
Patchstack Add-on Blocks 11.9M WordPress Threats for ManageWP
Patchstack's vulnerability protection add-on blocked more than 11.9 million threats across ManageWP sites in six months without code changes.
Patchstack reported on August 24, 2026 that its vulnerability protection technology, delivered as a native add-on inside the ManageWP dashboard, blocked more than 11.9 million threats across websites managed through ManageWP over six months. The figures cover a partnership that has been live since February 2026, according to the case study published by Patchstack. ManageWP is a remote management tool for WordPress sites, and the add-on gives agencies a single place to see security exposure across every client website and turn on protection for the entire portfolio at once. In this context, a vulnerability is a weakness in software that attackers can exploit to break in or cause damage.
The case study argues that software updates alone are not enough to close the window between disclosure of a vulnerability and an available fix. According to Patchstack, attackers weaponize the most-targeted vulnerabilities in a median of five hours, meaning half of those flaws are turned into working attacks within five hours of disclosure. In addition, nearly half of newly public vulnerabilities have no update available at the moment they become public. WordPress.org's "Protect the Shire" policy, live since June 2026, adds up to a 24-hour hold on every plugin and theme release before it reaches sites. For a site owner, that sequence means a known weakness can remain open for hours or days even when a fix is being prepared, because the fix itself may be delayed by the review process.
The solution described in the case study is a vulnerability protection add-on that sits inside the existing ManageWP dashboard. Because it is native, it does not require a separate login or a second tool. Once a user opens the ManageWP dashboard, key vulnerability information is visible across all the sites being secured, which helps staff decide what to work on first. Protection can be turned on across the whole portfolio at once, with no per-site logins and no code changes. The case study also says that mitigation rules are applied automatically to each protected site the moment a vulnerability is identified. Those rules are automatic instructions that block traffic matching known attack patterns, and they work before a patch exists or before a fix clears WordPress.org's review window. The protection also appears as part of ManageWP's checklist-style navigation, making it an ordinary step in an agency's workflow rather than an extra task outside the usual process.
The headline number in the case study is not a small pilot: Patchstack blocked more than 11.9 million threats in six months across sites protected through ManageWP's Vulnerability Protection add-on. According to Patchstack, not one of those protected sites required an emergency update or a manual patch, and no code changes were made on any protected client site. Instead of triaging each client site separately while an attack clock runs, agencies get one dashboard view across the full client portfolio. ManageWP's Predrag Zdravkovic frames the result as evidence that proactive security inside the ManageWP workflow can stay ahead of emerging threats across an entire portfolio. The case study states that blocking more than 11.9 million threats in six months shows what is possible when security is built into the workflow.
For a single website owner, the same principle applies even without a multi-site dashboard. A vulnerability can be publicly known before a patch is ready, and attackers can begin probing for it immediately. Protection that blocks known attack patterns without requiring a code change can therefore reduce the window during which a site is exposed. The ManageWP numbers illustrate how many attack attempts a portfolio can face, but the underlying issue is the same for one site: waiting for an update may not be fast enough on its own.
For agency owners, the practical payoff described by Patchstack and ManageWP is fewer 2 a.m. support tickets and fewer client calls about a hacked site. Protection covers the whole portfolio rather than only the sites someone remembered to update. The two companies say their teams are working closely to exchange notes, test edge cases, and meet in person to improve preventive security. Patchstack's case study ends by suggesting that agencies can turn client maintenance plans into a secure, high-converting add-on and encourages interested readers to contact Patchstack for details. For website owners and agencies evaluating portfolio-wide WordPress security, a managed WordPress hosting service such as AEU Hosting is designed to handle WordPress security end to end, which can reduce the number of separate tools a team has to monitor.
How to Protect Yourself
- If you manage several WordPress sites from one tool, look in its settings for a security or vulnerability add-on and switch it on for every site at once.
- Turn on automatic updates for your WordPress core, themes, and plugins so you receive fixes as soon as they are released.
- Keep a recent backup of your website stored somewhere separate from your hosting account, and test that you can restore from it.
- Use a long, unique password for your WordPress admin account and enable two-step login to stop attackers who try stolen passwords.
- Remove any plugins or themes you no longer use, because unused add-ons are a common way attackers get in.
- If your website dashboard shows a warning that a plugin or theme has a known security flaw, update it immediately or remove it until a fix is available.
Terms Explained
- Vulnerability A weakness in software that attackers can use to break into or damage a website.
- Add-on An extra feature that can be switched on inside an existing tool without installing a separate program.
- Patch A small update from a software maker that fixes a security hole or bug.
- Dashboard A single screen in a web tool where a user can see and control many things at once.
- Portfolio All the websites a person or agency manages for different clients.
- Mitigation rules Automatic instructions that block traffic from known attack patterns before a fix is available.