

Dashboard — aggregate score, last scan status, known vulnerabilities, 24-hour brute-force block count.
InTouch Integrity Guard is not a malware scanner and does not try to be one. It does a few focused things, all designed to run in the background without adding weight to a single front-end page load:
InTouch Integrity Guard deliberately does not include a heuristic malware/YARA scanner, an always-on web application firewall, or automatic malware removal. If you need those, this is not the right tool — InTouch Integrity Guard is the lightweight layer that watches for unauthorized file changes and closes the easy doors, not a full security suite replacement.
SS_2FA_DISABLE constant is a site-wide escape hatchok tracked file (modified, missing or unrecognized) with a paginated view, a read-only file content viewer, a direct link to the official plugin/theme/core source for comparison, and a CSV export for checking the list with external toolsAlways active (core functionality):
Opt-in, disabled by default:
WPVulnerability API — used only to check your installed core, active plugins and active theme against a database of known vulnerabilities, and to email the site admin if a match is found.
https://www.wpvulnerability.net/ — the public, key-less REST API. The service (API and policies alike) is operated by ROBOTSTXT (Barcelona, Spain); its policy pages are published on the company site wpvulnerability.com / robotstxt.es and cover this same API.core, plugin or theme), the slug and the installed version number of each active component. No site URL, domain, IP address, admin email or other identifying data is sent, and no account or API key is required. Responses are cached locally for 12 hours.ipinfo.io — used only to look up the country of an IP address that brute-force login protection has actually blocked, shown on the Blocked IPs screen.
https://api.ipinfo.io/lite/ (the “IPinfo Lite” country/ASN lookup).