PluginProbe
Patchstack – WordPress & Plugins Security / 2.3.4
Patchstack – WordPress & Plugins Security v2.3.4
2.3.7 trunk 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.2 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.3 2.1.4 2.1.5 2.1.6 All 49 releases
patchstack / readme.txt

readme.txt in Patchstack – WordPress & Plugins Security 2.3.4, at readme.txt

197 lines 13.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 === Patchstack - WordPress & Plugins Security ===
2 Contributors: patchstack
3 Tags: security, firewall, vulnerability, vulnerabilities,virtual patching
4 License: GPLv3
5 License URI: https://www.gnu.org/licenses/gpl-3.0.html
6 Requires at least: 4.4
7 Tested up to: 6.9
8 Stable tag: 2.3.4
9 Requires PHP: 5.6
10
11 Patchstack automatically identifies and mitigates security vulnerabilities in WordPress plugins, themes, and core.
12
13 == Description ==
14
15 Patchstack is a powerful tool that helps identify security vulnerabilities within your websites' plugins, themes, and WordPress core. It is powered by the WordPress ecosystem’s most active community of ethical hackers. Patchstack is trusted by leading WordPress experts such as Pagely, Cloudways, GridPane, Plesk, and others!
16
17 https://www.youtube.com/watch?v=z2nuYpg26Vc
18
19 Patchstack is a security plugin for WordPress that finds WP core, plugin and theme vulnerabilities in your websites.
20
21 The free version includes up to 48-hour early warning for new vulnerabilities found by our security research community. It also allows you to automatically update vulnerable software, manage updates remotely, and get snapshot reports on your sites’ security status.
22
23 The paid version includes automatic vulnerability protection. Patchstack deploys highly targeted rules on a per-site basis, only when a specific vulnerability is detected on a site.
24
25 This prevents vulnerable components from being exploited without modifying website code, or impacting site performance or functionality. Patchstack’s paid version includes access to 12,000+ individual protection rules (vPatches).
26
27 Patchstack paid version also includes other preventive security features, such as 2 factor authentication, WordPress specific hardening rules, a Community IP blocklist for malicious IP addresses, advanced security settings, and custom protection rules.
28
29 ### Post-hack cleanups vs attack prevention in WordPress security
30 Unlike the standard approach to WordPress security (malware scanning and infection cleanups), Patchstack is focused on preventing infections in the first place.
31
32 Thanks to its big WordPress security research community and partnerships with nearly one thousand plugin vendors and developers, Patchstack is regularly among the first to identify new vulnerabilities.
33
34 ### Who is Patchstack's WordPress security plugin for?
35 Patchstack’s vulnerability management works extremely well for:
36
37 * Agencies with WordPress care/maintenance plans for their customers’ websites
38 * WooCommerce websites to protect their revenue and customers from attacks
39 * Hosting companies that want to deliver highly targeted vulnerability protection easily and at scale
40 Website owners
41
42 You don’t have to be highly technical to use it. Install the plugin, connect it with the Patchstack App, and stay safe!
43
44 ### What features are included in the Patchstack Personal (Free) plan?
45 Patchstack’s Personal plan is a free security service for WordPress that lets you find and manage vulnerabilities in your websites. It includes access to a central security dashboard via the Patchstack web App for more visibility and control over your sites’ security:
46
47 * Be the first to know about new vulnerabilities.
48 * Receive notifications if any installed plugins or themes have security issues.
49 * Detect the latest security vulnerabilities in WordPress plugins.
50 * Detect the latest security vulnerabilities in WordPress themes.
51 * Detect the latest security vulnerabilities in WordPress core.
52 * Receive real-time alerts via email if any security vulnerabilities are found.
53 * Manage core, plugin and theme updates from a single dashboard.
54 * [Optional] Enable automatic updates for vulnerable plugins only.
55 * Generate snapshot reports about the security status of your website.
56
57 ### What features do Patchstack paid subscriptions have?
58 Patchstack’s paid subscriptions include automatic protection for WordPress vulnerabilities, as well as other protection modules.
59
60 * Virtual patching to prevent vulnerable components from being exploited
61 * Advanced hardening module for added WordPress security
62 * Remote hardening settings (including .httacess, login protection and reCAPTCHA)
63 * Community IP Blocklist of known attacker IP addresses
64 All of these features are included in the Developer and Enterprise plans.
65 Additionally, Developer and Enterprise plan users have access to custom protection rule creation, periodical security reports and report scheduling.
66
67 Personal (Free) plan users can enable these features on a per-site basis for $5 / site per month.
68
69 **Important Resources**
70
71 * [Patchstack website](https://patchstack.com)
72 * [Help Center](https://docs.patchstack.com)
73 * [Changelog](https://docs.patchstack.com/patchstack-plugin/changelog/)
74 * [Patchstack Vulnerability Database](https://patchstack.com/database)
75
76 **See what our customers say about our paid plans:**
77
78 * "An excellent and valuable service that’s backed by a company that contributes a significant number of resources and money directly back to the WordPress ecosystem." – John Blackbourn
79 * "Patchstack is like CrowdStrike, but for websites!" – Ryan McCue, HumanMade
80 * "The service here is superb! And they are always right on it with the best solution to solve the problem or question at hand. The tool itself speaks for itself. I am very satisfied with this project and the service they offer." – Daniel Canup
81 * "This is a security plugin everyone needs to install. The Patchstack team are incredible at what they do. We have been using them for years and have not been disappointed!" – @craniumstudio
82 * "We’ve been with Patchstack for a LONG time (even before they were Patchstack). It has always done its job seamlessly and without fail. Ongoing innovation and updates to the Patchstack product mean this plugin is a winner. 5 stars all the way." – @guapx
83
84 (*Comparisons are made by evaluating paid versions.)
85
86 [Sucuri vs. Patchstack](https://patchstack.com/sucuri-alternative/)
87 [Wordfence vs. Patchstack](https://patchstack.com/wordfence-alternative/)
88 [Malcare vs. Patchstack](https://patchstack.com/malcare-alternative/)
89 [Sitelock vs. Patchstack](https://patchstack.com/sitelock-alternative/)
90
91 == Installation ==
92
93 Simply install the Patchstack plugin by searching for "Patchstack" on the plugin management page of WordPress, or install it manually by following these steps:
94
95 1. Download the plugin from the WordPress.org Patchstack plugin download page.
96 2. Unzip the `.zip` file.
97 3. Upload the entire `patchstack` directory to the `/wp-content/plugins/` directory.
98 4. Activate Patchstack through the "Plugins" menu in WordPress.
99
100 == Frequently Asked Questions ==
101
102 = What makes plugin vulnerabilities so dangerous? =
103 A worrisome website hacking statistic is that well over 90% of WordPress vulnerabilities are related to plugins or themes. One report found that up to 98% of WordPress vulnerabilities are due to plugins, while another study reported that 95% were caused by plugins and themes.
104 To stay secure, always keep your WordPress plugins, themes, and core updated and monitored. Be aware of which plugins you’re using and remove any that are no longer needed.
105 When choosing a WordPress security plugin, it's important to understand how the WordPress security ecosystem works.
106 Look for a tool that offers [vPatching](https://patchstack.com/articles/virtual-patching) (see [Patchstack’s features](https://patchstack.com/pricing)).
107
108 = How does the Patchstack Personal (Free) plan protect sites from vulnerabilities? =
109 The Patchstack Personal (Free) plan alerts you if vulnerabilities are present in the plugins, themes, or WordPress core installed on your site.
110 By staying informed, you can reduce the time and resources spent fixing WordPress security issues and avoid costly clean-ups.
111
112 = What features does the Patchstack Personal (Free) plan include? =
113 You can detect security vulnerabilities in your WordPress plugins, themes, and core. You’ll receive email notifications if vulnerabilities are found, and access a central security overview for up to 3 websites using the Patchstack App.
114 You can optionally enable vPatching for individual sites for $5/month.
115
116 = What features does the Patchstack Developer (Paid) plan include? =
117 With the Patchstack Developer plan, you can protect your sites against known plugin and theme vulnerabilities through automatic virtual patches — non-intrusive firewall rules that block exploit attempts.
118 You also gain access to advanced hardening options, 2FA, CAPTCHA, security reports, and various alert types.
119
120 = Included features: =
121 * Plugin vulnerability detection (also included in free)
122 * Theme vulnerability detection (also included in free)
123 * WordPress core vulnerability detection (also included in free)
124 * Logs and analytics (also included in free)
125 * Snapshot PDF security reports (also included in free)
126 * Email alerts (also included in free)
127 * vPatches for WordPress plugins
128 * vPatches for WordPress themes
129 * Unlimited custom firewall rules
130 * Unlimited custom alert triggers
131 * Weekly/monthly PDF reports
132 * Slack alerts
133 * Unlimited [Patchstack App API usage](https://docs.patchstack.com/api-solutions/app-api/patchstack-app-api/)
134
135 = What checks does the Patchstack Personal (Free) plan perform? =
136 No external checks are performed. The plugin matches the installed plugins, themes, and WordPress core on your site with our [vulnerability database](https://patchstack.com/database/) to identify vulnerable versions.
137
138 = How will I be alerted about a new vulnerability? =
139 With the Personal (Free) plan, you’ll receive alerts via email. Slack alerts are available in the paid Developer plan.
140
141 = Does Patchstack conflict with other security plugins? =
142 We have not encountered any conflicts. However, we recommend using as few security plugins as possible and avoiding overlapping features to prevent potential issues.
143 If you encounter problems, contact our support team for assistance.
144
145 = Does the Personal (Free) plan include a firewall? =
146 No, the free version does not include a firewall. It focuses on vulnerability detection and notifications.
147
148 = Will Patchstack slow down my website? =
149 The free version only runs scheduled tasks, with no noticeable impact on your site speed or server load.
150 The paid version runs tasks on each page load to filter traffic, but our tests and customer feedback confirm minimal performance impact.
151
152 = Does Patchstack work on multisite? =
153 Yes. After installation, you can activate Patchstack per site within the network. Each subsite must be added individually to your Patchstack account and will take one site slot.
154
155 = Where can I learn more about Patchstack? =
156 Visit our [website](https://patchstack.com) and [blog](https://patchstack.com/blog/) for more information.
157
158 = What support options are available? =
159 Patchstack provides chat support via [patchstack.com](https://patchstack.com) and documentation through our [Help Center](https://docs.patchstack.com).
160 To access chat support, click the green chat bubble in the bottom right corner (note: some ad blockers may hide this).
161
162 = How long does it take to set up Patchstack? =
163 Setup takes just a few minutes. Install the plugin, register at [Patchstack App](https://app.patchstack.com/register?free=1), add your site, and paste the API key into the plugin.
164 See our [Getting Started guide](https://docs.patchstack.com/getting-started/start-using-patchstack/) for help.
165
166 = How do I upgrade from the Personal (Free) plan to the Developer plan? =
167 Upgrade through your dashboard at the [Patchstack App](https://app.patchstack.com/login) or directly at [app.patchstack.com/setup](https://app.patchstack.com/setup).
168
169 = Do I need to pay for support? =
170 No, support is free. However, free plan users may receive replies within 1 business day, while paid users typically get responses in under 30 minutes.
171
172 = What information does Patchstack collect? =
173 We take privacy seriously. We sync and store data such as your domains, installed software, and activity logs.
174 For details, see our [Terms & Conditions](https://patchstack.com/terms-and-conditions/), [Privacy Policy](https://patchstack.com/privacy-policy/), and [DPA](https://patchstack.com/data-processing-agreement-dpa/).
175
176 = Where can I find the Terms & Conditions, Privacy Policy, and DPA? =
177 * Terms & Conditions: [patchstack.com/terms-and-conditions](https://patchstack.com/terms-and-conditions/)
178 * Privacy Policy: [patchstack.com/privacy-policy](https://patchstack.com/privacy-policy/)
179 * DPA: [patchstack.com/data-processing-agreement-dpa](https://patchstack.com/data-processing-agreement-dpa/)
180
181 = How can I get a WordPress plugin security audit from Patchstack? =
182 We offer an AI-powered code review tool for plugin audits. Start by joining our [mVDP program](https://patchstack.com/for-plugins).
183 You can also request a manual audit here: [patchstack.com/auditing](https://patchstack.com/auditing/).
184
185 = Where do I report security bugs? =
186 Report security bugs through the [Patchstack Vulnerability Disclosure Program](https://patchstack.com/database/vdp/patchstack). Our team will assist with verification and CVE assignment.
187
188 == Screenshots ==
189
190 1. Patchstack security - be the first to receive notifications of new plugin vulnerabilities
191 2. Patchstack security - automatic protection against ongoing attacks
192 3. Patchstack security - level up your WordPress hardening and tweak the security rules
193 4. Patchstack security - security analytics, detailed periodic reports and activity monitoring
194
195 == Changelog ==
196
197 To view the plugin changelog, go [here](https://docs.patchstack.com/patchstack-plugin/changelog/).