One view of every WordPress site your organisation owns
Marketing teams accumulate sites: campaign microsites, regional variants, product launches, acquired brands. Someone eventually has to keep all of them secure, current and online.
Free during early access. No credit card required.
Sites accumulate faster than anyone plans for
Almost no organisation decides to run thirty WordPress sites. They arrive one at a time: a campaign that needed its own domain, a regional team that built their own, a product launch, a brand acquired with its own web presence, an event site nobody switched off afterwards.
Each was someone's project and none of them are anyone's ongoing responsibility. Agencies who built them have moved on, credentials live in a shared document, and the person who knew how the German site was configured left eighteen months ago.
The failure is rarely dramatic. It is a slow drift: sites falling behind on updates, certificates expiring on properties nobody monitors, and a growing inability to answer basic questions about what the organisation actually runs.
Questions in-house teams need answered
- How many WordPress sites do we actually own
- Which are behind on security updates right now
- Which have backups, and have any been tested
- Who has administrator access, and should they
- Which certificates expire in the next month
- Which sites could be decommissioned entirely
From scattered sites to a managed estate
The sequence matters. Inventory first, then risk, then policy, then automation. Attempting to automate an estate you have not inventoried does not work.
Find everything
Build a complete list, including the sites nobody remembered. Domain registrar records, DNS zones, hosting accounts and expense reports each surface properties the official list is missing.
Assess risk
Connect what you find and get an immediate picture: WordPress and PHP versions, plugin vulnerabilities, backup status, certificate expiry and administrator accounts across the whole estate.
Decide what stays
Decommissioning is usually the highest-value outcome of a first audit. Every site retired is one that no longer needs patching, monitoring, hosting or attention.
Set policy and automate
Update schedules, backup frequency, approval requirements and access rules applied consistently rather than site by site. Routine maintenance stops depending on anyone remembering.
What in-house teams get
Estate inventory
A live, accurate list of every property with its versions, plugins, certificates and access, updated continuously.
Safe automated updates
Routine maintenance that runs itself, verifies the result, and rolls back rather than breaking a live brand site.
Role-based access
Regional teams scoped to their own sites, agencies scoped to the sites they work on, with access removable in one action.
Approval workflows
Required approval before changes to flagship properties, with requester and approver recorded.
Monitoring
Uptime, performance and certificate expiry across every property, including the ones nobody is watching.
Audit trail
Who changed what and when, which matters when an external agency has access to production.
Managing external agencies without handing over the keys
Most in-house teams work with external agencies, and access is usually handled badly: an administrator account is created, shared credentials end up in an email thread, and nobody revokes anything when the project ends. Years later, several agencies retain production access to properties they no longer work on.
Scoped access solves this cleanly. An agency gets access to the specific sites they work on, with the specific permissions their work requires, for as long as the engagement lasts. Revoking it is one action rather than an audit of every site.
The audit trail matters just as much. When an external party can change production, knowing exactly what they changed and when is the difference between a quick diagnosis and a long argument.
Access problems worth auditing today
- Agency accounts still active after the engagement ended
- Shared administrator credentials in documents or email
- Former employees with production access
- No record of who made a change or when
- No way to revoke access across all sites at once
Questions from in-house teams
Domain registrar records, DNS zones, hosting account inventories and expense reports each surface properties missing from the official list. Marketing campaign records and old project documentation usually add more. Expect the real number to exceed the assumed one.
Yes. Access is scoped by site or group, so a regional team sees and acts on only their properties while central IT retains estate-wide visibility and policy control.
Scoped access to the specific sites they work on, with the permissions their work requires, revocable in one action when the engagement ends. That is considerably safer than creating administrator accounts on individual sites and hoping someone remembers to remove them.
Yes. This is a management layer above hosting, not a replacement for it. Sites stay wherever they are hosted, across as many providers as you currently use.
Usually decommissioning. Most estates contain properties that serve no current purpose, and retiring them removes maintenance, monitoring, hosting cost and attack surface simultaneously. It is also the easiest change to get approved.
Find out what you actually run
Connect your estate and get an immediate picture of versions, vulnerabilities, backups, certificates and access across every property.
Free during early access. No credit card required.