WP Umbrella Logo

WordPress Security

Harden client sites, catch real threats early, and manage security at scale from one dashboard, without turning maintenance into a constant emergency.

  • Vulnerability monitoring on every plan
  • Security hardening toggles on every plan
  • Site health warning management
  • Firewall and virtual patching (Security add-on)
  • Security-Driven Activity Log (Security add-on)
  • Daily malware scanning (Security add-on)
Start your free trial
WordPress Security

How WP Umbrella protects sites

Continuous vulnerability detection: every 6 hours

WP Umbrella scans every site in your portfolio every 6 hours for known vulnerabilities affecting WordPress core, plugins, and themes. Scans are powered by Patchstack, one of the leading WordPress vulnerability databases, which tracks and discloses CVEs across the WordPress ecosystem in real time. Each detected vulnerability is surfaced directly in your dashboard with enough context to act: severity level, affected component, and the version that fixes it, with the fixing update one click away. You can also re-scan on demand instead of waiting for the next automatic check. All of this is included on every plan.

Clear risk visibility across your portfolio

Vulnerabilities are ranked by severity so you can prioritize: a critical vulnerability gets your attention immediately, while a low-risk issue on a staging environment can wait for the next maintenance window. This lets agencies manage security across 50 or 500 sites without treating every alert as an emergency.

Security hardening included on every plan

Per-site toggles close the doors attackers try first: hide your WordPress version, block user enumeration, mask login error messages, disable the file editor, add security headers, rate-limit login attempts, disable XML-RPC, and protect your uploads folder. Every site gets the same baseline protection, and warnings you have consciously accepted can be dismissed so Site Health stays a real to-do list.

Firewall and virtual patching (Security add-on)

When a vulnerability is discovered but no patch is available yet, or when updating immediately isn't safe, the Security add-on's firewall applies virtual patching (powered by Patchstack): it blocks exploit attempts targeting the known vulnerability without modifying the plugin or theme code itself. The insights view shows the attacks blocked over the last 30 days, the top blocked IPs, and the rules that caught them, proof you can put in front of clients. The Security add-on replaces in-WordPress security plugins like Wordfence, Sucuri, or Solid Security, with no impact on site performance. It does not replace network or server-level firewalls, which remain part of your hosting infrastructure.

A malicious-IP blocklist learned across the network (Security add-on)

WP Umbrella watches login attacks across every site on the platform and continuously builds a shared blocklist of malicious IP addresses. Once an IP is flagged anywhere on the network, it is blocked on your login page in advance, before it ever reaches your site.

Security-Driven Activity Log (Security add-on)

Detections run on the sites themselves across eight checks: brute-force attempts, new admin accounts, sign-ins from new locations, file integrity, critical settings changes, mass content deletion, hidden administrator accounts, and .htaccess changes. Every alert carries its evidence: the accounts involved, the IPs, the timeline, and a recommended response. A searchable stream below records every event.

Daily malware scanning (Security add-on)

A daily scanner flags known malicious files, so an infection that slipped past prevention stops being invisible. Files you have verified yourself can be dismissed into their own list. And if the scanner flags a real infection, malware cleanup is available on demand: contact support and our team handles the removal with you.

Included on every plan, upgraded with one switch

Every account gets the visibility and hygiene layers: vulnerability monitoring, Site Health checks, and the security hardening toggles.

The Security add-on is the active protection layer on top. Enabling it turns on four components together, with sensible defaults:

  • A firewall with virtual patching (powered by Patchstack)
  • A malicious-IP blocklist learned across the whole network
  • The Security-Driven Activity Log with attack detections
  • Daily malware scanning, with cleanup on demand

Each piece can then be adjusted per site. 10,000+ sites already run it, and because it is priced per site, you protect the sites that need it without paying for the ones that don't.

Included on every plan, upgraded with one switch

How agencies typically use security

Most agencies start with the visibility layer that every plan includes: vulnerability monitoring across all client sites, hardening toggles switched on, and Site Health warnings triaged.

From there, the routine settles in:

  • Fixing vulnerabilities during regular maintenance, one click at a time
  • Enabling the Security add-on on high-value or frequently attacked client sites
  • Reviewing detections and firewall insights before each client report

As portfolios grow, security becomes about prioritization and consistency, not reacting under pressure.

Related capabilities

Security works best when combined with:

Together, they turn security into a predictable part of your maintenance process.

I used ManageWP for years, but I felt like it just got outdated. I had issues with their support which made me lose hope and that's when I moved to WP Umbrella.

Jeffrey Dalrymple
Jeffrey Dalrymple · Founder @ Lytbox

When a Cloudways customer asks us what the best WordPress management tool is, we are happy to recommend WP Umbrella.

Muhammad Saad Khan
Muhammad Saad Khan · Product Marketing @ Digital Ocean

After trying virtually every management tool out there, I've fully moved my agency to WP Umbrella, and I'm convinced I won't need to look further.

Kyle Van Deusen
Kyle Van Deusen · Founder @ The Admin Bar

Get started, without pressure

Most agencies start with the security visibility included on every plan, then enable the Security add-on on the client sites where active protection matters most.

Free trial | No card required

Frequently Asked Questions

WP Umbrella detects known vulnerabilities affecting WordPress core, plugins, and themes, using trusted vulnerability data sources like Patchstack.

Virtual patching blocks exploit attempts targeting a known vulnerability at the firewall level, before the fixing update is applied or even released, without modifying plugin or theme code. It buys agencies time to plan and test a proper update without leaving sites exposed. The durable fix is still the update.

Every plan includes vulnerability monitoring (checked against the Patchstack database every 6 hours, with one-click fixing updates), Site Health checks with dismissible warnings, the security hardening toggles, the platform Activity Log, and uptime, PHP error, and performance monitoring. The Security add-on adds the active protection layer: the firewall with virtual patching, the network-learned IP blocklist, the Security-Driven Activity Log, and daily malware scanning.

It costs 2€ or $2 per site per month, on top of the per-site subscription. Per site means you can protect the sites that need it without paying for the ones that don't. You can enable it in bulk from the dashboard or site by site from the Security tab.

It replaces in-WordPress security plugins like Wordfence, Sucuri, or Solid Security: the add-on covers the firewall with virtual patching, a network-learned malicious-IP blocklist, attack detections through the Security-Driven Activity Log, and daily malware scanning, with no impact on site performance. It works at the PHP level, so it complements DNS or CDN-level services like Cloudflare and does not replace hosting-level firewalls or DDoS mitigation.

The daily scanner lists every flagged file in the Malware section. Files you have verified yourself can be dismissed. If the scanner flags a real infection, malware cleanup is available on demand: contact support and the team handles the removal with you. Your backups remain the recovery path for the worst cases.

Yes. Security events and actions can be included in client maintenance reports to help explain risks and remediation work.

Yes. Security status and vulnerabilities are visible across your entire portfolio, allowing agencies to prioritize and act consistently at scale.

Trusted by 80,000+ sites (as of July 2026)

Get the complete WordPress care toolkit, all in one platform.

WP Umbrella is designed to grow with your care business, from your first maintenance clients to a mature, multi-site operation.

  • All your care plan tools in one place
  • Sites backed up, monitored, and updated automatically
  • Client reports that prove your value on autopilot
  • Expert support whenever you need it
Get started for free