See security risk across every client site, ranked by what it would actually cost you
Site-by-site security scanning tells you each site's problems. Portfolio security tells you that one plugin creates the same exposure across eleven clients, three of which take payments.
Free during early access. No credit card required.
Per-site scanning does not scale to a portfolio
Security tooling in WordPress is overwhelmingly built for a single site. Install a scanner, it tells you what is wrong with that site, and you fix it. Multiply that by forty sites and the model breaks down, not because the scanning is wrong but because the output is unusable.
Forty separate lists of findings, each ranked within its own site, gives you no way to answer the question that actually matters: what should the team do first this morning. A critical vulnerability on a staging copy outranks a medium one on a payment-taking store, purely because each site was assessed in isolation.
The second problem is that portfolio patterns are invisible. When the same widely-used plugin has a critical disclosure, an agency needs to know immediately how many client sites run it, which of those are ecommerce, and whether any are already exposed. Site-by-site scanning makes that a manual audit at exactly the moment you have no time for one.
Questions portfolio security answers
- Which vulnerability affects the most client sites right now
- Which affected sites take payments or hold personal data
- How long has each exposure window been open
- Which sites are running end-of-life PHP or WordPress versions
- Which certificates expire in the next thirty days
- Which sites have administrator accounts that should have been removed
Detection, prioritisation, then safe patching
Finding the vulnerability is the easy part. The value is in ranking it correctly and then patching quickly without breaking anything.
Continuous inventory
Every connected site reports its WordPress version, plugins, themes, PHP version and certificate status. That inventory is the basis for everything else, and it updates as sites change rather than on a scan schedule.
Matched against disclosures
The inventory is matched against known vulnerability data continuously. When a disclosure lands for a component you run anywhere in the portfolio, you know within minutes rather than at the next scheduled scan.
Ranked by real exposure
Severity is combined with how many sites are affected, whether those sites take payments or hold personal data, whether the vulnerability is remotely exploitable without authentication, and how long the window has been open.
Patched safely at speed
Security patches run through the same safe-update workflow as everything else: restore point, patch, verification, automatic rollback on failure. Patching fast and patching carefully stop being a trade-off.
What is monitored
Plugin and theme vulnerabilities
Continuous matching of your live inventory against known disclosures, across every connected site.
Core and PHP versions
Which sites are behind on WordPress core or running end-of-life PHP, before your host forces the upgrade.
SSL certificates
Expiry tracked across the portfolio with enough notice to act, including on callback and webhook subdomains.
Administrator accounts
Unexpected administrators and recently elevated roles surfaced across every site at once.
File integrity
Core files that differ from the official release, which should never happen and usually means trouble.
Evidence for clients
A record of what was found, when it was patched and how long the exposure lasted, ready for the monthly report.
Speed of patching is the metric that matters
Almost every WordPress compromise an agency deals with involves a component with a published vulnerability and an available patch. The attack was not sophisticated. The patching was slow. That is uncomfortable to hear and genuinely good news, because it means the problem is operational rather than technical.
The gap between a patch being published and applied across a portfolio is therefore the single most useful security metric an agency can track. Reducing it from weeks to hours removes most of the practical risk, and it is achievable without any new security product.
What usually prevents it is fear of breaking something. An agency that has been burned by a bad update reasonably becomes cautious, and caution translates into delay. This is why safe updates and portfolio security are the same problem: once every patch carries a restore point and automatic rollback, patching quickly stops being the risky option and becomes the safe one.
Signals your patch cycle is too slow
- You cannot say how long a known vulnerability has been open on client sites
- Security updates wait for the monthly maintenance window
- Patching is delayed because a previous update broke something
- You find out about disclosures from the news rather than your tooling
- Nobody owns the decision about when a patch is urgent enough to break the schedule
Related capabilities
Questions about portfolio security
No, and it is not trying to. Firewalls and malware scanners running on the site do a different job. This is the portfolio layer above them: knowing what you run everywhere, what is vulnerable, what matters most, and how quickly it gets patched. Both layers are worth having.
Detection is continuous rather than on a scan schedule, so when a disclosure lands for a component in your inventory you are notified within minutes. Whether it gets patched within minutes is up to your policy, and for critical unauthenticated issues it should be.
That is exactly why security patching runs through the safe-update workflow. A restore point is taken, the patch applied, the site verified, and if verification fails the site is rolled back automatically and you are told. The failure mode is a delayed patch, not a broken client site.
Yes. Every detection, patch and exposure window is recorded and exportable, which is what you need when a client asks how long a known issue was open on their site.
Partially. PHP version, SSL configuration and certificate validity are checked. Server hardening, firewall configuration and network-level protection sit with your host and are outside what a site connector can see.
Patch what matters first
Portfolio-wide vulnerability detection ranked by real exposure, with safe patching so speed does not mean risk.
Free during early access. No credit card required.