on unusual but legitimate code (obfuscated loaders, ionCube, aggressive minifiers). Open the path, compare to a clean copy from the vendor, then Ignore or restore.
Vulnerabilities
Matches come from advisory data for the installed slug+version. If you already patched and still see a hit, refresh the match (Pro: hourly; Free: daily after opt-in) or confirm the version string WordPress reports.
Login Protection
Shared office IPs or reverse proxies can look like brute force. Add legitimate IPs to the allowlist and unlock from the Login tab (or via recovery steps in Locked out).