WordPress security for Plesk

Block known WordPress exploits before they reach your site

WordPress threats move fast. In July 2026, attackers began targeting a critical WordPress core vulnerability just 90 minutes after the security update was released, according to Patchstack. That gap matters. An exploited vulnerability can mean malware, downtime, stolen data and an expensive clean-up before you've even had time to safely test and deploy the update.

WP Guardian closes that gap automatically with a virtual patch, often before the vendor has even released a fix.

Live in about two minutes No code, no configuration Works alongside your existing security Managed through Plesk

From £4/month per site, down to £1.56 across a portfolio. Full pricing tiers ↓

Not sure where to start? Start with your highest-risk site, then add more once it's proven itself.

Time to first exploit

90min

Attacks can begin within 90 minutes of a vulnerability becoming public. WP Guardian automatically applies a virtual patch, closing the gap between disclosure and a safe update.

A WordPress site owner working at a laptop

Who it's for

Built for the person keeping WordPress patched, and everything else

WP Guardian is for agencies and site owners who manage WordPress through Plesk and cannot drop everything to test and apply an update the moment a vulnerability is disclosed. It is the layer that holds while you decide when to update, not a replacement for updating.

  • You manage WordPress sites through Plesk, for yourself or for clients
  • A vulnerability notice does not always mean you can safely update right away
  • You want known exploits covered without racing every disclosure

How does WP Guardian work?

Three steps, and the third one is the part that actually protects you

Step 1

Connect

Installs the agent that links your Plesk server to WP Guardian.

Step 2

Detect

Scans every WordPress site on that server for vulnerable plugins, themes and core.

Step 3

Protect

Blocks the known exploit with a virtual patch, or applies the update if you've set it to.

You can see vulnerabilities across all your WordPress sites, regardless of how many WP Guardian licences you have. Protection is limited by your licence count. For example, if you have 10 sites and 5 licences, all 10 are scanned for vulnerabilities, but you choose which 5 have Vulnerability Protection (virtual patching) enabled.

One product, two different jobs

Built for the portfolio. Built for the one site that matters

Whether you're covering forty client sites or the one that runs your business, WP Guardian solves the same underlying problem: closing the gap between disclosure and patch. The payoff just looks different depending on which side of that you're on.

For agenciesFor businesses
Per-site cost drops from £4 to £1.56 as you scaleNo more choosing: exposed plugin, or risky live update
Bulk updates across every site, not one login at a timeNo security expertise needed, protection is automatic
Fewer hacked-site emergencies eating into billable hoursProtects what matters: revenue, reputation, search rankings
Visibility you can show clients: what's vulnerable, what's coveredRuns quietly in the background, nothing to babysit
One dashboard instead of forty loginsFrom £4/month, far less than a hacked-site cleanup

Why the gap matters

Why the time between disclosure and patch is the riskiest part

Patchstack's State of WordPress Security in 2026 report recorded 11,334 new WordPress ecosystem vulnerabilities in 2025, roughly one new vulnerability every 46 minutes. For serious vulnerabilities, attackers do not wait. Patchstack has tracked critical flaws being exploited within 90 minutes of disclosure. The median time to mass exploitation for heavily exploited vulnerabilities is 5 hours, and around half of high-impact vulnerabilities are exploited within 24 hours.

WordPress core
WordPress 7.0.2, July 2026: Patchstack recorded the first real exploitation attempts about 90 minutes after release, and blocked over 65,000 exploitation attempts from more than 1,500 IP addresses in the days that followed.
Plugin example
OttoKit / SureTriggers: exploitation attempts began 91 minutes after the vulnerability was disclosed.

Source: Patchstack's State of WordPress Security in 2026 report and Patchstack's public vulnerability database.

That gap shows up as a real decision, not an abstract risk:

  • A vulnerability scan flags a plugin with no fix released yet
  • The available update has not been tested against a live, customised site
  • A client's site cannot go down to test an update mid-week
  • You are choosing between an exposed plugin and a risky update

None of those is a good choice on its own. WP Guardian gives you a third option: block the known exploit now, apply the real fix once it is safe to.

Updating eventually is not the same as covered now

Generic server defences were not built for WordPress-specific exploits

Standard hosting security catches a lot, but it isn't designed to recognise every WordPress-specific vulnerability. In a Patchstack test of 11 WordPress vulnerabilities across 5 hosting environments, 87.8% of exploit attempts got past the existing defences. Two environments stopped none at all, and even the best-performing setup blocked only 4 of 11. WP Guardian is designed to close that specific gap. Without it, every new vulnerability disclosure puts you back into the same loop:

The reactive vulnerability update cycle

  • Disclosure
  • Investigate
  • Scramble to test the update
  • Repeat

Every cycle through that loop is either a rushed update on a live site, or an exposed plugin left running while you find the time.

WP Guardian breaks that loop. A virtual patch blocks the known exploit while you test and deploy the vendor's fix safely, turning an emergency update into a scheduled job. The update still happens. It just stops being a race.

How it actually works

What a virtual patch actually blocks

WP Guardian does not rewrite your plugin or wait for you to update it. It recognises the known exploit pattern associated with the vulnerability and blocks matching requests. The plugin itself stays exactly as it is until you choose to update it.

The Security Status view shows you exactly where you stand: your risk score, which plugins are vulnerable, how severe each vulnerability is, and the actions available to fix it, including updating or deactivating the affected plugin.

You can see the risk, the affected plugin and what to do next in one place.

The WP Guardian Security Status view for a WordPress site, showing a security risk score, Protection Enabled, available updates, and a list of vulnerable plugins ranked by risk with one-click update or deactivate options
A real Security Status view. Domain shown is a placeholder (example.com).

What it actually does

Four things it covers, running quietly in the background

WP Guardian runs at the server layer for every WordPress site you manage through Plesk:

  • Vulnerability Protection: blocks known exploit attempts in high and medium risk vulnerabilities automatically, without touching your site's code, so you are covered without lifting a finger
  • Smart Updates: before a WordPress core, plugin or theme update runs, WP Guardian clones your site, applies the update to the clone, and checks for issues. The update only reaches your live site once you confirm it, or automatically if the test run found nothing wrong. You stop discovering a broken update from an angry client, and start discovering it on a clone nobody was using
  • Smart PHP Updates: run a compatibility check directly on your live site, without changing anything, to see whether switching PHP versions would need a code change before you commit to it, so upgrading PHP stops being a guess
  • Continuous monitoring, not a one-off scan you have to remember to rerun
WP Guardian running a Smart Update test: analysing the original site, creating a test site, updating it, and comparing the test site before and after
A Smart Update test run in progress: your live site is untouched until this finishes.

Kept current

Vulnerability intelligence updated continuously, not on schedule

WP Guardian draws on continuously updated vulnerability intelligence from Patchstack and Wordfence, two of the most established vulnerability databases in WordPress.

  • Same-day coverage: protection for a newly disclosed vulnerability lands the day it's published, not whenever the next scheduled scan happens to run
  • Sometimes ahead of disclosure: Patchstack can mitigate certain vulnerabilities up to 48 hours before they're made public
  • Runs alongside what you already have: server layer, before a request reaches WordPress, so it doesn't replace a security plugin, a firewall, or your own update process
  • Closes one specific gap: the time between a vulnerability going public and the vendor's fix landing, which none of the above are built to close

Staying in control

Updating your plugins is still your call

Whatever WP Guardian blocks, three things you can count on:

Applying the real fix is your decision

A virtual patch buys you time. It does not update the plugin for you, and it does not stop you updating whenever you are ready.

Runs at the server layer, not inside WordPress

WP Guardian does not modify your plugin files, themes or database, which is why it runs with negligible performance impact and needs no code changes to your site.

Managed the way everything else on your VPS is

Turned on and off from inside Plesk. A question about something it flags goes to Layershift support, not a second vendor relationship.

What you get out of it

When the gap between disclosure and patch is covered

Day to day, that changes a few concrete things:

Known exploits blocked the day they are disclosed, not the day you get to them

Fewer "we need to update this right now" emergencies

Visibility into every vulnerable plugin and theme across every site you manage

Runs quietly in the background, with negligible performance impact

And you can see what's covered

WP Guardian's reporting shows which plugins and themes are vulnerable and what has been virtually patched, so protection is not something you take on faith.

A WordPress site's plugin list in WP Guardian, with vulnerable plugins flagged and active and autoupdate toggles for each plugin
A real plugin list. Vulnerable plugins are flagged automatically, no scan to run.

The word for all of that is

covered

You stop finding out about a vulnerable plugin from a hacked site, and start finding out from a dashboard, before it becomes an incident that damages your business or reputation.

Pricing

Clear pricing, lower cost per site as you grow

Bulk discounts are built in. Billed monthly, cancel anytime.

SitesMonthly pricePer-site cost
1£4.00£4.00
5£11.75£2.35
10£19.50£1.95
20£35.00£1.75
30£50.50£1.68
50£77.75£1.56
50+Contact us for a quote →

Priced per site, not per server, so cost tracks what you're actually protecting.

Getting WP Guardian: the fastest way

Click Try one site for £4/mo, log in and choose your VPS. Then select the licence tier that covers the number of sites you want to protect. For example, if you're protecting 3 sites, choose the 5-site tier. WP Guardian is then applied directly to your server.

Already in Plesk?

When you view your website in Plesk, you can activate WP Guardian directly from the Security section by enabling Vulnerability Protection and following the on-screen instructions.

The Available Updates panel in WP Guardian, listing outdated WordPress plugins with current and new version numbers, changelogs, and a Smart Update toggle
A real Available Updates panel, with Smart Update ready to enable.

Available on Plesk Web Pro and Web Host editions. If Vulnerability Protection is not offered on your current plan, our support team can check and adjust it for you.

Still weighing it up? Talk to us first

Frequently asked questions

Questions, answered

Pick the area you are weighing up, or just scan the lot. Most questions land on how it works, how much control you keep, and licensing.

Who is WP Guardian for, and how do I get it?

It is a security add-on for WordPress sites managed through Plesk. If you already have a Layershift Managed VPS, you can turn it on for any site by enabling Vulnerability Protection in WP Toolkit, in about two minutes. If you're not on a Managed VPS yet, talk to us first.

How is this different from a WordPress security plugin?

WP Guardian operates at the server layer, before a request ever reaches WordPress, rather than working from inside WordPress the way a plugin does. That means it keeps blocking a known exploit even for a plugin you have not been able to update yet, without needing to touch WordPress itself.

Does virtual patching mean I do not have to update my plugins?

No. A virtual patch blocks the known exploit while you wait; it does not replace the vendor's update. If the plugin author has not released a fix yet, the virtual patch simply stays in place for as long as it takes, so you are not left exposed while you wait. Once an update is available, you test and apply it in your own time.

Will it slow down my site?

No. WP Guardian runs at the server layer with negligible performance impact, and it does not modify your plugin, theme or database files.

Do I need technical knowledge to set it up?

No. It is turned on from inside Plesk with a single switch and needs no coding or configuration.

Who do I contact if I have a question about something WP Guardian flags?

Us. WP Guardian is an add-on we provide as your host, so anything to do with it goes to Layershift support in the usual way.

How much time does this actually save for an agency managing multiple sites?

Enough to notice. Patchstack, the vulnerability intelligence behind WP Guardian's virtual patching, published a case study with a hosting provider running this same protection for its customers: over 15 hours of support workload saved weekly, because vulnerabilities were mitigated before they turned into customer-facing incidents. That's a third-party hosting deployment's result, not a Layershift-measured figure, but it's a reasonable proxy for what fewer "site's been hacked" emergencies are worth across a portfolio.

I only run one WordPress site for my business. Is WP Guardian overkill?

No. The problem doesn't scale down: a single vulnerable plugin can still take your one site offline, and the choice between updating immediately on a live, revenue-generating site or waiting while exposed is the same choice whether you run one site or forty. At £4 a month for a single site, it's priced for exactly that case.

Does WP Guardian only scan the sites I'm paying for?

No. Detection isn't limited by your licence. WP Guardian scans every WordPress site on a connected server for vulnerabilities, including ones beyond your current plan, so you can see what's exposed across your whole portfolio. Virtual patching and updates only apply to sites within your licensed count; sites beyond that show up as "unmanaged" with their vulnerabilities still visible, until you add them to your plan.