Stop guessing which client site needs attention. WP Triage scores every site, surfaces the top three issues, and tells you what to fix first.
The agency problem
You manage dozens of WordPress installs. CVEs drop weekly. Plugins go unmaintained. PHP versions drift. Client sites do not fail on a schedule — but when they do, it is your reputation on the line.
Security plugins and management dashboards give you more information. What agencies need is a priority list: which site is most exposed right now, and what is the single next fix that reduces risk fastest?
Without that list, maintainers either over-update everything (wasted hours) or under-react until something breaks. WP Triage exists to close that gap: a decision engine for the portfolio, not another place to stare at raw alerts.
Weekly triage workflow
- Monday: Open your site list sorted by risk score. Start with Critical and At Risk sites.
- Per site: Read the top three issues and fix order — patch the RCE before the unmaintained sidebar widget.
- During the week: Rely on alerts only for critical vulnerabilities and sudden score drops — not every plugin update notification.
- Friday: Review the weekly digest — what changed across the portfolio and what carries into next week.
That cadence fits retainer work: a predictable block of security triage each week, instead of interrupt-driven firefighting every time a CVE newsletter lands in the inbox.
What you see for each client site
Every connected site always resolves to the same shape of output:
- Risk score (0–100) with a band: Safe, At Risk, or Critical — so the portfolio list sorts itself
- Top three issues — the only items that belong in digests, site lists, and emails
- Recommended fix order — first, second, third — so juniors and seniors share the same plan
- Full ranked inventory on the site detail page when you need depth for a ticket or client note
Recurring false positives or accepted risks can be suppressed per site or account-wide, so the score stays useful instead of noisy. See suppressing findings.
Why agencies choose WP Triage
- Portfolio view — every client site scored 0–100 in one list
- Actionable output — top three issues and fix order per site, not raw scan dumps
- Quiet alerts — critical CVEs and score drops only; no inbox spam
- Works with your stack — keep Wordfence, MainWP, Patchstack, or host tools for execution; use WP Triage to decide order. Compare the fit.
- Simple pricing — pay for the sites you monitor, from $9/mo
What it is not
WP Triage is intentionally narrow so it stays cheap to run and easy to adopt:
- Not a remote WordPress admin or bulk-update console
- Not a firewall, malware scanner, or backup product
- Not a client-facing white-label portal (use your existing reporting for that)
If you need perimeter defense, use a WAF/scanner on the site. If you need remote updates, use a management dashboard. Use WP Triage when the question is: which site, which issue, in what order?
Onboarding a client portfolio
- Create an account and generate one agent key for your agency.
- Install the Triage Agent Connector plugin on each client site and paste the same key.
- Sites register automatically; daily snapshots start scoring the portfolio.
- Suppress known noise once, then run the Monday triage loop above.
Most agencies can connect a first batch of sites in a single sitting. Full setup detail is in the connecting WordPress guide.
Pricing for agencies
- Starter — $9/mo · 1–5 sites · For freelancers and solo operators getting started with risk triage.
- Pro — $29/mo · 6–25 sites · For growing agencies that need triage across a full client portfolio.
- Agency — $49/mo · 26–50 sites · For established agencies managing dozens of WordPress installs.
One prevented hack pays for a year.
Get started
Install the Triage Agent Connector plugin on each client site, paste one agent key, and your portfolio appears in minutes. Learn more about WordPress risk scoring or how scores are calculated in the scoring methodology.
Get started