Daily monitoring of your website, with automatic clean-up
Every night we check your website for malicious code and failures. If we find anything, we clean it and email you what we found and what we did. You do not have to do a thing.
An infected website does not look infected
When someone breaks into a website, the last thing they want is for it to show. The page keeps loading as always while whoever got in does as they please: sending spam, showing spam pages to search engines only, or reading your customers' data. Weeks often go by before anyone notices, and by then it is because the domain has landed on a blacklist or because Google is warning visitors.
WebSentinel looks at your site every night, and it does not ask the site whether it is fine: it checks from the outside, from the server, with tests a compromised site cannot fake.
Four steps that happen while you sleep
It checks
Every night your site gets a full check: every file, one by one, looking for malicious code, plus the checks that tell whether the site really works.
It diagnoses
If something odd turns up, the evidence is analysed and a clean-up plan is drawn up saying, file by file, what should be done and why.
It cleans
When the diagnosis is clear, the plan is applied straight away. If there is any doubt, it waits for one of our technicians to review it before anything is touched.
It tells you
You get an email, in your own language, with what was found and what was done. The Control Panel has the site's record and the history of every check.
What it looks at, what it repairs and what it tells you
A daily check for malicious code
Every night the whole site is scanned with the Wordfence engine, looking for backdoors, webshells and injections.
Code hidden inside images
One of the most common hiding places is PHP inside a file that looks like an image, a video or a font. We look there too.
Site failures, not just infections
A blank page, a database connection error or a WordPress critical error: they are spotted and we try to repair them.
Content hidden from search engines
We compare what a visitor sees with what Google receives. A hijacked site often shows its spam only to search engines, and that is how it gets caught.
Security plugins switched off
Having one installed is no use if it is switched off. If that happens, we let you know.
WordPress and plugins kept up to date
The core and the plugins are updated automatically, always with a database backup taken first and a roll-back if the site breaks.
Automatic clean-up
Whatever is found does not wait to be reported: it is cleaned and the site is checked again straight afterwards to confirm it came out clean.
Quarantine, never deletion
Everything removed is kept for six months in a store outside your web space, in case anything needs to come back.
New passwords when they are needed
If the diagnosis concludes that the credentials have been compromised, we renew those of the site, the database and FTP, and send them to you.
Touching a site that works is the real risk
A badly done automatic clean-up can cost more than the infection itself. That is why the service is built the other way round from what seems natural: what decides and what executes are two separate things, and everything it touches can be undone.
- Nothing is ever deleted: whatever is removed goes to a quarantine outside your space, and stays there for six months.
- Your site's configuration files (wp-config.php, .htaccess, .user.ini, php.ini and robots.txt) are never touched.
- A database backup is taken before any update, and if the site stops responding the change is undone.
- The analysis is done by an artificial intelligence with no access whatsoever to your server: it receives text and returns a plan. What writes to disk is our own program, with a closed catalogue of permitted actions.
- Diagnoses that are not clear enough, and any that involve changing passwords, are approved by a person before being applied.
- The engine uses no administrative credentials over your data: it works with least-privilege accounts.
Bought by volume, switched on site by site
The price is per customer, not per individual site: you buy, once, the number of sites you want to be able to protect, and then switch them on from the Control Panel one at a time, up to the limit. Switching a site on while you have free slots costs nothing extra, and you can free a slot up when you stop looking after that site.
WebSentinel Single
1 websiteFor anyone with a single website who wants it watched over.
- A daily check on every protected site
- Automatic clean-up and quarantine
- WordPress and plugins kept up to date
- Email report and history in the Panel
- An on-demand check whenever you need one
WebSentinel 30
30 websitesFor small agencies and anyone running a handful of projects.
- A daily check on every protected site
- Automatic clean-up and quarantine
- WordPress and plugins kept up to date
- Email report and history in the Panel
- An on-demand check whenever you need one
WebSentinel 250
250 websitesFor agencies with an established client base.
- A daily check on every protected site
- Automatic clean-up and quarantine
- WordPress and plugins kept up to date
- Email report and history in the Panel
- An on-demand check whenever you need one
WebSentinel 500
500 websitesFor anyone running a large estate of client websites.
- A daily check on every protected site
- Automatic clean-up and quarantine
- WordPress and plugins kept up to date
- Email report and history in the Panel
- An on-demand check whenever you need one
A single customer can spread the slots across all the sites they host with us. If you are an agency or a reseller, the slots in your volume can be used on your own clients' sites: the volume is bought once on your account and you bill it on however you like.
Prices exclude VAT. The annual payment is the equivalent of ten months: two months free. No lock-in: you can stop the service whenever you want.
WebSentinel works from the server where the site lives, so it can only be switched on for sites hosted at Intergrid. If yours is with another provider, we will migrate it at no cost: Services Migrator
Already a customer? You can switch it on from the Control Panel, in the applications section of each domain. Login
Questions about your site's security
How is WebSentinel different from a security plugin such as Wordfence?
My site is not WordPress. Is it still useful to me?
Who decides what gets deleted from my site?
Could it break my site?
How will I know what happened?
How do I buy it and how do I switch it on?
Can I protect a site hosted with another provider?
Leave your website watched over
Tell us how many sites you want protected and we will switch them on for you. If you are not sure where to start, we will run a check on your site and explain what we found.
Request more information