WP Umbrella Logo

WordPress Security Cost in 2026: What Agencies Actually Pay Per Site

Site Protect Pricing: What's the ROI for WordPress agencies managing 50–500 client sites? Hint - one security incident costs far more.

Medha Bhatt

If you manage 50 to 500 WordPress client sites, you have probably looked at WP Umbrella’s Security add-on (formerly Site Protect) and thought: “$2 per site. That adds up quickly.” It does. What that $2 is actually worth depends on one thing: what happens when a vulnerability hits your portfolio before a patch exists.

Virtual patching is the answer to that window. When a plugin vulnerability is disclosed, a firewall rule blocks the exploit at runtime, before the developer ships a fix and before your clients approve the update. The vulnerable code stays in place; the attack never lands.

The window is real. Per Patchstack’s State of WordPress Security in 2026 whitepaper, 11,334 new vulnerabilities were found in the WordPress ecosystem in 2025, a 42% increase over 2024, and 91% of them were in plugins. Worse: 46% did not receive a developer fix in time for public disclosure.

This article does the pricing work that vendor pages avoid: what WP Umbrella charges, what every credible alternative charges at 10, 50, 100, and 300 sites, and what agencies bill on top of a $2 line item.

How much does the WP Umbrella Security add-on cost?

The Security add-on costs $2 per site per month (2€). It sits on top of WP Umbrella’s base subscription: 1.99€ per site per month (displayed as $2.19 in USD on the pricing page), with all platform features included. No tiers, no feature locking, no seat charges. The add-on requires a paid plan; it is not sold standalone.

The base subscription already carries a security layer before you spend the extra $2: vulnerability monitoring refreshed every 6 hours with one-click fixing updates, Site Health security warnings, the platform activity log, and uptime plus PHP error monitoring. The add-on builds on that with three components: a Patchstack-powered firewall with virtual patching, per-site security hardening, and a security-driven activity log. More on each below.

Two pricing details matter more than the sticker.

First, the price is flat. Ten sites cost $20 per month, 300 sites cost $600 per month. No volume tiers to negotiate, no quote calls: care-plan costing is a multiplication, not a procurement exercise.

Second, it is per-site selective. You enable the add-on site by site, not account-wide. Protect the WooCommerce stores and the clients with SLAs; leave the dormant brochure sites on the base layer. The invoice follows the toggles.

More than 10,000 sites already run with the Security add-on enabled. You can see the full breakdown on the WordPress security feature page.

What does virtual patching cost across the market in 2026?

Most comparisons skip this: virtual patching almost always traces back to the same engine. Patchstack supplies the vulnerability intelligence behind several products below, including WP Umbrella’s own firewall. You are not choosing different protection; you are choosing packaging: bought direct, inside a security plugin, a hosting plan, or the platform that already runs your care plans. All prices verified July 2026.

Patchstack, bought direct. The Developer plan costs $69 per month billed annually, $828 per year, and protects up to 25 sites by default. Beyond that, capacity extends at $12.50 per month for each additional 5 sites; an Enterprise tier with custom pricing exists above it. Buying direct gets you the firewall and the feed. Updates, backups, monitoring, and client reporting still live somewhere else.

Wordfence Premium. $149 per year, per site, with volume discounts of up to 25%. It is a full security plugin with its own scanner and firewall, licensed per site, so the cost scales linearly with your portfolio.

Sucuri. The Basic Platform costs $229 per year, and each plan covers exactly one site; anything above 10 sites is quote-only. Credit where due: Sucuri includes malware cleanup, which almost nobody else in this table touches.

PerfGrid. A security add-on starting at €4 per month per website, also Patchstack-powered. The catch: it is available exclusively on PerfGrid’s hosting plans, so the real price includes moving your hosting.

Kadence bundles (Liquid Web). The former Solid Security line now lives inside the Kadence Pro ($299 per year) and Elite ($499 per year) bundles, whose security suite covers a firewall, 2FA, and Patchstack-powered virtual patching. The site allowance is not published, so an honest per-site figure is impossible.

WP Umbrella. The Security add-on at $2 per site per month, $24 per site per year, flat at any scale, inside the maintenance infrastructure you already run.

The real question is rarely “which firewall.” It is whether you want the same Patchstack intelligence as a separate system to operate, or as a $2 line inside the platform you already have.

Per-site cost at 10, 50, 100, and 300 sites

Vendors publish single-site prices. Agencies buy portfolios. Here is what a year actually costs at agency scale, using the July 2026 prices above.

Product10 sites50 sites100 sites300 sites
WP Umbrella Security add-on$240$1,200$2,400$7,200
Patchstack Developer (direct)$828 (1)$1,578$3,078$9,078 (2)
Wordfence Premium (list)$1,490 (3)$7,450$14,900$44,700
Sucuri Basic (extrapolated)$2,290 (4)$11,450$22,900$68,700
PerfGrid security add-onfrom €480 (5)from €2,400from €4,800from €14,400
Kadence bundles (Liquid Web)$299 Pro / $499 Elite, flat (6)not publishednot publishednot published
  1. Developer includes up to 25 sites; 10 sites still pay the full $828, $82.80 per site.
  2. At 300 sites, Patchstack’s custom-priced Enterprise tier likely undercuts the pack math; read as “from.”
  3. List prices. With volume discounts of up to 25%, 50/100/300 sites come to roughly $5,588, $11,175, and $33,525.
  4. Extrapolated: each Sucuri plan covers one site; 10+ sites is quote-only.
  5. “Starting at” pricing; requires hosting on PerfGrid.
  6. Flat bundle price, site allowance unpublished; no honest per-site cell is possible.

The per-site arithmetic is where the models separate. At 10 sites, Patchstack direct works out to $82.80 per site per year against WP Umbrella’s $24, because the 25-site allowance makes small portfolios pay for capacity they do not use. At 100 sites and beyond, direct settles around $31 per site, while per-site licenses like Wordfence stay at $149 list.

WP Umbrella’s number is $24 at every row because there are no tiers, and per-site selectivity means the real invoice is often lower: you only multiply by the sites that need protecting.

What the $2 actually buys: three components

1. A firewall with virtual patching. When a vulnerability is disclosed and no patch exists yet, a rule sourced from Patchstack’s threat research blocks the exploit at the PHP level before WordPress fully loads. The full mechanics live in what virtual patching is in WordPress. An insights view shows attacks blocked, top attacking IPs, and top triggered rules, so the protection is visible rather than theoretical. This replaces a per-site security plugin license.

2. Per-site security hardening. The hardening rules WP Umbrella used to apply silently in the background are now visible, per-site toggles, with the first batch shipped in July 2026 and more coming. Recommended toggles switch on automatically when you enable the add-on; two stay off by design (application passwords and REST API restriction) because they can break legitimate integrations. This replaces manual .htaccess work and single-purpose hardening plugins.

3. A security-driven activity log. Where the base platform’s activity log records what happens inside WP Umbrella, this one watches the WordPress sites themselves: brute-force attempts, mass content deletion, privilege escalation, unusual sign-in locations, file-integrity changes to core and theme files, and critical settings changes, each with account, IP, and timeline forensics. This replaces an audit-log plugin and gives you a first-pass forensic trail.

4. A malware scanner: it surfaces know corrupted files and tables.

Setup cost is effectively zero: the add-on needs no configuration to start, and everything is adjustable per site afterward.

Is the Security add-on worth it for agencies managing multiple sites?

Worth is a function of the patch window. With 46% of new vulnerabilities lacking a developer fix at disclosure, there is often nothing to update on day one. For the most heavily targeted vulnerabilities, Patchstack’s whitepaper puts the weighted median time to first exploit attempt at 5 hours, and 1,966 of 2025’s vulnerabilities (17%) carried a high severity score, the kind exploited in automated mass-scale attacks. Attackers automate; agencies coordinate. Virtual patching covers the gap.

When the Security add-on is worth it

  • Agencies that stage updates. If your workflow includes testing, client approval windows, or scheduled maintenance days, you live inside the vulnerability window by design. This is the exact gap virtual patching closes.
  • Agencies running WooCommerce stores. E-commerce sites are higher-value targets: a compromised store risks payment data, chargebacks, and legal liability. $2 per site is cheap insurance against that class of incident.
  • Agencies with high-value clients. Larger clients expect prevention, not just detection. The add-on’s activity shows up in your client reports’ security sections, so the posture is documented, not claimed.
  • Agencies past 100 sites. One disclosure can touch dozens of clients at once. Coordinating 200 emergency updates in an afternoon is not an operations plan; a rule that blocks the exploit portfolio-wide is.

Because the add-on is per-site, “worth it” is not an account-level verdict. Enable it where the risk lives, and let the quiet half of the portfolio ride on the base platform’s monitoring.

When you don’t need this

An honest pricing article owes you the other side. Skip the add-on, or scope it down, when:

  • The sites are hobby projects. Low-traffic sites with no client expectations do not justify the line item the way client sites do.
  • Your worry is DDoS. That is edge-layer work. The add-on’s firewall operates at the application level and runs alongside a CDN service like Cloudflare rather than replacing it.

None of these mean virtual patching is overpriced. They mean the $2 buys a specific thing, and you should know whether you need that thing before multiplying it by your site count.

The care-plan math: what agencies bill for a $2 line item

Cost is half of the pricing question. The other half is that agencies do not consume security; they resell it inside care plans.

Run the worked example. Fifty sites with the add-on enabled cost $100 per month. Agencies that carry a security line on their care plans commonly price it at $15 to $25 per site per month, which on the same 50 sites bills $750 to $1,250 per month. The delta is margin on work the infrastructure performs: patch-window coverage, hardening, and a forensic log that answers “what happened” before a client asks.

The margin is defensible only if the client sees the deliverable. WP Umbrella’s client reports include security sections, so blocked attacks and hardening posture appear in the document that justifies the retainer. A line item a client can see renews; an invisible one gets negotiated away.

Per-site selectivity maps cleanly onto plan tiers. Put protection on the premium care tier and price it accordingly; keep the standard tier on the base platform’s monitoring. Your cost structure then mirrors your packaging instead of fighting it.

Security vendors price per site and climb. Almost none frame the line item the way an agency experiences it: as a revenue line with a $2 cost of goods. That is why the flat price matters; predictable cost makes a margin promise safe to put in a proposal.

What is the ROI of virtual patching for WordPress agencies?

Price one incident first, in hours rather than headlines.

A hacked client site typically absorbs 5 to 15 expert-hours: triage, cleanup, entry-point hunting, re-hardening, and the client communication around all of it. At Codeable’s published rate of $80 to $120 per hour for vetted WordPress experts, that is roughly $400 to $1,800 in labor per incident, before reputation damage and the uncomfortable calls.

The market prices the same fear as a product: Wordfence Response, the incident-response tier on the plans page linked above, runs $1,250 per year for a single site. That is what “someone answers when it goes wrong” sells for standalone.

Now convert. The Security add-on costs $24 per site per year, so one incident’s labor bill equals roughly 17 to 75 site-years of coverage. Prevent one incident across a 100-site portfolio in a year and the $2,400 spend has cleared its bar. The exposure is not hypothetical: 46% of disclosed vulnerabilities ship without a fix, so the window opens no matter how good your update process is.

There is also a quieter return: consolidation. The add-on rides on infrastructure that already handles updates, backups, monitoring, and client reporting, so the $24 is incremental rather than another system to license and operate. The table above makes the alternative concrete: at 100 sites, standalone per-site licensing runs $11,175 to $14,900 per year against $2,400.

The math is not subtle. It never was; it just needed the per-site table.

Virtual patching cost: the final answer

Three numbers decide this.

  • The price: 1.99€ per site per month for the WP Umbrella platform, plus $2 per site per month for the Security add-on, flat at any scale, enabled only on the sites that need it.
  • The market: at 100 sites, comparable protection runs from about $31 per site per year bought direct to $149 list per site as a plugin license, with quote-only pricing above that.
  • The downside: one incident costs $400 to $1,800 in expert labor, or 17 to 75 site-years of coverage.

For agencies operating at scale, enabling the add-on across the exposed part of the portfolio removes one variable from an already complex system. You’re not buying a feature. You’re buying stability during the hours before patches land and updates deploy.

Start your free trial. 14 days, all features, no credit card required.

Next, read the complete WordPress Security Guide 2026.