SiteVigilante

WordPress management for agencies

You did not become a web agency to spend Monday morning logging into forty admin panels. SiteVigilante puts every client website you look after into one dashboard — updates, reachability, security checks, what is installed where, and the report your client reads — and gets on with the routine parts by itself.

€1.49 per month per website 14-day trial, no card required No minimum number of websites

The estate is the unit of work, not the website

Tools built for one WordPress website assume somebody is looking at it. An agency's problem is the opposite: forty or sixty websites, none of which anybody is looking at on any particular morning, and the one that matters is the one that broke overnight.

SiteVigilante is built around that asymmetry. Every screen starts at the estate and narrows: what needs attention right now, which websites are behind, which are unreachable, what changed since yesterday. You open an individual website because something sent you there, not to find out whether anything is wrong.

Each website runs a small connected plugin that answers signed requests from the platform. Nothing is scraped, nothing is guessed from the outside, and what you read on the dashboard is what the website itself reported.

On one screen

  • Every website you manage, with its WordPress and PHP version, and whether it is answering.
  • Everything waiting to be updated, across core, plugins and themes.
  • Anything that stopped responding, with what the website said when it was asked.
  • Findings that are still open, and which website each one belongs to.
  • What this product did overnight, per website, with the outcome of each item.

Clients, not just a list of websites

Websites belong to clients, and an agency's work is organised the same way. So is this product.

A client owns its websites

Group websites under the client that pays for them. A client overview answers "how is this account doing" in one place, across every website they have with you, instead of website by website.

Client contacts

Record who at the client should receive reports, and which of them actually get sent one. Adding a contact is not the same as subscribing them, and the two are separate on purpose.

A cadence per client

One client wants a report every month and another wants one every quarter. The schedule belongs to the client, not to a global setting you have to compromise on.

Websites with no client yet

Unassigned websites are a real category with their own overview, rather than an empty field you are nagged about. Onboarding an estate does not have to be finished before it is useful.

Know what is installed, everywhere

"Which of our websites still run PHP 7.4" and "where is that plugin installed" are questions that used to be answered by opening sixty admin panels. SiteVigilante projects every website's components into one inventory, so they are answered by reading one screen.

You can also declare what a website of yours is supposed to have — the set of plugins your agency puts on everything — and see which websites have drifted from it. That is how a standard stops being a document nobody opens.

The inventory is also what makes vulnerability matching possible: the published advisory feed is refreshed hourly and matched against the versions actually installed on your estate, rather than against a list of plugin names.

Answered from the inventory

  • Every plugin and theme across the estate, and the version on each website.
  • WordPress and PHP versions, grouped — including the websites that cannot be spoken for.
  • Your standard set, and every website that has drifted from it.
  • Published advisories matched against installed versions, refreshed hourly.

Checks that run without you

These run on the platform's own schedule, against every connected website, whether or not anybody is signed in.

Reachability, every four minutes

Each website's public surface is checked continuously, and a website answering with something that is not your website — a hosting suspension page, a parking page, a provider error served with a success code — is not counted as up.

The pages that matter, every quarter hour

Nominate the pages and journeys a client would notice — a shop's checkout, a contact form — and they are checked more closely than the homepage.

Certificates and domains, daily

A TLS certificate about to lapse and a domain name about to expire are the two failures that take the website and the email at the same time. Both are read once a day.

Core integrity, daily

WordPress core files are compared against what that release is supposed to contain, so a modified core file is found the next morning rather than the next quarter.

How a search engine sees it, daily

A noindex left on after a rebuild is invisible from the front end and costs a client their traffic. It is checked every morning, from the robots tag, the header and robots.txt.

Mail path, daily

The DNS records that decide whether a client's password resets and order confirmations land in an inbox or in spam. Read-only: no record is ever changed by this product.

What is on-demand, and is not claimed otherwise

The full security scan and the PageSpeed and Core Web Vitals test run when you ask for them, per website. They are not background jobs, this page will not tell you they are, and a test in this repository fails the build if any public page starts saying otherwise. The full cadence of everything that is scheduled is on the monitoring page.

A report the client actually reads

Maintenance work is invisible when it goes well, which is a commercial problem: the month nothing broke looks identical to the month nobody did anything. A report is how an agency shows the difference.

SiteVigilante builds a client report from the work it actually recorded — the updates it ran, what it found, how the websites behaved — carries your agency's branding rather than ours, and can be downloaded as a PDF or sent to the client contacts you nominated, on the cadence you set for that client. What is in the report walks it section by section, including what it prints for a dimension nothing measured.

In a client report

  • The updates run in the period, and how each one ended.
  • How the websites behaved: reachability and what was observed.
  • Findings raised and findings closed.
  • Your logo and your colours. Downloadable as a PDF.

Your team, at the right level

An agency is more than one person, and not everyone who needs to see a website should be able to change it.

Roles, including read-only

Invite colleagues with the access their job needs. A read-only seat can see everything and change nothing — enforced on the request itself, so a screen added next year is closed to them without anybody remembering to close it.

An activity log

Who did what, and when. Both what a person did and what the platform did on its own, in one record, so "when did this change" has an answer.

Two-factor authentication

Available per person, with recovery codes. The account holds credentials for every website you manage, and it is treated that way.

Workspaces are isolated

Your agency's websites, clients and reports are yours. Platform data is hosted in the European Union, and the third parties involved are published in full.

What it costs

One price per website per month. Every capability on this page is included at that price — there is no tier that unlocks reports, no seat charge, and no minimum number of websites.

You pay for the time each website is connected, calculated proportionally on your invoice, so a website you add on the 20th does not cost a full month. Adding and removing websites is subject to available platform capacity.

Pricing

Per website, per month
€1.49
VAT
Excluded
Trial
14 days
Card to start
Not required
Minimum websites
None
Cancellation
Any time

Connect one website and see it working

The trial runs for 14 days and starts without a card. Connect a website you already look after, let it run a night, and read what it found in the morning.

No credit card required Connect a website in minutes