We watch your WordPress sites and tell you the moment something changes
Sentinel is the WordPress security monitoring built into WPCentrify. It watches every site you manage continuously, the files, the plugins, the certificates, the settings and who is signing in, and surfaces only what changed and what needs deciding. One list, across the whole portfolio, sorted by what matters. You find out the same day, not when the client calls.
Watches from inside each site · findings appear the same day · built for portfolios

You cannot log into forty WordPress sites every morning
Anyone running a portfolio of WordPress sites knows the feeling. Dozens of client sites, each one a target, and no realistic way to open every dashboard before coffee to check that nothing moved overnight. Every WordPress site on the internet is attacked constantly, so a raw feed of security events is worse than useless: it buries the one thing that matters under thousands of things that do not.
The plugin that gets you breached looks exactly like the plugin you installed. A backdoor hidden in the right place looks like ordinary code. A brand-new administrator account looks like a colleague. The whole job of WordPress security monitoring is separating the ordinary from the dangerous across many sites at once, quickly, without a person reading everything. That is what Sentinel is built to do.
What usually goes wrong
- A tool that emails a security report per site, so nobody reads any of them
- A green tick that means "we did not look", shown as if it meant "nothing found"
- A withdrawn plugin across nine sites shown as nine separate rows to work through
- Finding out a password was guessed when the client phones, not when it happened
Four kinds of change, watched from inside every site
Sentinel installs a connector plugin on each WordPress site, so it reports what is actually installed and what the files actually contain, not what an external scanner can guess from outside. Here is what it keeps an eye on.
File and code integrity
Sentinel watches your WordPress core and plugin files and tells you the moment any of them have been changed, removed or added since they were installed. It also finds runnable code hiding in places nothing executable belongs, such as your media library.
- Spots changes to your WordPress core files
- One-click repair of changed core files
- Spots plugin files that have been tampered with
- Finds runnable code hiding where it should not be
Sign-in monitoring
Sentinel keeps a full record of who signs in to every site you manage, from where and when. It knows when a sign-in comes from somewhere an account does not normally use, and it turns a stream of failed attempts into a clear picture of what is happening rather than a raw count.
- Alerts when an account signs in from somewhere unusual
- A clear record of failed sign-in attempts
- Tells you whether it is random noise or a targeted account
- Flags large-scale attacks from many sources
Administrator monitoring
A brand-new account that already holds administrator is the most common way a compromise survives a clean-up, so Sentinel raises it as critical and emails immediately. It words a long-standing account that has only now been promoted differently, records administrators that appeared and then removed themselves, and warns about dormant admin accounts nobody uses.
- New administrator alerts, raised as critical
- Promoted-account alerts, worded for what they are
- Disappearing administrators kept on the record
- Dormant administrator warnings
Active protection: the upload shield
Everything above watches. This part refuses. The upload shield is a per-site switch that blocks risky file uploads from landing where they could do harm, and it catches files disguised to look harmless. It never blocks legitimate work: installing plugins and themes through WordPress still works normally.
- Blocks risky file uploads where they do not belong
- Catches files disguised to look harmless
- Shown as protected only when the site confirms it is working
- Tells you honestly when cover is only partial
Grouped by problem, and split into things to do and things to know
Most WordPress security tools show you a wall of events per site. Sentinel does two things differently, and both exist to keep the to-do list short enough to actually finish.
One row per problem, not one per site. A plugin withdrawn from the WordPress directory across nine client sites is one decision, not nine. Sentinel groups it into a single row that expands to the nine sites when you want the detail. Competitors show you nine rows and leave you to notice they are the same thing.
Two queues: Findings and Warnings. Findings are things that need an answer, a to-do list where every row ends when somebody does something. Warnings are standing conditions nobody can switch off, such as an ongoing attack on a login form: worth knowing, never a task. Keeping that noise out of the to-do list is what keeps the to-do list finishable. And when a check could not run, Sentinel says so, rather than showing a green tick. "Nothing found" and "we did not look" are never shown as the same thing.
Anything can be accepted as a known risk with a written note. It stops shouting but stays on the record, and the note explains the decision to whoever reads it in six months. Every acceptance is logged with who and when.

The difference between "somebody is trying" and "somebody is in"
Every login form on the internet gets guessed at all day, and on its own that is noise. The signal that matters is the moment it works. When an address that had been failing to sign in then succeeds, Sentinel raises it as a critical finding and emails immediately. That is what a guessed password looks like, and it is the difference between an attack you can ignore and an account you have already lost.
The alert reaches the right people at once: the workspace owner, anyone trusted with the security area, and the person whose WordPress account it actually was, matched by email address. They are the only one who can change that password in the next ten minutes. Sentinel does not block brute-force attempts, because two-factor authentication is what makes them pointless. What it does is tell you the moment one succeeds, and show you exactly who is attacking and how.


New plugins, hidden components and folders that should not be there
Anything installed on a WordPress site that was not there before is raised for confirmation. That includes the hidden places malicious code likes to load from, and anything sitting in your plugins area that WordPress does not recognise as a real plugin at all.
Each arrival is answered once as expected, unauthorised or malicious, and you can act on it without logging into the site. You can switch off or remove a component straight from the dashboard. Because that still works even when a site is down with a fatal error on every page, it is a genuine recovery tool, not just a convenience. Sentinel also flags withdrawn and abandoned plugins, components pulled from the WordPress directory or no longer maintained.
Everything Sentinel checks, in one place
A complete inventory of the WordPress security monitoring Sentinel performs across your portfolio.
File and code integrity
- Changes to WordPress core files
- One-click core file repair
- Tampered plugin files
- Runnable code where it does not belong
Plugins installed
- New plugin detection
- Hidden components in unusual places
- Unrecognised items in your plugins area
- Confirm, flag, deactivate or remove
- Withdrawn and abandoned plugin alerts
Sign-in monitoring
- Full sign-in record, filterable
- Location on every sign-in
- Unusual-location alerts
- A clear picture of failed attempts
- Large-scale attack alerts
- Guessed-password alerts, raised as critical
Administrator monitoring
- New administrator alerts
- Promoted-account alerts
- Disappearances kept on the record
- Dormant administrator warnings
Certificates and domains
- SSL certificate expiring soon
- SSL certificate already expired
- SSL certificate invalid or misconfigured
- Domain registration expiring soon
Configuration and hardening
- Missing security headers
- PHP version out of support
- WordPress version out of support
- Code editing enabled in the admin area
- XML-RPC reachable
- Directory listing enabled
- Open registration into a powerful role
The Sentinel area, and where security shows up across the product
Sentinel lives in its own area with a small number of tabs, and threads through the rest of WPCentrify so security is never a separate silo.
Things that need an answer. A to-do list where every row ends when somebody does something.
Standing conditions nobody can switch off, such as an ongoing attack on a login form. Worth knowing, never a task.
The full record, with a switch between successful sign-ins and failed attempts, filterable by client, account and time.
Shown as coming soon so you can see the direction of travel. Not part of Sentinel today.
Security where you are already working
- A sidebar badge with a live count of things needing attention, counting only actionable items so it never carries a number nobody can clear
- A per-site Security tab with everything Sentinel knows about one website, including the upload shield toggle, on that site's own page
- A weekly summary email on Monday morning, with ongoing attacks summarised in one line rather than one row per site
- Immediate alert emails, sent only for things that mean somebody may already be in, so the urgent ones stay worth opening

Sentinel is part of the plan, not a separate product
Sentinel is included with WPCentrify's team plans rather than sold on its own. WordPress core file repair and the weekly summary email are available on the higher tiers. The entry plan for a single operator does not include Sentinel. Plan prices are announced at launch; the pricing page explains what is included, and early access is free while we build.
Two policies are worth stating plainly, because they are real trust signals rather than fine print.
- Critical findings are never withheld from anybody. Even where a plan is configured to delay routine findings, anything critical still reaches you immediately.
- Nothing is ever missed. Where routine findings are delayed, only reading the detail waits. The moment somebody upgrades, they see everything already found rather than starting a fresh watch.
- Fine-grained permissions. Team members can be given view-only access to Sentinel, or the ability to act on it. Anyone without the grant never sees the controls.
Requirements, and what Sentinel does not claim
- Sentinel needs the free WPCentrify connector plugin on each site. It has no dependencies and works on PHP 7.4 and up.
- Sites check in every few minutes and findings appear the same day. Sentinel reports on a cycle, so it is within minutes rather than real time.
- When a site is on an older connector version, the dashboard says so plainly rather than showing an empty result.
- Sentinel is not a firewall and does not sit in front of traffic.
- It is not a signature-based malware scanner. It finds files that changed and code where it should not be, rather than matching a virus database.
- It does not do backups or restore. Only core WordPress files can be restored. For backups, see backups and restore.
- Known-vulnerability matching against a CVE database is a future addition. Withdrawn and abandoned plugins are flagged today.
Works with the rest of WPCentrify
Questions about Sentinel
WordPress security monitoring, explained without overstatement.
Sentinel is the WordPress security monitoring layer inside WPCentrify. It watches every WordPress site you manage from the inside, using a connector plugin, and reports the few things that need a person: changed core and plugin files, new or promoted administrators, sign-ins from unusual locations, a login password that has been guessed, expiring certificates and weak settings. It is detection and alerting, plus one specific upload block, not a firewall, and it surfaces one list across the whole portfolio grouped by problem.
No. Sentinel is not a firewall and does not sit in front of traffic, and it is not a signature-based malware scanner. Instead of matching a virus database, it watches your WordPress core and plugin files and reports anything modified, missing or added, and it finds executable code in places it should not be, such as the media library. It also blocks executable file uploads on sites where you turn the upload shield on.
Sentinel keeps a record of every sign-in to every managed WordPress site, and knows when one comes from somewhere an account does not normally use. When repeated failed attempts are followed by a success, Sentinel raises it as a critical finding and emails immediately, because that is what a guessed password looks like. It shows you who is attacking and tells you the moment one gets in. It does not block brute-force attempts; two-factor authentication is what makes them pointless.
Sites check in every few minutes and findings appear the same day. Sentinel is not real time; sites report on a cycle rather than instantly. Critical items that mean somebody may already be in, such as a guessed password or a brand-new administrator, trigger an immediate alert email.
Sentinel needs the free WPCentrify connector plugin installed on each WordPress site. It has no dependencies and works on PHP 7.4 and up. The connector reports what is actually installed and what the files actually contain, rather than what an external scanner can guess from outside. When a site is on an older connector version, the dashboard says so plainly rather than showing an empty result.
Sentinel is part of the WPCentrify plan rather than a separate product. It is included on the team plans, with core WordPress file repair and the weekly summary email on the higher tiers. Critical findings are never withheld from anybody: even where routine findings are delayed on a lower tier, anything critical still reaches you immediately. See the pricing page for what is included.
Find out the same day, not when the client calls
Connect your sites during early access and let Sentinel watch them. You will see what changed, who signed in and what needs deciding, across the whole portfolio, in one list.
Free during early access. No credit card required.