Product
Solutions
Compare
Resources
Get early access Talk to us
Sentinel · WordPress security monitoring

We watch your WordPress sites and tell you the moment something changes

Sentinel is the WordPress security monitoring built into WPCentrify. It watches every site you manage continuously, the files, the plugins, the certificates, the settings and who is signing in, and surfaces only what changed and what needs deciding. One list, across the whole portfolio, sorted by what matters. You find out the same day, not when the client calls.

Watches from inside each site · findings appear the same day · built for portfolios

app.wpcentrify.com/sentinel
The Sentinel Findings dashboard across managed WordPress sites, showing a critical finding where an address that had been failing to sign in then succeeded as a guessed password, alongside failed sign-in attempts and a needs-attention count
One list for the whole portfolio. Findings ranked by what actually needs a person, with a live count of what still needs an answer.
The problem

You cannot log into forty WordPress sites every morning

Anyone running a portfolio of WordPress sites knows the feeling. Dozens of client sites, each one a target, and no realistic way to open every dashboard before coffee to check that nothing moved overnight. Every WordPress site on the internet is attacked constantly, so a raw feed of security events is worse than useless: it buries the one thing that matters under thousands of things that do not.

The plugin that gets you breached looks exactly like the plugin you installed. A backdoor hidden in the right place looks like ordinary code. A brand-new administrator account looks like a colleague. The whole job of WordPress security monitoring is separating the ordinary from the dangerous across many sites at once, quickly, without a person reading everything. That is what Sentinel is built to do.

What usually goes wrong

  • A tool that emails a security report per site, so nobody reads any of them
  • A green tick that means "we did not look", shown as if it meant "nothing found"
  • A withdrawn plugin across nine sites shown as nine separate rows to work through
  • Finding out a password was guessed when the client phones, not when it happened
What Sentinel watches

Four kinds of change, watched from inside every site

Sentinel installs a connector plugin on each WordPress site, so it reports what is actually installed and what the files actually contain, not what an external scanner can guess from outside. Here is what it keeps an eye on.

File and code integrity

Sentinel watches your WordPress core and plugin files and tells you the moment any of them have been changed, removed or added since they were installed. It also finds runnable code hiding in places nothing executable belongs, such as your media library.

  • Spots changes to your WordPress core files
  • One-click repair of changed core files
  • Spots plugin files that have been tampered with
  • Finds runnable code hiding where it should not be

Sign-in monitoring

Sentinel keeps a full record of who signs in to every site you manage, from where and when. It knows when a sign-in comes from somewhere an account does not normally use, and it turns a stream of failed attempts into a clear picture of what is happening rather than a raw count.

  • Alerts when an account signs in from somewhere unusual
  • A clear record of failed sign-in attempts
  • Tells you whether it is random noise or a targeted account
  • Flags large-scale attacks from many sources

Administrator monitoring

A brand-new account that already holds administrator is the most common way a compromise survives a clean-up, so Sentinel raises it as critical and emails immediately. It words a long-standing account that has only now been promoted differently, records administrators that appeared and then removed themselves, and warns about dormant admin accounts nobody uses.

  • New administrator alerts, raised as critical
  • Promoted-account alerts, worded for what they are
  • Disappearing administrators kept on the record
  • Dormant administrator warnings

Active protection: the upload shield

Everything above watches. This part refuses. The upload shield is a per-site switch that blocks risky file uploads from landing where they could do harm, and it catches files disguised to look harmless. It never blocks legitimate work: installing plugins and themes through WordPress still works normally.

  • Blocks risky file uploads where they do not belong
  • Catches files disguised to look harmless
  • Shown as protected only when the site confirms it is working
  • Tells you honestly when cover is only partial
The difference

Grouped by problem, and split into things to do and things to know

Most WordPress security tools show you a wall of events per site. Sentinel does two things differently, and both exist to keep the to-do list short enough to actually finish.

One row per problem, not one per site. A plugin withdrawn from the WordPress directory across nine client sites is one decision, not nine. Sentinel groups it into a single row that expands to the nine sites when you want the detail. Competitors show you nine rows and leave you to notice they are the same thing.

Two queues: Findings and Warnings. Findings are things that need an answer, a to-do list where every row ends when somebody does something. Warnings are standing conditions nobody can switch off, such as an ongoing attack on a login form: worth knowing, never a task. Keeping that noise out of the to-do list is what keeps the to-do list finishable. And when a check could not run, Sentinel says so, rather than showing a green tick. "Nothing found" and "we did not look" are never shown as the same thing.

Anything can be accepted as a known risk with a written note. It stops shouting but stays on the record, and the note explains the decision to whoever reads it in six months. Every acceptance is logged with who and when.

Weekly summary email
The Sentinel weekly summary email listing open findings across several WordPress sites, grouped by problem with critical, high, medium and low severities, and a single row covering multiple affected sites
The Monday summary. The state of the whole portfolio in one email, ongoing attacks summarised in one line rather than one row per site.
The signature moment

The difference between "somebody is trying" and "somebody is in"

Every login form on the internet gets guessed at all day, and on its own that is noise. The signal that matters is the moment it works. When an address that had been failing to sign in then succeeds, Sentinel raises it as a critical finding and emails immediately. That is what a guessed password looks like, and it is the difference between an attack you can ignore and an account you have already lost.

The alert reaches the right people at once: the workspace owner, anyone trusted with the security area, and the person whose WordPress account it actually was, matched by email address. They are the only one who can change that password in the next ten minutes. Sentinel does not block brute-force attempts, because two-factor authentication is what makes them pointless. What it does is tell you the moment one succeeds, and show you exactly who is attacking and how.

A Sentinel alert email headed Was this you, telling the account owner that their WordPress account signed in from a different country than usual, with the account, time and location and a button to see every sign-in
Did you install this?
The Sentinel confirm dialog asking whether a plugin that appeared on a WordPress site was installed by the team, with three answers: yes we installed it, no but it looks harmless, or no this should not be here
Every arrival answered once. Expected, unauthorised, or malicious. Answers can be corrected later, and the note travels with the finding.
Watching what gets installed

New plugins, hidden components and folders that should not be there

Anything installed on a WordPress site that was not there before is raised for confirmation. That includes the hidden places malicious code likes to load from, and anything sitting in your plugins area that WordPress does not recognise as a real plugin at all.

Each arrival is answered once as expected, unauthorised or malicious, and you can act on it without logging into the site. You can switch off or remove a component straight from the dashboard. Because that still works even when a site is down with a fatal error on every page, it is a genuine recovery tool, not just a convenience. Sentinel also flags withdrawn and abandoned plugins, components pulled from the WordPress directory or no longer maintained.

The full list

Everything Sentinel checks, in one place

A complete inventory of the WordPress security monitoring Sentinel performs across your portfolio.

File and code integrity

  • Changes to WordPress core files
  • One-click core file repair
  • Tampered plugin files
  • Runnable code where it does not belong

Plugins installed

  • New plugin detection
  • Hidden components in unusual places
  • Unrecognised items in your plugins area
  • Confirm, flag, deactivate or remove
  • Withdrawn and abandoned plugin alerts

Sign-in monitoring

  • Full sign-in record, filterable
  • Location on every sign-in
  • Unusual-location alerts
  • A clear picture of failed attempts
  • Large-scale attack alerts
  • Guessed-password alerts, raised as critical

Administrator monitoring

  • New administrator alerts
  • Promoted-account alerts
  • Disappearances kept on the record
  • Dormant administrator warnings

Certificates and domains

  • SSL certificate expiring soon
  • SSL certificate already expired
  • SSL certificate invalid or misconfigured
  • Domain registration expiring soon

Configuration and hardening

  • Missing security headers
  • PHP version out of support
  • WordPress version out of support
  • Code editing enabled in the admin area
  • XML-RPC reachable
  • Directory listing enabled
  • Open registration into a powerful role
How it is presented

The Sentinel area, and where security shows up across the product

Sentinel lives in its own area with a small number of tabs, and threads through the rest of WPCentrify so security is never a separate silo.

Findings

Things that need an answer. A to-do list where every row ends when somebody does something.

Warnings

Standing conditions nobody can switch off, such as an ongoing attack on a login form. Worth knowing, never a task.

Sign-ins

The full record, with a switch between successful sign-ins and failed attempts, filterable by client, account and time.

Page health Soon

Shown as coming soon so you can see the direction of travel. Not part of Sentinel today.

Security where you are already working

  • A sidebar badge with a live count of things needing attention, counting only actionable items so it never carries a number nobody can clear
  • A per-site Security tab with everything Sentinel knows about one website, including the upload shield toggle, on that site's own page
  • A weekly summary email on Monday morning, with ongoing attacks summarised in one line rather than one row per site
  • Immediate alert emails, sent only for things that mean somebody may already be in, so the urgent ones stay worth opening
app.wpcentrify.com/team
The WPCentrify team page with the Sentinel item in the sidebar and per-member permission controls, showing that team members can be given view-only or act-on access to Sentinel
Fine-grained permissions. Team members can be given view-only access to Sentinel or the ability to act on it. Anyone without the grant never sees the controls at all.
Plans and access

Sentinel is part of the plan, not a separate product

Sentinel is included with WPCentrify's team plans rather than sold on its own. WordPress core file repair and the weekly summary email are available on the higher tiers. The entry plan for a single operator does not include Sentinel. Plan prices are announced at launch; the pricing page explains what is included, and early access is free while we build.

Two policies are worth stating plainly, because they are real trust signals rather than fine print.

  • Critical findings are never withheld from anybody. Even where a plan is configured to delay routine findings, anything critical still reaches you immediately.
  • Nothing is ever missed. Where routine findings are delayed, only reading the detail waits. The moment somebody upgrades, they see everything already found rather than starting a fresh watch.
  • Fine-grained permissions. Team members can be given view-only access to Sentinel, or the ability to act on it. Anyone without the grant never sees the controls.

Requirements, and what Sentinel does not claim

  • Sentinel needs the free WPCentrify connector plugin on each site. It has no dependencies and works on PHP 7.4 and up.
  • Sites check in every few minutes and findings appear the same day. Sentinel reports on a cycle, so it is within minutes rather than real time.
  • When a site is on an older connector version, the dashboard says so plainly rather than showing an empty result.
  • Sentinel is not a firewall and does not sit in front of traffic.
  • It is not a signature-based malware scanner. It finds files that changed and code where it should not be, rather than matching a virus database.
  • It does not do backups or restore. Only core WordPress files can be restored. For backups, see backups and restore.
  • Known-vulnerability matching against a CVE database is a future addition. Withdrawn and abandoned plugins are flagged today.
Answers

Questions about Sentinel

WordPress security monitoring, explained without overstatement.

Sentinel is the WordPress security monitoring layer inside WPCentrify. It watches every WordPress site you manage from the inside, using a connector plugin, and reports the few things that need a person: changed core and plugin files, new or promoted administrators, sign-ins from unusual locations, a login password that has been guessed, expiring certificates and weak settings. It is detection and alerting, plus one specific upload block, not a firewall, and it surfaces one list across the whole portfolio grouped by problem.

No. Sentinel is not a firewall and does not sit in front of traffic, and it is not a signature-based malware scanner. Instead of matching a virus database, it watches your WordPress core and plugin files and reports anything modified, missing or added, and it finds executable code in places it should not be, such as the media library. It also blocks executable file uploads on sites where you turn the upload shield on.

Sentinel keeps a record of every sign-in to every managed WordPress site, and knows when one comes from somewhere an account does not normally use. When repeated failed attempts are followed by a success, Sentinel raises it as a critical finding and emails immediately, because that is what a guessed password looks like. It shows you who is attacking and tells you the moment one gets in. It does not block brute-force attempts; two-factor authentication is what makes them pointless.

Sites check in every few minutes and findings appear the same day. Sentinel is not real time; sites report on a cycle rather than instantly. Critical items that mean somebody may already be in, such as a guessed password or a brand-new administrator, trigger an immediate alert email.

Sentinel needs the free WPCentrify connector plugin installed on each WordPress site. It has no dependencies and works on PHP 7.4 and up. The connector reports what is actually installed and what the files actually contain, rather than what an external scanner can guess from outside. When a site is on an older connector version, the dashboard says so plainly rather than showing an empty result.

Sentinel is part of the WPCentrify plan rather than a separate product. It is included on the team plans, with core WordPress file repair and the weekly summary email on the higher tiers. Critical findings are never withheld from anybody: even where routine findings are delayed on a lower tier, anything critical still reaches you immediately. See the pricing page for what is included.

Early access

Find out the same day, not when the client calls

Connect your sites during early access and let Sentinel watch them. You will see what changed, who signed in and what needs deciding, across the whole portfolio, in one list.

Free during early access. No credit card required.