Features

Everything you need to operate WordPress at scale.

70+ features designed to eliminate every failure mode in WordPress operations. Verified backups, real monitoring, automated security, and operational tooling — in one platform.

Backup & Recovery

Backups you can actually trust.

Every backup is verified by restoring it in an isolated Docker container. You never have to wonder if a restore will work.

Monitoring

Monitoring that checks the actual application.

Beyond simple pings. BlockForge validates that your WordPress sites actually work — content, SSL, performance, and error logs.

Real Uptime Monitoring

Multi-region checks from Frankfurt, Amsterdam, and New York. 1-minute intervals. Response time tracking with min, max, and average. Uptime percentage over 24h and 30d.

HTML Verification

Every check validates the actual HTML response — not just the HTTP status code. Detects white screens, PHP fatal errors, and broken layouts that return 200.

Expected Title Verification

Configure the expected page title. If it changes — defacement, error page, or plugin conflict — BlockForge catches it immediately.

SSL Monitoring

Certificate expiry tracking with countdown alerts. Chain validation, protocol version checking, and multi-region SSL verification.

Multi-Location Probes

Monitoring from 3+ global locations simultaneously. Detect regional outages and CDN issues that single-region monitoring misses.

PHP Error Monitoring

Track errors, warnings, and notices across all sites. Severity classification, read/unread status, and error statistics from one dashboard.

Debug Log Control

Toggle WordPress debug mode remotely. View, download, and clear debug logs without SSH. Real-time polling for new entries.

Cron Job Monitoring

List all scheduled WordPress cron jobs. Create, delete, enable, or disable crons. Trigger manual execution on demand.

Broken Detection

Automatically detect when a site is broken — white screen, database errors, or plugin conflicts. Instant alerts with diagnostic context.

Performance Monitoring

Continuous response time tracking, trend analysis, and performance threshold alerts. Spot degradation before users notice.

Lighthouse Integration

Google PageSpeed API integration. Desktop and mobile scores. Core Web Vitals — FCP, LCP, TBT, CLS, Speed Index, TTI.

Domain Expiry Monitoring

Track domain registration expiry dates with countdown alerts. Get notified 14 and 7 days before expiration to prevent accidental lapses.

Change Detection

Detect external changes made outside BlockForge — new users, plugin installs, setting changes, and core updates. Heartbeat monitoring with critical push alerts.

AI-Assisted Diagnostics

AI-powered analysis of PHP errors and debug logs. Automatic root cause identification, fix suggestions, and severity classification with sensitive data scrubbing.

Notification Rules

Per-site alert configuration via email and Slack. Event-specific rules for backups, downtime, security, and updates. Deduplication for alert fatigue.

Security

Comprehensive security visibility.

Detect vulnerabilities, monitor file changes, scan for malware, and track configuration drift across every WordPress installation.

Plugin Vulnerability Checks

Continuous scanning of all installed plugins against known CVE databases. Severity ratings with CVSS scores and remediation guidance.

Theme Vulnerability Checks

Scan active and inactive themes for known vulnerabilities. Cross-reference with CVE databases for every theme version.

Core Vulnerability Checks

WordPress core version monitoring against known vulnerabilities. Alerts when your core version has published security issues.

File Integrity Monitoring

Core file checksum verification against WordPress.org originals. Plugin integrity checks. Modification tracking with exclusion lists.

Malware Checks

Pattern-based malware scanning with signature database. Detects backdoors, injected scripts, and obfuscated code across all installations.

Snapshot System

Point-in-time security snapshots of your entire WordPress configuration. Compare snapshots to detect drift and unauthorized changes.

WordPress Config Snapshot

Track changes to users, roles, permissions, and plugin settings over time. Per-plugin snapshot tracking with change history.

Key Rotation

Automated WordPress security key and salt rotation. Configurable intervals with rotation history. Invalidates all existing sessions.

Security Checks

File permission audits, security hardening verification, and configuration best-practice checks. Automated detection and one-click fixing.

Plugin Code Safety Check

8-category static analysis before every update: malware patterns, SQL injection, code injection, input validation, external connections, file integrity, CVE lookup, and checksum verification. Results cached globally — scan once, apply everywhere.

Site Health Score

Aggregated health score per site based on 6 categories: updates, security, backups, uptime, SSL, and vulnerabilities. Displayed on site overview and detail pages with critical filter.

Security Posture Dashboard

Workspace-wide security overview. Aggregated vulnerability counts, compliance scores, SSL status, and security trend charts across all managed sites.

WordPress Management

Full remote control over every site.

Manage plugins, themes, core, database, and settings from one dashboard. No wp-admin logins required.

Global Updates Center

See all available plugin, theme, and core updates across every site in one view. Select, batch-update, and rollback with per-site progress tracking, backup toggles, and code safety verification.

Remote WordPress Control

Configure auto-updates, admin UI, editor settings, security hardening, and frontend features remotely. All settings synced directly to WordPress.

Plugin Management

View, activate, deactivate, update, delete, and upload plugins. Bulk actions for batch operations. Version history with rollback support. Quick backup before every update.

Theme Management

View, activate, update, and delete themes. Child theme creation with auto-generated functions.php and style.css. Safe updates with rollback.

Core Updates

One-click WordPress core updates. PHP version display, server software info, and database details at a glance.

Maintenance Mode

Toggle maintenance mode remotely. Customize page content, colors, and CSS. Manage allowed IPs for bypass access. Tabbed settings for full control.

Database Optimization

Clean post revisions, spam, trash, and expired transients. Preview impact before execution. Scheduled maintenance with cleanup history.

Search & Replace with Backup

Database-wide search and replace with serialization support. Automatic backup before every operation. Dry-run preview before committing.

File Editor

Edit wp-config.php and .htaccess directly from BlockForge. Content validation, version history, and instant restore to previous versions.

WP Auto-Login

One-click login to any WordPress admin panel. Secure, token-based authentication — no passwords needed. Jump straight into wp-admin.

Safe Update Workflow

Backup before update, apply update, verify site health, auto-rollback on failure. Per-plugin safe mode toggle. Notification on every automatic rollback.

Maintenance Windows

Schedule maintenance windows for updates and operations. Automatic maintenance page activation during the window. Configurable duration and recurrence.

Site Onboarding

Onboard entire servers in minutes.

Three ways to add sites — SSH discovery, bulk import, or CSV upload. From one site to hundreds in a single operation.

Team & Organization

Built for teams and agencies.

Workspaces, granular permissions, client management, and branded reports. Everything you need to run a professional WordPress operation.

Workspace System

Separate workspaces for different teams or clients. Workspace switching, invitation links, and workspace-level Slack integration.

Team Permissions

30+ granular permissions across sites, backups, security, staging, and more. Create custom permission groups. Standard Admin and Editor templates.

Client Management

Organize sites by client. Contact management, client notes, and client-specific activity logs. Assign and unassign sites with one click.

Client Reports

Build reports with uptime, performance, security, backups, errors, and activity sections. Custom date ranges. PDF generation and download.

Activity Logs

Complete audit trail across all sites. Filter by category, status, and time period. User attribution for every action. Export to CSV and PDF.

Client Portal

Dedicated portal for your clients with their own login. White-label branding, custom domain support, and read-only access to site status, backups, and reports.

White Label

Brand BlockForge as your own. Custom logo, colors, and custom domain for client-facing interfaces. Present a professional, unified experience.

Weekly Audit Reports

Automated weekly email to workspace admins with team member overview, site count, active alerts, and security summary. Configurable via platform settings.

Support & Communication

Support your clients. Not just their sites.

Integrated ticket system, Slack alerts, and a WordPress admin widget for your clients to reach you directly.

Support Ticket System

Integrated ticket system with replies, internal notes, priority levels, and assignment. Attachments and status management. Central support center.

WP Admin Support Widget

Your clients create tickets directly from their WordPress admin panel. No separate support portal needed. Tickets appear in your BlockForge dashboard.

Slack Integration

OAuth 2.0 Slack connection. Workspace-level setup with per-site channel overrides. Alert deduplication to avoid notification fatigue.

Email Notifications

Per-event notification configuration. Backup completion, uptime alerts, security scans, vulnerability discoveries, and update availability.

Outgoing Webhooks

HTTP callbacks to external URLs on 30+ site events. HMAC SHA-256 signing, per-webhook event filters, delivery logs, and automatic retries with exponential backoff.

Developer Tools

Tools for developers who take WordPress seriously.

Sandbox environments, code safety checks, native apps for iOS and macOS, a browser extension, and a free security scanner.

Sandbox Environments

Spin up isolated WordPress installations with any PHP and WordPress version. Docker-based, configurable lifetime, auto-cleanup after 24 hours.

Plugin Code Safety Check

Static analysis across 8 categories before every update. Results cached globally in a vulnerability database — check a plugin version once, reuse the result across all sites instantly.

iOS Monitoring App

Native SwiftUI app with a real-time status circle, uptime charts (Swift Charts), health scores, push notifications, and WP Auto-Login. Built for iOS 17+, Keychain-secured auth.

macOS Support App

Native SwiftUI menu bar app for support ticket management. View, reply, and get desktop notifications for new tickets — without opening a browser. Built for macOS 14+.

Browser Extension

Detect WordPress sites as you browse. View plugin info, theme details, and security status instantly. Available for Chrome and Safari.

Free Security Scan

13 security checks, plugin vulnerability lookup, performance snapshot, and A–F grading. Shareable URLs and PDF export — no account required.

Compliance & Auditing

Audit-ready from day one.

Exportable audit reports, incident documentation, and data retention policies designed for ISO 27001, SOC 2, and NIS2 compliance.

Exportable Audit Reports

Generate PDF and CSV audit reports covering uptime, security, backups, and activity logs. Designed for ISO 27001, SOC 2, and NIS2 compliance requirements.

Incident Report Generator

Generate NIS2 Article 23 compliant incident reports with timeline, impact assessment, and remediation steps. PDF export for regulatory submissions.

Data Retention Policies

Configurable retention periods for logs, backups, and audit data. Automated daily cleanup jobs. Per-data-type retention settings with compliance presets.

Comprehensive Audit Logging

80+ logging points across all operations. Login, logout, and authentication events. Sensitive data access tracking. Full user attribution for every action.

Session Management

View and revoke active sessions. Configurable session timeouts with dynamic lifetime adjustment. IP and device tracking for every session.

Risk-Based Authentication

Login anomaly detection via GeoIP. Email OTP verification for new locations. Impossible travel detection. Two-factor authentication via TOTP with recovery codes.

Enterprise

Enterprise-grade identity and access.

SAML 2.0 and OIDC single sign-on for organizations that require centralized identity management. Domain-based discovery with optional enforcement.

SAML 2.0 SSO

Connect any SAML 2.0 identity provider — Azure AD, Okta, OneLogin, Keycloak, and more. SP metadata endpoint for easy IdP configuration.

OpenID Connect SSO

Generic OIDC integration with automatic endpoint discovery. Connect Google Workspace, Azure AD, Auth0, or any OIDC-compliant provider.

Domain-Based Discovery

Configure email domains for automatic SSO routing. Users are redirected to their organization’s identity provider based on their email address.

SSO Enforcement

Optionally enforce SSO for specific domains. Block password login for users whose organization requires identity provider authentication.

Just-in-Time Provisioning

Automatically create user accounts on first SSO login. Configure default workspace assignment and team membership. No manual user creation required.

Google OAuth

One-click login and registration via Google. Automatic linking with existing accounts. Available on all plans.

70+ features. One platform. Zero compromises.

Start with 3 sites for free. No credit card required.