Daily monitoring

An audit is a photograph. Your site is a moving target.

A site that passed clean this morning can be vulnerable by tomorrow — not because anything on it changed, but because somebody published an advisory about a plugin it has been running for two years. That is a monitoring problem, and it is not one a periodic audit can solve.

Free. No account, no card. Your report in about two minutes.

65

Sample report · 3 September 2026

northfield-outfitters.com

3 critical10 warnings27 passed
Visibility
38
Conversion
76
Security
42
Compliance
86
Speed
62
Usability & Design
84
Read the full sample report

The risk arrives from outside

You did not do anything. A researcher disclosed a flaw, a maintainer shipped a fix, and the version you froze eighteen months ago because it worked is now on a published list. Nothing on your site moved, which is exactly why nobody on your side notices.

Exact versions, not guesses

We record the components you actually run, with their version numbers, and match them against advisories by precise affected range. That is the difference between a real alert and the noise a generic scanner produces by telling everyone with WordPress installed that WordPress has vulnerabilities.

Re-verified before you hear about it

When a matching advisory appears we re-probe the live site before sending anything. If you have already patched, the alert is dropped and you never see it. An alert channel that cries wolf gets filtered, and then the one that mattered is lost with the rest.

Named checks

How the watch works

Four steps, running every day against the inventory your first audit recorded. Subscribing runs that full audit first, so you get the complete report as well as the alerts.

We record what you run
Core, plugins and themes, with exact versions, captured from the outside with no plugin to install.
We check every day
A precise affected-range match against newly published advisories, not a guess from a version number alone.
We re-verify first
The live site is re-probed before any alert is sent. Already patched means the alert is dropped silently.
Then we email you
One message about one thing, with what it affects and what to do. No digest, no newsletter, one-click unsubscribe.
43,000+ advisories
The mirror we match against, refreshed daily, covering more than 18,000 distinct plugins and themes.
Free to subscribe
Including the full initial audit. There is no card, and leaving is one click in any message we send.

Questions

Before you run it

How often will I actually hear from you?

Rarely, and that is deliberate. You hear from us when a newly published advisory matches a component you are running and the live site is still affected after we re-check. For a well-maintained site that can be a handful of times a year. If it were more often you would stop reading it.

Do I need to install anything?

No. The inventory is built from the outside, the same way an attacker would fingerprint your stack, so there is no plugin, no agent and no credential to hand over. It also means we see what is publicly detectable about your site, which is the thing worth knowing.

Does this work on sites that are not WordPress?

The daily advisory matching is deepest on WordPress and WooCommerce, because that is where a large public advisory database exists. On other platforms we monitor what we can identify from the outside, and we will tell you plainly what is and is not covered rather than charging for a watch that is not watching.

What happens to my email address?

It is used to send you the report and the alerts. Every message carries a one-click unsubscribe that takes effect immediately, and unsubscribing is never rate-limited or delayed. The privacy policy sets out the rest.

Run it on your own site.

Your score, and every finding ranked by what it costs you. If it comes back clean, that is a useful thing to know too.

Free. No account, no card. Your report in about two minutes.