Hello everyone,
At Ldesign Media, we’ve been developing Moodle plugins and supporting Moodle sites for more than 16 years. A recurring problem we see is clients coming to us with outdated installations, insecure settings or plugins with known vulnerabilities, often without realising their site is at risk. With AI increasingly being used to support penetration testing and vulnerability discovery, keeping track of security findings and acting on them is becoming even more important. Getting a site secure is only the beginning; keeping it that way requires ongoing attention and monitoring.
Getting a site into good shape is only the first step. Keeping it that way takes ongoing attention. Updates get missed, configurations change and new vulnerabilities affect components that were previously considered safe. Without a clear overview, it’s easy to lose track of what needs attention, especially when managing multiple sites.
That experience led us to build GuardLMS platform, and we’ve now published a local Moodle plugin that connects your site to the service.
What does it do?
The plugin sends a daily inventory of your Moodle version, installed plugins, available updates and server environment to GuardLMS. This helps you keep track of:
-
Known vulnerabilities: GuardLMS checks Moodle core and installed plugin versions against known CVEs through NVD integration.
-
Available updates: Update information comes from Moodle’s own update checker, with alerts when components fall behind.
-
JavaScript errors: Optional real-time monitoring reports browser errors with stack traces and technical context, helping you investigate broken pages without waiting for someone to report them.
-
Security configuration: An optional review checks a defined set of security and session settings, such as cookie flags, password policies and account lockout settings, against hardening best practices.
The aim is to make ongoing maintenance easier: a clearer view of what needs attention across your sites, with less manual checking.
Beyond the Moodle plugin
The plugin is one part of the wider GuardLMS platform. GuardLMS also monitors uptime, SSL/TLS certificates, DNS changes, email security, security headers and performance, bringing these checks together with vulnerability alerts and error reports in one dashboard.
It supports multiple web platforms, so you can monitor your Moodle environment alongside other sites you manage. For agencies and IT teams, this provides an overview across clients and environments, with health scores and automated reports to help prioritise maintenance and share findings.
Getting started
Install the plugin, open its settings and click Connect to GuardLMS. Log in or create an account, then confirm the connection. The daily inventory runs through Moodle cron. The plugin’s settings page shows the connection status, last inventory push and key expiry, so you can check that the site is still reporting.
The plugin supports Moodle 3.9-5.2. It connects to the external GuardLMS service, and a free account is enough to get started. Available features depend on your GuardLMS plan.
Links
We’d welcome feedback from other Moodle administrators and developers. How do you currently keep track of vulnerable plugins and missed updates across your sites? What would make this more useful in your day-to-day work?
Questions and feedback are welcome here. You can also report bugs or suggest improvements through the GitHub issue tracker.
Thanks,
Luuk Verhoeven - Ldesign Media / GuardLMS




