Sign in Start free
Features

Fifteen modules, engineered around one idea: your agency owns everything

Your servers, your storage, your Stripe account, your client relationships, your domain on the portal. WPClientHub is the command center — never the landlord.

Sites · Command center

Every site you manage, sorted by what needs you

One computed health score per site — 0 to 100, from pending updates, backup freshness, offsite coverage, vulnerabilities, uptime, PHP version and SSL — replaces the wall of status icons that stops making sense past twenty sites.

  • Action Inbox aggregates everything that needs attention across every site — open incidents, core and plugin updates, sites never backed up — grouped by module, workable in bulk.
  • Transparent scoring: every number expands into its exact deductions (core −10, a critical vulnerability −10, no offsite copy −10…) — no black-box “site grade”. Recomputed on every event and reconciled nightly.
  • Scale tooling: labels, client grouping, search, health-band filters, list and grid views, worst-first sorting, every filter in the URL, CSV export.
  • One-click login into any wp-admin via single-use, sixty-second signed tokens — logged, and never a stored WordPress password.
app.wpclienthub.com/sites
The site list: fifteen client sites with health scores, pending updates, backup status and incident state, sorted worst-first
Updates · Safe by default

Updates that check their own work

Every scheduled update runs the same loop: a restore point on the site first, then the updates, then a real-browser screenshot diff of the pages you nominated. Under your threshold it ships and logs itself; over it, the batch is held for review with the before/after pair attached and an alert raised.

  • Visual diffs on the pages you choose — homepage, checkout, booking form — captured by headless Chromium at 1366×900, with a per-page breakdown of what moved and a threshold you set (25% by default).
  • Approval queue or auto mode, per site, in the site’s own maintenance window — Tuesday 03:00 site-time, never during launch week.
  • Automatic rollback, if you want it: when a diff exceeds the threshold, the batch’s own pre-update restore point is restored automatically — safety backup first, atomic switch-over — and everyone who would have been paged for the review is told it was rolled back instead.
  • In-row updates with live progress: update one plugin from the pending list or fifty across the fleet; succeeded items slide into “recently updated”, failures turn red with the error and a Retry button.
  • The connector updates itself, in waves: roll a new plugin release to canary sites first, watch, then advance or halt — from the hub, owner/admin only.

Rollback is a per-policy switch, off by default: leave it off and an over-threshold batch stops, keeps the restore point ready and waits for you; turn it on and the site is restored on its own, the batch stays marked for review with the before/after pair and the restore linked, and the alert says which happened.

Read: how safe-update pipelines work
app.wpclienthub.com/updates
Scheduled safe updates: two batches needing attention — one held at a 31% visual diff, one awaiting approval — above the per-site update policies
Backups · Off our cloud

Built on the client’s server. Replicated to yours. Restored in one click.

Every restore point is built on the client’s own server, in a web-denied directory inside wp-content, then streamed to storage you own. WPClientHub receives the manifest, the checksums and the outcome — and not one byte of the archive. There is nothing for us to meter, nothing for us to lose, and nothing to ask us for if you leave.

  • Offsite to your own bucket: S3-compatible (AWS S3, Backblaze B2, Wasabi, Cloudflare R2) or SFTP with a password or SSH key. Every destination is write-tested when you save it; credentials are encrypted at rest and wiped from the job when it finishes.
  • One-click restore from the dashboard: a safety backup of the current state first (the restore aborts if it fails), checksums verified, database imported into shadow tables, files unpacked to staging — then an atomic switch-over. The connector, its keys and the site URL are preserved. Cancel any time before the switch.
  • Database and files, in resumable phases: db → files_scan → files_zip → manifest, each step time-boxed to survive shared-host execution limits, driven by a guarded loopback with WP-Cron as a fallback — a backup finishes even if the hub stops polling.
  • Standalone restore script ships inside every backup set: one PHP file that verifies checksums, extracts, imports the database, can rewrite the site URL, and deletes itself when done — no dashboard required.

Not yet: archives are not encrypted at rest on the destination — your bucket’s own encryption applies. Google Drive and Dropbox are not destinations. Both are on the list; neither is ticked on any tier.

Read: where backups should live
app.wpclienthub.com/sites/ridgeline
A site’s backups tab: the schedule, the offsite destination, and recent restore points with a Restore button on each
Security · Vulnerability-first

Know exactly where you are exposed — and what to do about it

Every installed plugin, theme, and core version on every site is matched on each sync against a live public WordPress vulnerability feed, and the whole fleet is rescanned daily — so “are we exposed anywhere?” is a query, not an audit. Then every finding tells you what to do.

  • One row per finding with severity, CVSS, and the affected range matched to the exact version each site runs — filter by severity and status, search by CVE, sort, export CSV, ignore or resolve in bulk.
  • How to fix, in four parts for every finding: what this is, the recommended fix, how to verify, and what to do if you can’t update today — drawn from the CWE, the CVSS vector and a curated remediation library.
  • Ask AI: is it exploitable on this site, why, what happens if you ignore it, and the mitigations — with a confidence score. One credit; three runs per finding per day; under 50% confidence it says “needs a person”.
  • Hardening checks and login protection: core version, PHP, WP_DEBUG, HTTPS, administrator count, inactive plugins — plus brute-force throttling in the connector, every attempt in the activity log. A check the sync can’t judge is a warning, never a failure.
app.wpclienthub.com/security
Security posture across the fleet: open findings by severity, the sites needing attention first, and the one-row-per-CVE findings list with How to fix, Ask AI and Ignore on every row
Uptime · Confirmed alerts

An alert you can trust at three in the morning

Every site is checked once a minute by a probe that runs outside the app, so an outage of ours can’t look like an outage of yours. A single failed check never pages anybody: an incident opens only when a second check confirms it, and closes itself on the first success with the downtime recorded.

  • Confirmation before escalation — two consecutive failures to open, backdated to the first, so the incident duration is honest rather than flattering. Reminders at 30 minutes, 2, 6 and every 12 hours while it lasts; a recovery notice on the way back.
  • Every period, every number: 24 hours to 12 months or a custom range, with uptime %, total downtime, MTTR, longest incident, average and p95 response time, a per-region breakdown when more than one probe reports, and an SLA target per site (99.9% by default) with a met/missed badge.
  • Fleet view: portfolio uptime, sites with open incidents worst-first, the top ten by downtime, and the sites you forgot to monitor.
  • SSL expiry, keyword and content checks — the page renders what it should, not merely a 200 — plus redirect chain and time-to-first-byte on every check. Incidents export to CSV.

Straight about scale: production runs a single probe region today. The agent is built to fan out and every result is stamped with the region it came from, but alerting relies on confirm-and-recheck, not a region quorum — because we don’t have one yet. Domain-expiry monitoring is on the same list: SSL is live, domain registration is not.

app.wpclienthub.com/uptime
Fleet uptime over 30 days: 99.98% across thirteen monitored sites, no open incidents, and a worst-by-downtime table
Performance · Trends over time

See a site drifting before anyone complains

A page doesn’t get slow overnight; it gets slow over two quarters, and nobody notices until a client does. Turn measurement on per site, run it on a schedule or on demand, and keep the history — so the drift shows up as a line rather than a complaint.

  • Mobile and desktop, every run. Both form factors are measured in sequence — mobile first, because it is the slower one and the one Google ranks on.
  • Lab scores plus real-user field data where Google has enough traffic to report it, so you can tell “slow in the lab” from “slow for actual visitors”.
  • What to fix first, from the run’s own diagnostics, with page weight in requests and bytes.
  • Report-ready: “mobile performance 58 → 84 since March” is a client sentence, and the performance history writes it for you.
SEO Health · Crawler-based

A score you can defend to a client

SEO Health crawls each site the way a search engine does — following its own sitemap and internal links — and checks the on-page fundamentals: titles and meta descriptions, a single H1 with a sane heading order, image alt text, canonical tags, robots directives, broken internal links, and structured data. Everything rolls up into one 0–100 score.

  • Four honest bands: Excellent (90–100), Good (70–89), Needs attention (40–69), Critical (0–39) — a crawl that can’t complete reports the affected checks as skipped, never as a quiet pass.
  • Scheduled, not one-off: weekly on Free, daily from Studio up, plus an on-demand rescan any time.
  • Search Console sync from Studio up adds real query and impression data next to the crawl findings.
  • White-label PDF, from Studio up — your logo and colors, ready to send to a client.
Read the SEO Health doc
app.wpclienthub.com/sites/ridgeline
A site’s SEO Health tab: a score of 78, the four-band gauge, and a checklist of on-page findings by category
AI Visibility · AI-readability

What an AI assistant already thinks about the business

Search is no longer just Google. AI Visibility runs 28 checks for how readable a site is to AI crawlers and assistants — is GPTBot, ClaudeBot or PerplexityBot blocked, is there an llms.txt, does the homepage carry Organization and WebSite schema, are answers direct enough to quote — and can probe real AI assistants with no context fed to them, to see what they already say about the business.

  • 28 checks, same four bands as SEO Health — robots access for the major AI crawlers, llms.txt, schema (Organization, WebSite, Article, FAQ, Breadcrumb), question-style headings, direct answers, visible dates and bylines, thin or JS-only content.
  • The Ask AI probe asks real assistants a set of questions with zero site context — on purpose, to measure what the model already knows — and classifies each answer against the site’s own facts as correct, partial, incorrect, or “doesn’t know”. One credit per probe run.
  • Same schedule as SEO Health: weekly on Free, daily from Studio up, plus on-demand rescans and probes.
  • White-label PDF, from Studio up, alongside the SEO Health report.
Read the AI Visibility doc
app.wpclienthub.com/sites/ridgeline
AI Visibility for a site: score 82, 28 checks by category, and the Ask AI probe’s latest classified answers
Activity Log · Audit trail

Who changed what, and when — on every site

Every change on a client’s WordPress site is recorded the moment it happens, and so is every action your team takes inside WPClientHub — including every help desk reply. One combined history per site, in plain language: where “who changed this?” gets answered, and where a run of failed logins stops being invisible.

  • Entries a client could read: “admin published the post Spring Sale” — with the exact time, the person, their IP address, and the browser they used.
  • Captured automatically: content, plugins, themes, core updates, users and roles, settings, media, store orders, support requests — and every login, successful or failed.
  • One timeline, both sides: what happened on the site and what your team did in WPClientHub share a single feed — per site, and across the whole account.
  • Filter, then export: category, action, person, source, IP, date range, free-text search — then download exactly that view as CSV or JSON. Twelve months of retention.
app.wpclienthub.com/activity
Activity Log with filters for category, event, source, person, date range and IP, export to CSV or JSON, and plain-language rows such as “Dana Whitfield replied on ticket #16” with the time, site, person and IP address
Reports · Proof of work

The monthly report writes itself

Every update, backup, incident, scan, and fix across every site you manage lands in a proof-of-work feed as it happens. The report builder assembles that feed into a branded PDF on whatever schedule you set.

  • Templates decide the sections and their order: updates, backups, uptime, security, performance — summary or detailed, per client.
  • Your brand kit: logo, colors, and the sender name the client sees — and “powered by WPClientHub” is off by default, not a paid upgrade.
  • Schedules per template and site, with the client’s own report recipients; every past run stays under Generated reports, downloadable and re-sendable.
  • Proof-of-work feed means the report is evidence, not marketing — the strongest churn-prevention asset a care plan has.

One detail worth knowing before you sell it: the report email carries your agency’s name in the From line and replies go to your support address, but the underlying sending address is still ours, because that is the domain we are authenticated to send from. Sending from your own domain isn’t built yet.

Read: the checklist clients pay for
app.wpclienthub.com/reports
Client Reports: two templates, scheduled deliveries per client, and the list of generated reports from the last two months
Help Desk · Clients & portal

A front door your clients will actually use

The Help Desk is its own product surface — helpdesk.wpclienthub.com for your team, and a client portal on your domain for theirs — sharing one account, one sign-in and every site fact the rest of WPClientHub already knows. Clients open requests in their own words; you work them with evidence, estimates and a timeline they can follow.

  • Magic-link portal on your domain: no client passwords; a 15-minute single-use link, throttled and enumeration-safe. Add your domain, prove it with a TXT record, and the certificate is issued on first visit. Your name, logo and colour on every page and email.
  • Clients see exactly enough: status, replies, a plain-language “where things stand” timeline, and estimates they approve or decline with one click — never internal notes, agency-only evidence, unsent prices or another client’s data.
  • Work the queue, not the inbox: Needs attention, Mine, Waiting on client; service-level countdowns; assign, reprioritise and resolve in bulk; CSV export; j / k / a / x from the keyboard.
  • Estimates from the diagnosis: line items, assumptions and an ETA drafted from the AI’s priceable hint, sent from the request, expiring in 14 days with a reminder at 48 hours — and “we’ll fix it ourselves” when it’s on you.

Also built in: a docs-backed help chat for your own team with a real handoff to the people who build WPClientHub — the same help desk, pointed at us.

helpdesk.wpclienthub.com
The Help Desk dashboard: twelve requests needing attention, your queue, open requests by client and this week’s AI diagnoses
support.your-agency.com
The client portal: Ridgeline Outfitters’ open requests with plain-language statuses such as Received, Being reviewed and Fix delivered
AI Diagnosis · Evidence, not vibes

Diagnosis with the evidence attached

When a request arrives, WPClientHub reads it alongside the site’s own facts — versions, plugins, recent changes, the activity log — and writes back a probable cause, the evidence, a suggested category and severity, and how confident it is. Below 50% it says “needs a person” rather than guessing. The same engine answers Ask AI on security findings and deep questions in the help panel.

  • One currency, one credit per check: a ticket diagnosis, a re-run, a security Ask AI, a knowledge-base deep answer. Ordinary help-panel answers cost nothing.
  • Charged before, refunded on failure, never queued at zero — and an append-only ledger under Settings → AI usage shows every grant, charge and refund.
  • Included on every plan, topped up when you need more: 20 credits a month on Free, 50 on Studio, 250 on Agency, 1,000 on Scale — plus 100-credit ($9) and 500-credit ($39) top-up packs from Settings → AI usage, spent after your plan credits and never expiring. A banner and an owner email at ten left.
  • Client-safe by construction: the technical diagnosis is agency-only; a plain-language summary can be shared with the client with one toggle, and re-runs are capped at three per request per hour.

Diagnoses run on Anthropic’s Claude models. Your requests and site facts are sent to produce the answer and are never used to train anything.

app.wpclienthub.com/settings/ai-usage
AI usage: 182 of 300 credits left this month, on track, with usage by kind — ticket diagnoses, security Ask AI and knowledge-base answers
Notifications · Slack & webhooks

Tell Slack. Page the on-call. Digest the rest.

Every alert kind — downtime, certificates, failing backups, a connector gone dark, a new request, an estimate decision, the weekly security digest — can go somewhere besides your inbox: a Slack channel, a signed webhook, an outside email address, or a specific teammate, scoped to one client or one site.

  • Routes, not rules: pick the alert, pick the destination, pick immediate or a daily digest, hit Send test. Owners and admins only.
  • Webhooks you can trust: every delivery carries an X-WPClientHub-Signature HMAC over the body with a per-route secret shown once, three retries with backoff, and the last error recorded per route.
  • Slack gets Block Kit — a readable card with the site, the incident and a deep link — not a JSON dump.
  • Personal alerts stay personal: sixteen kinds, one-click RFC 8058 unsubscribe with Undo, every timestamp in your timezone, and a “who gets alerted” roster so you know whose phone lights up tonight.
app.wpclienthub.com/settings/notifications
Notification routes: a #client-alerts Slack channel for downtime and the security digest, a PagerDuty webhook scoped to one client, and a daily digest to an external inbox — plus the who-gets-alerted roster
Billing · Revenue

Care-plan revenue, next to the work that earns it

Client billing runs on your own Stripe account — connected with a restricted API key, no Stripe Connect, no platform in the middle — or with no processor at all. Define products and plans, attach clients and their sites, and let invoices, subscriptions, and dunning run themselves, with an MRR dashboard on top.

  • Your money never touches us. Paste a restricted key from your own Stripe account and everything — customers, subscriptions, invoices, payouts — lives in your Stripe. No Stripe? Invoice directly: bank, ACH, wire, UPI, PayPal or any payment link, and mark invoices paid. No platform fee on any plan.
  • Recurring invoices and a client portal: every subscription raises a numbered, branded PDF invoice each period, emailed to the client and waiting in their portal with a Pay button — Stripe’s hosted page, or your own link and payment instructions.
  • One-time and recurring plans, plan-line or free-form invoices, void, mark paid, change plan — model your real care-plan ladder.
  • Dunning built in: reminders at 3, 7 and 14 days past due, and an opt-in pause of a client’s sites at 21.
  • MRR, active subscriptions, past-due, net billed, revenue by client — twelve months of month-end snapshots, exportable — the agency’s health metrics, always current.
Read: productizing care plans with Stripe
app.wpclienthub.com/billing
Billing overview with $2,340 MRR, nine active subscriptions, one past-due, and the 12-month MRR chart
Team · Roles & 2FA

The whole studio, with the right blast radius

Everything in WPClientHub belongs to an organization, and every person in it has one of four roles. Invite a contractor without handing them the Stripe account; give a client-services lead read access without the ability to push an update at 4 p.m. on a Friday.

  • Four real roles — owner, admin, tech, viewer — enforced on the server, not hidden in the UI. Restores and connector rollouts are owner/admin only; who works the help desk is a per-member toggle.
  • Two-factor authentication with an authenticator app and ten single-use recovery codes — and an owner can require it for the whole organization. Sensitive actions ask for your password again.
  • Sessions you can see and end: device, IP and last active for every sign-in, one click to sign out everywhere else; changing your password does it for you.
  • Invitations that expire in seven days, with one reminder; change a role inline; remove someone and their access ends with the click. Viewers are never paged.
Get started

Every module, on every plan

Every module on every tier — pick a site count, not a feature list. White-label PDF reports, Search Console and on-demand AI scans start on Studio. Free for your first three sites.

No credit card · connect your first site in about a minute