Platform features

One command center for WordPress monitoring, diagnosis, backup, and repair.

WPFixAgent gives agencies and site owners a clear operating system for WordPress reliability: connect sites, collect baselines, review incidents, queue safe repair actions, and keep every change auditable.

Signed

Connector

5-stage

Repair flow

0

Hosting passwords

Per-site

Repair history

wpfixagent.com/features

How the feature stack works together

Pair the connectorGenerate a short-lived token for one organization and exchange it for encrypted, site-specific credentials.
Collect a baselineThe site sends signed inventory and health data outbound without exposing a public repair endpoint or requiring hosting credentials.
Detect and prioritizeRules convert health data, incidents, vulnerabilities, and update context into severity-ranked issues and high alerts.
Protect and repairRisky playbooks create a restore point before the connector runs a signed, allowlisted action for that website only.
Verify and recoverA fresh scan and optional independent test determine whether the run completes, remains open, or rolls back.

What WPFixAgent does that most WordPress tools don't

Monitoring tells you something's wrong. This actually fixes it.

Plenty of tools watch your site and email you when something breaks. Here's what happens after that email, on WPFixAgent.

Dead-site recovery, no connector required

White-screened, unreachable, never even paired? WPFixAgent connects over FTP/SFTP and deploys a standalone rescue file to bring it back -- no working wp-admin, no plugin installed beforehand.

Most monitoring tools can't touch a site that's already down

Quarantine and reinstall, not just a scan report

When malware is found, it's disabled and locked away -- or the plugin is redownloaded from its official source and every tampered file replaced. Not a list of findings for you to act on yourself.

Most security add-ons stop at detection

A plugin fatal gets caught and quarantined automatically

MU Safe Mode runs before your normal plugin stack loads. The instant it catches a plugin-caused crash, it isolates that exact plugin -- no alert to wait on, no manual restart.

Most tools alert you and wait

AI that actually diagnoses, not just chats

Redacted incident context goes to an AI model that explains the likely cause and recommends a specific registered repair playbook -- execution still stays limited to signed, allowlisted actions.

Most "AI features" elsewhere are just a chat assistant bolted on

Plugin conflicts get isolated and tested live

A dedicated workflow backs up the site, isolates one candidate plugin at a time, tests, and restores automatically -- turning "probably this plugin" into evidence.

Most tools only show you a PHP error log

Self-built security scanning, zero third-party API

Malware detection and WordPress core-file integrity checks are computed by WPFixAgent itself against the real wordpress.org release -- no external vendor key required to keep working.

No dependency on a third-party vulnerability feed for core protection

Complete platform coverage

Every feature supports safer decisions and provable outcomes.

Monitoring, repair, recovery, security intelligence, and team operations stay connected to the exact website and incident that produced the work.

01

Continuous website monitoring

Track connector heartbeat, WordPress and PHP versions, active theme, plugin inventory, update signals, WP-Cron, REST health, disk capacity, database errors, and filesystem writability.

02

Site-specific Issue Center

Convert health signals, incidents, update findings, vulnerability matches, and connector failures into a prioritized queue for the affected website.

03

AI-assisted diagnosis

Send redacted incident context to the configured AI provider for an explanation and a recommended registered playbook. AI output never becomes arbitrary executable code.

04

One-click supported fixes

Queue known actions directly from issues, including scans, restore points, rewrite flushing, supported cache clearing, Elementor CSS regeneration, and recovery review.

05

Safe auto-fix

Group eligible low-risk issues into an automatic action queue while leaving malware, database, disk, hosting, and uncertain failures for human review.

06

Protected local restore points

Create database and wp-content archives before risky repairs, retain up to three protected local copies, and display the latest restore point per site.

07

Five-stage repair runs

Track analysis, protection, repair, verification, and recovery as one persisted run instead of showing unrelated commands without context.

08

Verification and rollback

Run a fresh connector scan, PageSpeed test, or browser smoke check after repair. Failed verification keeps the issue open and can enter rollback when a valid restore point exists.

09

Emergency recovery

Use a must-use Safe Mode loader and signed CLI rescue bridge to block a crashing plugin, remove stuck maintenance mode, or restore access when the normal plugin stack fails.

10

Recovery for a site with no connector installed

A site can be white-screened or completely unreachable before WPFixAgent was ever connected. Using FTP or SFTP credentials entered once and never stored, WPFixAgent locates the WordPress install and deploys a standalone rescue file to bring it back -- Professional and Agency plans.

11

Independent security scanning

Self-built malware detection and WordPress core-file integrity checks -- no third-party security vendor or external API, ever. Findings surface as critical, malware, error, and operational alerts in SaaS and WordPress.

12

Malware quarantine

Disable a suspicious file in place -- moved into a locked, non-executable folder with a recovery manifest -- rather than deleted outright, so a false positive is never destructive.

13

Reinstall from official source

Redownload a plugin or theme's current official WordPress.org release and replace every file -- even without a pending update -- removing anything injected that wasn't part of the real package.

14

Plugin, theme, core, and database updates

Apply WordPress's own trusted updates with component snapshots first -- a plugin or theme update restores itself automatically on failure; a core or database upgrade requires a verified full restore point from the last 24 hours.

15

Backup restore and retention

Restore full, database-only, or component-scoped from any local archive, delete obsolete restore points without opening WordPress, and keep up to three protected local copies automatically pruned.

16

Configuration hardening

Disable public debug-output exposure and the in-dashboard file editor after snapshotting current configuration, closing two of the most common post-compromise persistence paths.

17

Repair history and audit logs

Keep issue fingerprints, commands, stages, results, timestamps, verification outcomes, rollback status, and organization activity attached to the correct site.

18

Multi-site teams and reports

Manage fleets with organization-scoped access, six team roles, account reports, and separate website workspaces for client operations.

One connected operating model

How the feature stack works together

01

Pair the connector

Generate a short-lived token for one organization and exchange it for encrypted, site-specific credentials.

02

Collect a baseline

The site sends signed inventory and health data outbound without exposing a public repair endpoint or requiring hosting credentials.

03

Detect and prioritize

Rules convert health data, incidents, vulnerabilities, and update context into severity-ranked issues and high alerts.

04

Protect and repair

Risky playbooks create a restore point before the connector runs a signed, allowlisted action for that website only.

05

Verify and recover

A fresh scan and optional independent test determine whether the run completes, remains open, or rolls back.

06

Review the evidence

The site dashboard retains repair history, commands, alerts, audit activity, and unresolved escalation context.

Built for operational trust

No cPanel, FTP, SSH, or database password required for standard pairing

Tenant-scoped websites and signed connector requests

Sensitive values redacted before optional AI diagnosis

Repair history records verification and rollback outcomes

FAQ

Common questions

Is WPFixAgent only a monitoring tool?

No. Monitoring is the starting point. The product also provides an Issue Center, diagnosis, restore points, supported fixes, safe auto-fix, verification, rollback workflows, emergency recovery, alerts, reports, and audit trails.

Can teams manage multiple sites?

Yes. Organizations keep websites, roles, incidents, repair runs, alerts, and reports separated by workspace.

Does AI directly change my site?

No. AI can explain redacted context and recommend a registered playbook, but execution remains limited to signed, allowlisted connector commands.

Where are backups stored?

Standard repair restore points are stored locally inside a protected connector directory. Enterprise deployments can add custom object-storage integration; local copies alone are not disaster recovery.

What still needs a specialist?

Unknown malware, server outages, exhausted disks, database-server failures, deleted core files, compromised hosting credentials, and custom-code defects may need a specialist.

Free 14-day trial · no card required

Give every WordPress site a safer path from incident to verified recovery.

Install the connector, pair with a one-time token, and start monitoring in minutes -- upgrade whenever you're ready.

Start Free Trial