
Patchstack Add-on Blocks 11.9M Threats for ManageWP
Patchstack's add-on for ManageWP blocked more than 11.9 million threats in six months, the company reports.
ManageWP and Patchstack report that the Patchstack-powered Vulnerability Protection add-on blocked more than 11.9 million threats across protected WordPress websites in six months. The figure comes from a case study published by Patchstack on August 24, 2026, and it quantifies what the two companies describe as a portfolio-wide security answer for agencies that manage many client sites at once.
The context behind the number is important for any website owner. Patchstack notes that attackers weaponize the most-targeted vulnerabilities in a median of five hours, and that nearly half of those vulnerabilities have no update available at the moment they become public. On top of that, the WordPress.org "Protect the Shire" policy, live since June 2026, adds up to a 24-hour hold on every plugin and theme release before it reaches sites. That delay is meant to give the WordPress ecosystem time to review code, but for an agency it also means a known weakness may remain unpatched on live sites for longer. According to the case study, this combination of quick attacker action and slow update availability creates a gap that manual updating cannot close alone.
The solution described in the case study is a native add-on inside the ManageWP dashboard. Patchstack has been powering ManageWP's Vulnerability Protection since February 2026. Once the add-on is enabled, agencies can see every client site's vulnerability exposure in one view and turn on protection across the whole portfolio. There is no need to log into each site separately, no code changes on the client sites, and no waiting for an update to ship. The case study also shows that vulnerability protection appears as part of ManageWP's checklist-style navigation, so it becomes a routine part of the agency workflow rather than a separate security tool.
ManageWP and Patchstack explain that when a vulnerability is identified, mitigation rules are applied automatically to every protected site. Those rules close the gap before a patch exists or before a patched plugin or theme clears the WordPress.org review window. The result, according to the case study, is that over six months Patchstack blocked more than 11.9 million threats across sites protected through the ManageWP add-on, and none of those protected sites needed an emergency update or a manual patch. The case study lists three concrete outcomes: more than 11.9 million threats blocked, zero code changes on any protected client site, and one dashboard view replacing site-by-site triage.
Predrag Zdravkovic, identified in the case study as representing ManageWP, frames the partnership as a shift from vulnerability visibility to protection at scale. He says agencies need more than a list of problems; they need proactive security that works across every client site. The quote in the article states that by partnering with Patchstack, ManageWP gives its customers proactive security directly inside the ManageWP dashboard, helping them stay ahead of emerging threats across their entire portfolio, and that blocking more than 11.9 million threats in six months proves what is possible when security is built into the workflow.
The case study closes with a forward-looking note. For ManageWP users, the expectation is fewer emergency tickets and fewer client calls about hacked sites, because protection covers the whole portfolio rather than only the sites someone remembered to update. The two teams say they are working closely to swap notes, test edge cases, and meet in person to make preventive security work. For website owners and agencies that manage multiple WordPress sites, the underlying lesson is that real-time vulnerability protection can reduce the window between disclosure and attack. Readers who manage their own WordPress hosting may also want to review their hosting environment; services like AEU Hosting provide managed WordPress hosting with security measures built in, which can complement a dedicated vulnerability protection add-on.
How to Protect Yourself
- Turn on automatic updates for WordPress plugins and themes, and apply core updates as soon as they appear.
- If you use ManageWP, enable the Vulnerability Protection add-on in the dashboard so it blocks known attack patterns across all your sites at once.
- Use a security plugin or firewall service that can block malicious requests before they reach your website.
- Back up your website regularly and store the backup somewhere separate, so you can restore it quickly if something goes wrong.
- Protect every administrator account with a long, unique password and two-factor authentication, which asks for a second code when you log in.
Terms Explained
- ManageWP A central dashboard service used to manage many WordPress websites at once.
- Patchstack A security service that provides real-time threat blocking for WordPress websites.
- Vulnerability Protection add-on An optional feature inside ManageWP that automatically blocks known attack patterns.
- Mitigation rules Automatic instructions that stop specific malicious requests from reaching a website.
- WordPress.org review window The 24-hour delay before a plugin or theme update is made available, meant to allow time for review.
- Portfolio All of the client websites an agency manages together.