Siteward

وەسف

Siteward is a lean, self-hosted dashboard to manage multiple WordPress sites from one place, a no-bloat way to monitor uptime, run fleet-wide core, plugin and theme updates, watch UpdraftPlus backups and WP-Cron health, and catch critical errors across every site you maintain. It’s a free, unlimited-site alternative to hosted maintenance services, with no per-site fees and no third-party cloud: you own the control panel.

Install it on one central WordPress site, add the free Siteward Child plugin to each site you manage, and connect them with a one-time secure handshake. Then manage everything from your dashboard:

  • Vulnerability monitoring: every installed plugin, theme and core version is checked against a live feed of known vulnerabilities, with severity, CVE and the version that fixes it. Free, no API key, no account.
  • Uptime monitoring: each site is checked on a schedule; retry-then-alert avoids false alarms, and you get an email the moment a site goes down or recovers.
  • Fleet-wide updates: see every pending core, plugin and theme update in one place and apply them one-click or in bulk, with a live progress view.
  • Critical-error detection: catches HTTP 5xx errors and the WordPress “critical error” white screen.
  • Backup monitoring: see each site’s latest UpdraftPlus backup and get alerted when backups are missing, stale, or failing.
  • WP-Cron & health flags: surfaces overdue cron events, recovery mode, plugins/themes auto-paused after a fatal error, and Site Health critical issues.
  • Secure & self-hosted: the dashboard initiates all traffic; every request is signed with an OpenSSL keypair and protected against replay. Your data never routes through a third-party cloud.

Every feature above is fully functional and free. Unlimited managed sites. No per-site fees.

Full feature list, screenshots and setup guides: omniswp.com

Siteward Pro (optional, sold separately): an add-on that adds fleet plugin management (bulk activate, deactivate, install and uninstall plugins across sites), SSL certificate & domain-expiry monitoring, a Dynamic Notification Engine that groups a whole server’s outage into a single alert, and Zapier webhook notifications.

External services

This plugin downloads a vulnerability data feed so it can tell you which of your managed sites are running software with a known vulnerability.

The feed is fetched from https://omniswp.com/wp-json/omnis-updates/v1/vulnerabilities (and a small /vulnerabilities/meta document used to check whether the feed has changed since the last download). It is requested twice a day, and when you press “Refresh & rescan” on the Vulnerabilities screen.

These are plain downloads. No data about your dashboard, your managed sites or the software installed on them is sent. The request carries no identifier of any kind, and the matching between the feed and your sites happens entirely on your own server.

The feed is built by Siteward from the Wordfence Intelligence vulnerability database, provided by Defiant, Inc., and redistributed under its terms. Wordfence’s terms of service: https://www.wordfence.com/terms-of-service/ Wordfence Intelligence terms and conditions: https://www.wordfence.com/wordfence-intelligence-terms-and-conditions/ omniswp.com privacy policy: https://omniswp.com/privacy/

Vulnerability records that originate with MITRE carry MITRE’s copyright notice, and records from Defiant carry Defiant’s; both are displayed on the Vulnerabilities screen, as their licences require.

If you would rather the plugin never made this request, do not open the Vulnerabilities screen and remove the omnis_vuln_refresh scheduled event; no other feature of the plugin contacts an external service.

سکرین شۆتەکان

دامەزراندن

  1. Upload the siteward folder to /wp-content/plugins/, or install it from the Plugins screen.
  2. Activate the plugin through the Plugins screen.
  3. Open the Siteward menu and choose Add Site.
  4. On each site you want to manage, install and activate the free Siteward Child plugin (search “Siteward Child” under Plugins Add New, or https://wordpress.org/plugins/siteward-child/). On that site, open Settings Siteward Connection, copy its REST URL and one-time connection key, and paste them into Add Site.
  5. (Recommended) Add a real server cron for accurate scheduled checks, the dashboard shows the exact line to add.

پهد

Where does the vulnerability data come from, and does it cost anything?

It is built from the Wordfence Intelligence vulnerability database and served by Siteward. It costs nothing and needs no API key or account: you do not have to sign up with anyone or paste a licence key. Your dashboard downloads the same public feed everyone else does and does the matching locally, so nothing about your sites is sent anywhere.

A plugin I just licensed is not showing an update. Why?

Sites answer from a cached update check that can be up to twelve hours old, and premium plugins only report an update when their licence is active at the moment of that check. So a licence you have just bought or renewed will not appear until the cache expires. Use “Check for updates” on the Updates screen to make every site ask its licence servers again straight away. That needs Siteward Child 0.7.5 or newer on the managed site.

Do I need another plugin on the sites I manage?

Yes. Install the free Siteward Child plugin on each managed site and connect it to this dashboard.

Is there a limit on how many sites I can manage?

No. The free dashboard manages unlimited sites.

How are connections secured?

The dashboard generates an RSA keypair and signs every request. Each child site verifies the signature, rejects stale timestamps and blocks replayed requests.

Does it detect outages even if WordPress is down?

Yes. Uptime checks hit each site’s public URL directly, so a full outage is caught even when WordPress is unreachable.

What does Siteward Pro add?

Backup, WP-Cron and health monitoring are all included free in Siteward. Siteward Pro is an optional, separately-distributed add-on that adds fleet plugin management (bulk activate, deactivate, install and uninstall plugins across sites), SSL certificate & domain-expiry monitoring, a Dynamic Notification Engine that sends one alert when a whole server goes down instead of one per site, and Zapier webhook notifications.

پێداچوونەوەکان

تەممووز 5, 2026
At my agency we’ve been trialling Siteward in it’s development phase and it’s been outstanding. We’ve struggled to find a tool that helps us properly manage our clients sites in the past; trialling MainWP, WPUmbrella, and ManageWP; all of which fell short of the mark. Being in active development, Jason at Siteward is responsive to feedback and actually uses the tool regularly, meaning it’s constantly improving as the featureset becomes richer.I look forward to seeing what’s next, and I would recommend Siteward to any agency or freelancer that looks after multiple client sites on a regular basis.
خوێندنەوەی 1 پێداچوونەوە

بەشداربووان و گەشەپێدەران

“Siteward” نەرمەواڵەیەکی سەرچاوە کراوەیە. ئەم کەسانەی خوارەوە بەشدارییان تێدا کردووە.

بەشداربووان

“Siteward” وەربگێڕە بۆ زمانەکەی خۆت.

دەتەوێت بەشداربیت لە گەشەپێدان؟

گەڕان لە کۆدەکەدا بکە، سەیری تەمارگەی (SVN) بکە، یان بەشداربە لە ڕووداوتۆماری گەشەپێدان لە ڕێگەی (RSS).

ڕووداوتۆمارگەریی گۆڕین

0.12.0

  • New: a “Check for updates” button on the Updates screen. Sites normally answer from a cached check that can be up to twelve hours old, and a premium plugin whose licence was just renewed keeps reporting no update until that cache expires. This makes every site ask its licence servers again and reports what turned up. Needs Siteward Child 0.7.5 on the managed site; older children are counted and named as unsupported rather than failing.

0.11.1

  • Fix: syncing a single site now re-reads its installed plugins and themes, not just its status. Updating a plugin and pressing Sync used to leave the vulnerability list quoting the version that had just been replaced, because plugin versions come from a separate check that Sync did not trigger.
  • Fix: “Refresh & rescan” on the Vulnerabilities screen now collects any site whose software list has gone stale before rescanning, instead of rescanning against old data.

0.11.0

  • New: a vulnerability feed interval, with the last fetch and next check shown beside it, so you can see how current the data is rather than guessing.
  • New: an update timeout setting. A site carrying a lot of plugins can take longer to work through an update run than the fixed three minutes allowed before, and would report “timeout reached” for updates that actually applied. Raise it under Settings, Monitoring.
  • Change: add-ons now render their own settings cards rather than appending controls to the Notifications card.
  • Change: dropdowns on the Settings screen now match the other fields.

0.10.12

  • Change: the reports add-on now uses the same field styling as the Settings screen throughout, on the site list as well as the editing panel, and its site picker sits in its own stacked row.

0.10.7

  • Fix: the software inventory behind vulnerability matching was never refreshing on schedule. Its staleness check converted a stored local time incorrectly, so east of UTC every inventory looked brand new for ever. A site that patched a vulnerable plugin could keep showing that vulnerability indefinitely, and a newly installed one would go unnoticed.
  • Fix: applying an update now re-reads that site’s installed software straight away, instead of leaving the dashboard’s record up to six hours out of date.

0.10.6

  • Change: styling for optional Pro add-on cards, so they match the rest of the dashboard rather than looking like stock WordPress admin.

0.10.5

  • Fix: sites running a child older than 0.7.4 were being marked as having a connection error, which removed the “Log in to WP Admin” button from their row and raised a false health flag. The theme inventory added in 0.10.0 asks for something older children do not answer, and that answer was being treated as an unreachable site. Inventory checks no longer decide whether a site is reachable; the status sync does, as before. Affected sites correct themselves on the next sync.

0.10.4

  • Change: on the Updates screen, the search box now searches whatever the current tab is a list of. On “By plugin / theme” it finds the plugin or theme; on “By site” and “WordPress” it finds the site. It previously searched site names on every tab, including the one that groups by plugin.
  • Fix: the WordPress core tab ignored the search box entirely.

0.10.3

  • New: email alerts when a new vulnerability is found on a site, with its own toggle under Settings, Notifications. Only genuinely new findings alert, and the first scan after upgrading seeds quietly rather than emailing you about every vulnerability at once.
  • New: “Known vulnerability” is now one of the status filters on the Sites overview.
  • Fix: site names containing an ampersand or a quote arrived HTML-encoded in alert emails, so a client name read as markup instead of text. Affected every alert type, not just the new one.

0.10.2

  • Change: the Vulnerabilities screen now lists each affected site once, not once per advisory. A plugin with sixteen advisories on thirty sites was rendering as hundreds of rows when it is really one update.
  • Change: advisory detail is collapsed behind a chevron, with a summary line (“16 known vulnerabilities, 4 critical, 8 high, 4 medium”) on the outside. The detail is all still there, one click away.
  • Change: “Update to” now shows the single version that clears every vulnerability found on that site, rather than the fix for one of them.
  • New: known vulnerabilities are listed on the individual site page, with the same collapsible detail.

0.10.1

  • Performance: a fleet-wide vulnerability rescan re-read the whole stored feed once per installed plugin. On a 50-site fleet that was 70 seconds of pure overhead; it is now under a second.

0.10.0

  • New: Vulnerability monitoring. Every plugin, theme and WordPress version across the fleet is matched against a feed of known vulnerabilities, grouped by item (what to fix and everywhere it is installed) or by site, with severity, CVE and the version that fixes it.
  • New: a “Known vulnerability” health flag on the Sites overview, so an exposed site stands out without opening the new screen.
  • Free, with no API key, no account and no per-site fee. Nothing about your sites leaves your server: the feed is downloaded and matched locally.

0.9.28

  • Fix: some plugins and themes put HTML into the version they report (for example a “validate your licence” link). The Updates screen and site pages now show just the version number instead of a wall of raw markup.

0.9.27

  • Fix: the “Update all” button on the Updates page said “Select at least one update first” instead of running the updates, unless the “By site” tab happened to be open.

0.9.26

  • Added an internal hook (omnis_should_notify) so add-ons can suppress a notification per site. Powers Siteward Pro’s new per-site “pause notifications” control.

0.9.25

  • New: tags. Create colour-coded labels in Settings, assign them to sites, then filter the overview by tag with Is / Is-Not conditions — for example, “Sync all” everything except sites tagged “Do not update”. Bulk actions now run on whatever the overview is filtered to.
  • Tags: create a tag inline while assigning it on a site’s page, and apply (or remove) a tag across every site currently shown in one action.
  • Site pages now show the server IP each site reports (companion plugin 0.7.3+), flagging private/internal addresses so you know which to group by hand.
  • Overview: filter sites by status (Down, Connection error, Updates available, Backup issues, and more) from a dropdown next to the search, each showing a live count.
  • Fix: “Sync all” now shows each site’s real result — a green tick only when the site is healthy, amber with the reason when it synced but still has an issue (down, backup failing, etc.), and red when the sync failed. Previously every site showed a green tick regardless.
  • “Recover plugins” moved to Settings Maintenance, so the overview toolbar stays focused on day-to-day work.
  • The Updates page can now be filtered by tag (and searched), so you can bulk-update a scoped set — for example, update every site except those tagged “Manual update only”.
  • Optionally show tags on the sites overview (toggle in the Tags filter), so you can see each site’s tags — like which server it’s on — at a glance.

0.9.10

  • Housekeeping: the plugin author now links to omniswp.com. No functional change.

0.9.9

  • Each managed site now records which companion plugin it runs, so the dashboard knows what that site supports. No visible change on its own.

0.9.8

  • Siteward Child is now on WordPress.org, so the setup steps and the companion-plugin notice point there instead of to a manual download. Install it on each managed site from Plugins Add New.

0.9.7

  • Added an internal hook so add-ons can group related uptime alerts (for example, collapsing a whole server’s sites into one notification). No change on its own; behaviour is identical without the Pro add-on.

0.9.6

  • Bulk actions (updates, Sync all, Recover plugins) now run as many sites in parallel as your Concurrent requests setting allows, instead of a fixed few.

0.9.5

  • “Sync all” now also retries any site showing a connection error, so a site that briefly fell offline self-heals on the next sync instead of needing a separate resync.

0.9.4

  • Clearer, larger search icon on the sites overview.

0.9.3

  • Added a dismissible notice pointing to the companion Siteward Child plugin download while it awaits WordPress.org approval.

0.9.2

  • Settings Maintenance: “Resync all sites now” button that refreshes every paired site, including any showing a stale connection error.

0.9.1

  • Fix: align the Cancel button in the update-progress modal header.

0.9.0

  • Backup monitoring (UpdraftPlus), WP-Cron health, and health flags (recovery mode, auto-paused extensions, Site Health) are now built in and fully free.
  • Backup/cron alerting and per-flag thresholds added to Settings.
  • Hardened input sanitization on settings save and bulk updates.

0.8.0

  • Public release: unlimited-site monitoring, fleet updates, critical-error detection, and one-click admin login to managed sites.