Overview
Bantion is my own website security monitoring project. It gives website owners, freelancers and agencies one place to track suspicious files, WordPress components and agent health across the sites they manage.
The goal is to replace repeated manual checks with a clear view of which website needs attention and why.
The problem
When managing multiple websites, information becomes scattered across hosting accounts, WordPress administration screens and separate tools. Checking versions, suspicious files and scan progress means repeated logins and manual work.
Bantion brings that information into a shared interface while keeping each finding connected to its domain.
The solution
Each monitored website uses a lightweight PHP agent. The user generates it in the app, uploads it to their hosting via SFTP and enters its public URL. Installation requires no SSH access or application framework integration.
- A shared overview: domains, connected agents and scan progress on one screen.
- File scanning: detection of suspicious PHP patterns and known malware indicators.
- WordPress inventory: core, plugin and theme information for detected installations.
- Security alerts: the affected path, detection reason, severity and resolution status.
The agent also works on PHP websites without WordPress; WordPress installations provide additional component information.
My role
On Bantion, I combine product design with development of the frontend, backend and remote PHP agent. The project also includes a public landing page explaining the product and how to use it.
Technical implementation
The dashboard uses Vue and TypeScript, with Pinia for state management and Vue Router for navigation. The PHP backend handles the API, domain management, scheduled checks and scan results. TPsoft DBmodel and TPsoft APIlite support the data layer and API.
The PHP agent runs when contacted by the central system, rather than during normal visitor requests. Scans run in chunks that account for hosting time and memory limits. Communication uses HTTPS and HMAC request signatures; the agent verifies an RSA signature before installing an update.
Challenges
The project needs to work across different PHP hosting environments and scan files without long blocking requests. It also needs to clearly distinguish an unavailable agent, a scan in progress and a security finding that requires review.
The interface therefore shows connectivity, recent checks and scan progress alongside individual findings. Users can mark reviewed alerts as resolved.
The result
The result is a working web application that brings monitored domains, PHP agents and security findings into one workspace. The screenshots below show the actual application interface.
Bantion continues to evolve. SSL monitoring, DNS change detection and website uptime monitoring are listed as planned extensions on the product website.


