Features

Ten layers of protection. One plugin.

Pressfort stops attacks before they land and spots problems fast. If something does go wrong, a WordPress developer fixes it. Here's what each part does, and why it's there.

Prevent

Stop attacks before they land.

Most successful attacks use a known weakness. These four features close those weaknesses, or block anyone trying to use them.

Auto-updates that don't break your site

Keeping WordPress, plugins and themes up to date is one of the most effective things you can do for security. It's also the thing most likely to cause a problem, which is why so many sites quietly stop doing it.

Pressfort runs updates in a safe order. A full backup is taken first. The updates are applied to a staging copy of your site, so any problem shows up there, away from the site your customers use. Then they're pushed live.

  • WordPress core, plugins and themes
  • A backup before every update run
  • Tested on a staging site first
  • Easy to roll back if you ever need to
Update run
Tonight, 02:00
Complete

3 updates

  • WordPress coreSecurity release
  • WooCommerceMaintenance release
  • Gallery pluginFixes a known flaw

What happened

  1. Backup takenFull site, stored off-site
  2. Updated on stagingYour staging copy gets them first
  3. Pushed liveYour site is up to date
Restore point kept for 90 daysRoll back

An advanced firewall built for WordPress

Hosting firewalls are general-purpose. They protect the server, but they aren't tuned for the plugins and themes your site actually runs. In Patchstack's 2026 testing, standard hosting defences blocked just 26% of WordPress-specific attacks.

Pressfort's firewall checks every request before WordPress handles it. It knows what attacks on WordPress look like, from login attacks to requests aimed at specific plugin flaws, and blocks them.

  • Blocks known attack patterns and malicious requests
  • Stops password-guessing bots
  • Filters out bad bots scanning for weak spots
Firewall
Active
14 virtual patches6 countries geo-blocked
  • Password guessing203.0.113.24 · /wp-login.phpBlocked
  • SQL injection attempt198.51.100.7 · /shop/?id=Blocked
  • Virtual patch triggered192.0.2.183 · gallery plugin upload flawBlocked
  • Country blocked by your rules203.0.113.90Blocked
  • Known bad bot198.51.100.66 · scanning for weak pluginsBlocked

Virtual patching New

When a security flaw in a plugin goes public, attackers move fast. For the most heavily targeted flaws, the median time to mass exploitation is just 5 hours. The plugin's developer might take days or weeks to ship a fix. In 2025, 46% of WordPress vulnerabilities had no fix at all when they were made public.

Virtual patching closes that gap. A firewall rule blocks attempts to exploit the specific flaw, so your site is covered while you wait for the real update. Nothing in your site's code changes.

  • Covers known flaws in plugins and themes
  • Works in the background, with no changes to your site
  • Retired once the proper fix is installed
Gallery plugin flaw
File upload vulnerability
Protected
  1. Flaw made publicAttackers start scanning for it
  2. Virtual patch appliedFirewall blocks the exploit. You're covered from here.
  3. Waiting for the developerNo official fix yet, but attacks are blocked
  4. Fix released and installedTested on staging, then pushed live
  5. Virtual patch retiredThe real fix is in place

Geo-blocking

If all your customers are in the UK, there's little reason to accept traffic from the other side of the world. A lot of automated attacks come from places a small business never trades with.

Geo-blocking lets you shut out the countries you choose. Less junk traffic reaches your site, and the firewall has less to deal with.

  • You decide which countries are allowed
  • Easy to change as your business changes
Geo-blocking rules
yourbusiness.co.uk
On
  • United KingdomAllowed
  • IrelandAllowed
  • United StatesAllowed
  • Everywhere elseBlocked
412 requests from blocked countries stopped this week

Detect

Spot problems fast.

No defence is perfect. The sooner a problem is spotted, the smaller it stays. These four features make sure nothing sits unnoticed.

AI malware scanning

Malware on a WordPress site rarely announces itself. It might be a hidden backdoor, spam links slipped into your pages, or a redirect that only shows up for some visitors. Often the first you hear of it is a customer, or a warning from Google.

Pressfort scans your site's files using AI-powered detection and flags anything suspicious straight away, so it can be dealt with before it does any damage.

  • Looks for malicious code, backdoors and injected spam
  • Runs automatically in the background
  • Alerts as soon as something is found
AI malware scan
Finished 2 hours ago
Clean
Files checked
4,812
Threats found
0
Vulnerability alert

The version of your gallery plugin has a known upload flaw. A virtual patch is in place and the update is booked into tonight's run.

Covered by virtual patch

Vulnerability alerts

More than 11,000 new vulnerabilities were found in the WordPress ecosystem in 2025. That's around 30 a day. Nobody can keep track of that by hand.

Pressfort checks the plugins and themes on your site against known vulnerabilities and tells you when one affects you. Usually the fix is an update, which goes into the next update run. If there's no fix yet, virtual patching covers the gap.

  • Plugins and themes checked against known flaws
  • Tells you what's affected and how it's being handled
Vulnerability alerts
24 plugins, 1 theme checked
1 open
  • Gallery pluginFile upload flaw · virtual patch applied, update tonightCovered
  • Forms pluginCross-site scripting · fixed by updateResolved
  • SEO pluginSettings exposure · fixed by updateResolved
  • Everything elseNo known issuesClear

Uptime monitoring

Your site gets checked around the clock. If it goes down, the alarm goes off straight away, so it gets looked at before your customers start emailing.

Downtime isn't always a hack. It can be a hosting fault, an expired certificate or a plugin conflict. Either way, you want to know about it first.

  • Round-the-clock checks
  • Alerts the moment your site goes down
  • Uptime history included in your reports
Uptime
Last 30 days
99.98%
30 days agoToday

Incidents

  • Site unreachable for 9 minutes12 days ago · hosting fault, back up without changesResolved

Activity logs

A 7-day record of who did what in your WordPress dashboard. Logins, page edits, plugin installs and settings changes are all there.

It's handy when something changes and nobody remembers doing it. It's essential when you need to trace how a problem started.

  • Logins and failed login attempts
  • Content, plugin and settings changes
  • 7 days of history
Activity log
Last 7 days
142 events
  • SSarah edited the Pricing pageToday, 09:21
  • SSarah logged inToday, 09:14
  • 3 updates applied by PressfortToday, 02:09
  • TTom installed a cookie banner pluginYesterday, 16:40
  • ?Failed login as "admin"Yesterday, 03:12 · blocked by the firewall

Recover & report

Get back to normal, with a developer on hand.

If the worst happens, you need a clean copy of your site, a clear record of what's been going on, and someone who can fix it.

90 days of off-site backups

Your whole site is backed up every day and each backup is kept for 90 days. They're stored away from your hosting, so a problem with your server doesn't take your backups with it.

Why 90 days? Some problems take a while to notice. A malware infection or a bad change can sit unnoticed for weeks. With three months of backups, there's still a clean version to go back to.

  • Daily backups of your files and database
  • Kept for 90 days
  • Stored off-site
  • Restore to any day in the last three months
Backups
One a day, kept for 90 days
90 of 90 days
90 days agoToday
14 days ago, 03:00Full site · 1.4 GB · Stored off-site
Restore this version

Scheduled reports

Regular reports land in your inbox showing what's been updated, what the firewall blocked, scan results, backup status and uptime. You can see your site is being looked after without logging in to anything.

They're written to be read by people who don't work in tech, so they're easy to forward to a client, a manager or whoever pays the bills.

  • Updates, scans, backups, blocked attacks and uptime
  • Sent on a regular schedule
Your monthly Pressfort reportTo you@yourbusiness.co.uk
Updates applied14
Attacks blocked1,248
Malware found0
Uptime99.98%
30 of 30 daily backups completed and stored off-site

Hack repair, included

This is the part most security plugins leave out. They tell you there's a problem, then it's down to you to find someone to fix it, usually at short notice and at a price.

With Pressfort, the fix is included. If your site is hacked, an update breaks something or your site goes down, our team goes in and sorts it. We've been building and repairing WordPress sites for almost 15 years.

  • Malware and hack clean-up, twice a year included
  • Broken updates rolled back or fixed
  • The weak spot closed so it can't happen the same way again
  • No call-out fee and no extra invoice
Incident
yourbusiness.co.uk
Fixed
  1. Malware foundSpam links injected into 3 files
  2. Our team alertedStraight from the scanner
  3. Site cleanedInfected files replaced, backdoor removed
  4. Scan clean againWeak spot patched so it can't happen the same way
Extra costNone, it's included

Not sure yet?

Find out how exposed your site is.

Send us your site address and get a free, plain-English report of what we find. We check from the outside, so there are no logins to hand over and nothing to install.

Security check
yourbusiness.co.uk
Example
1 urgent3 to fix2 fine
  • Known vulnerability in 1 pluginGallery plugin, file upload flawUrgent
  • 6 plugins and 1 theme out of dateOldest is 14 months behindTo fix
  • Usernames publicly visibleListed through the WordPress REST APITo fix
  • Security headers missingNo clickjacking or content protectionTo fix
  • HTTPS set up correctlyCertificate valid, redirects in placeFine
  • WordPress core up to dateRunning the latest releaseFine