Daily monitoring
An audit is a photograph. Your site is a moving target.
A site that passed clean this morning can be vulnerable by tomorrow — not because anything on it changed, but because somebody published an advisory about a plugin it has been running for two years. That is a monitoring problem, and it is not one a periodic audit can solve.
Sample report · 3 September 2026
northfield-outfitters.com
- Visibility
- 38
- Conversion
- 76
- Security
- 42
- Compliance
- 86
- Speed
- 62
- Usability & Design
- 84
The risk arrives from outside
You did not do anything. A researcher disclosed a flaw, a maintainer shipped a fix, and the version you froze eighteen months ago because it worked is now on a published list. Nothing on your site moved, which is exactly why nobody on your side notices.
Exact versions, not guesses
We record the components you actually run, with their version numbers, and match them against advisories by precise affected range. That is the difference between a real alert and the noise a generic scanner produces by telling everyone with WordPress installed that WordPress has vulnerabilities.
Re-verified before you hear about it
When a matching advisory appears we re-probe the live site before sending anything. If you have already patched, the alert is dropped and you never see it. An alert channel that cries wolf gets filtered, and then the one that mattered is lost with the rest.
Named checks
How the watch works
Four steps, running every day against the inventory your first audit recorded. Subscribing runs that full audit first, so you get the complete report as well as the alerts.
- We record what you run
- Core, plugins and themes, with exact versions, captured from the outside with no plugin to install.
- We check every day
- A precise affected-range match against newly published advisories, not a guess from a version number alone.
- We re-verify first
- The live site is re-probed before any alert is sent. Already patched means the alert is dropped silently.
- Then we email you
- One message about one thing, with what it affects and what to do. No digest, no newsletter, one-click unsubscribe.
- 43,000+ advisories
- The mirror we match against, refreshed daily, covering more than 18,000 distinct plugins and themes.
- Free to subscribe
- Including the full initial audit. There is no card, and leaving is one click in any message we send.
Questions
Before you run it
How often will I actually hear from you?
Rarely, and that is deliberate. You hear from us when a newly published advisory matches a component you are running and the live site is still affected after we re-check. For a well-maintained site that can be a handful of times a year. If it were more often you would stop reading it.
Do I need to install anything?
No. The inventory is built from the outside, the same way an attacker would fingerprint your stack, so there is no plugin, no agent and no credential to hand over. It also means we see what is publicly detectable about your site, which is the thing worth knowing.
Does this work on sites that are not WordPress?
The daily advisory matching is deepest on WordPress and WooCommerce, because that is where a large public advisory database exists. On other platforms we monitor what we can identify from the outside, and we will tell you plainly what is and is not covered rather than charging for a watch that is not watching.
What happens to my email address?
It is used to send you the report and the alerts. Every message carries a one-click unsubscribe that takes effect immediately, and unsubscribing is never rate-limited or delayed. The privacy policy sets out the rest.
Run it on your own site.
Your score, and every finding ranked by what it costs you. If it comes back clean, that is a useful thing to know too.