🦻 What is WebFreeze?
WebFreeze is a PRO feature that lives inside Security Scanner → WebFreeze tab (admin.php?page=seensecure-security-scanner&subtab=webfreeze). It is not a separate menu item: it's another tab in the Security Scanner, alongside Malware, Integrity/FIM, and Quarantine.
When you activate WebFreeze ("Freeze the site"), the system takes an exact snapshot of every protected file. From that moment on, any unauthorized modification, deletion, or new file among the protected set is automatically detected and reverted or removed within minutes, restoring the exact frozen state. Think of it as an automatic "undo" for your site's core files.
It's built for stable sites that shouldn't be changing at the file level: once your WordPress, plugins, themes, and configuration are the way you want them, you freeze the site and any unexpected change gets corrected on its own, without you having to watch for it.
⚙️ The Two Modes of WebFreeze
The "Mode" dropdown lets you choose how WebFreeze should behave when it detects a change:
❌ Keep Frozen
Actively reverts and removes any unauthorized change or file, restoring the site to its frozen state. This is the full-enforcement mode.
📝 Log Only
Detects and logs changes, but doesn't revert or delete anything. Useful for testing WebFreeze before switching to full enforcement, or for seeing what it would catch without risking a false positive.
🔥 Why WebFreeze Depends on the Firewall (WAF)
WebFreeze needs the WAF/Firewall to be active to be able to freeze. This is a hard dependency:
- If the WAF is completely off, WebFreeze cannot be activated at all.
- If the WAF is in Monitor / log-only mode (not actively blocking), WebFreeze automatically inherits that enforcement level and also switches to Log Only mode, even if you selected "Keep Frozen".
🔗 Relationship with FIM (File Integrity Monitoring)
WebFreeze shares the same real-time detection engine as the File Integrity Monitoring (FIM) system. When you activate WebFreeze, FIM's own real-time monitoring pauses automatically: there's no need for both to watch the same files at once, so WebFreeze takes over that watching role while it's active, and FIM picks it back up as soon as you unfreeze.
📁 What WebFreeze Protects
When you freeze the site, WebFreeze watches these file categories:
Executable code & templates
.php, .phtml, .phar, .inc, .html, .htm — WordPress core, all plugins, and all themes; in general, anything that executes server-side or is served as a page.
Client-side code & styles
.js, .css, .svg — JavaScript is protected because it's a common malware vector (skimmers, redirects, site hijacking), and SVG files are frozen too because they can embed scripts — they're not just inert images.
Critical configuration
.htaccess, web.config, .env, .user.ini, .json, .xml, .yml, .yaml, .ini, .po, .mo — server rules, secrets, and settings; if these files change, the site can break or become exposed.
Theme & plugin resource files
Images and fonts that belong to themes and plugins (.png, .jpg, .webp, .ico, .woff2, .ttf, etc.) — they're part of how the site functions; if damaged, restoring only the PHP files wouldn't be enough, so they're frozen too.
🚫 What WebFreeze Does NOT Protect (and why)
Database content
Posts, pages, comments, and users live in the database, not in files, so WebFreeze doesn't touch them. You can keep publishing and editing content normally while the site is frozen.
Uploads from admins and editors
Files you upload through the WordPress editor (wp-content/uploads) — images, PDFs, videos added via the editor — are deliberately left free, so you can keep uploading and deleting content without any blocking.
Caches and temporary files
Excluded so they don't trigger false alarms.
📋 Exclusions List
You can list specific folders or files, one path per line, that WebFreeze should never freeze. It accepts paths relative to the WordPress root, or absolute paths.
- A trailing slash (
/) excludes everything inside that folder. - A
**wildcard is supported for advanced cases.
This is meant for sites whose own code legitimately generates files dynamically in some folder (for example, a reports generator that writes .php or .js files). Anything that shows up outside the exclusions is treated as "unauthorized" and reverted or removed.
wp-config.php, .htaccess, or WordPress core unless you know exactly what you're doing.
📦 Quarantine Option
A checkbox lets you choose to send detected changed or deleted files to quarantine (keeping the filename, action taken, origin, and timestamp for forensic review) instead of deleting them outright. Recommended when you want to be able to inspect what happened afterward.
🚀 How to Deploy Legitimate Changes with WebFreeze Active
The correct workflow for updating plugins, deploying new code, or making any file-level change is:
- Unfreeze the site.
- Make your changes normally — while the site is unfrozen, nothing gets reverted.
- Re-freeze. Re-freezing captures the new state as the new "known good" baseline.
✅ Pending Approvals
Sometimes SeenSecure itself needs to modify a configuration file as part of its own operation. Those specific changes are not silently reverted like a normal unauthorized change: they appear in a "Pending Approvals" table where you review each one individually and decide to Approve (keep the change) or Reject (revert it).
🛡️ Manifest Tamper Protection
WebFreeze keeps its own internal manifest of the frozen state. If that manifest is detected as tampered with, WebFreeze automatically rebuilds it from a secure backup copy (the "vault") and shows a warning telling you to review the log, since this could indicate the server has been compromised.
🧱 Defense in Depth: Where WebFreeze Fits
WebFreeze is the last layer of a multi-stage protection system:
- WAF / Firewall: blocks malicious traffic before it reaches your site.
- Malware Scanner: detects malicious signatures and behavior in real time.
- Automatic Quarantine: isolates suspicious files before they can act.
- WebFreeze: instantly reverts and restores any unauthorized change.
📊 Dashboard, Verification & Notifications
The WebFreeze tab includes a stats dashboard:
Protected
Modified
Deleted
Unauthorized
Restored
Runs a manual, on-demand check without waiting for the next automatic cycle.
📧 Email Notifications
With a custom recipient field; if left blank, it defaults to the site admin's email.
🕐 Timestamps
Last verification and last restoration, both visible right on the panel.
WebFreeze has its own event log, specific to this feature, which you can refresh or clear whenever you want.
🔧 Troubleshooting
I can't activate WebFreeze
Check that the WAF/Firewall is active. If the WAF is completely off, WebFreeze cannot be activated under any circumstances — turn on General Firewall first, then come back to WebFreeze.
I turned on WebFreeze and I'm still getting FIM alerts
That's expected if the alert corresponds to changes detected before you froze the site: WebFreeze pauses FIM monitoring as soon as it's activated, but it doesn't clear out changes that were already pending review at that moment. Check the Integrity panel and approve or restore anything pending before freezing.
I updated a plugin and WebFreeze reverted it
If the site was still frozen while you updated, WebFreeze treated that update as an unauthorized change and reverted it. Always follow the workflow: unfreeze → update → re-freeze.
Frequently Asked Questions
Why can't I activate WebFreeze? Most likely the WAF/Firewall is off — WebFreeze cannot freeze without an active WAF. Also check that your PRO license is active, since this feature is PRO-only.
Will I lose my posts if something goes wrong? No. Database content (posts, pages, comments, users) is not something WebFreeze watches or reverts; it only acts on files.
How do I update a plugin with WebFreeze active? Unfreeze the site, apply the update normally, and re-freeze when you're done. That way WebFreeze captures the new state as the new baseline instead of reverting it.
Can I still upload images to my posts while the site is frozen? Yes. Files you upload through the WordPress editor (wp-content/uploads) are deliberately exempt, precisely so you can keep publishing without any blocking.
Do WebFreeze and FIM run at the same time? Not exactly: they share the same engine, but while WebFreeze is active, FIM's own real-time monitoring is paused. FIM picks its watching back up as soon as you unfreeze the site.
What's the difference between "Keep Frozen" and "Log Only"? "Keep Frozen" actively reverts and removes any unauthorized change; "Log Only" detects and records those changes in the log without touching any file. Useful for testing before enforcing.
Can I exclude my custom plugin's folder? Yes, add its path to the exclusions list (a trailing slash excludes everything inside it). Keep in mind that excluding folders with PHP code leaves that part without WebFreeze's protection.
What happens if someone tampers with WebFreeze's own manifest? WebFreeze detects it, automatically rebuilds the manifest from its secure backup copy (the "vault"), and shows a warning so you review the log — it could be a sign the server has been compromised.