The AI operations layer for WordPress agencies

Run 100 WordPress sites like you run 10.

Developer Sentinel diagnoses, fixes, updates and optimizes across your whole portfolio. Every change is human-gated, snapshotted, and rolled back automatically if the site stops rendering — and the AI never gets a shell, raw SQL, or access to your server.

No card required · 5 free scans · Bring your own AI key

01Every client site in one panel
02Fixes that verify — and roll back if they break
03The AI never gets shell, SQL, or your server
Run 100 sites like you run 10 |Every fix human-gated & reversible |Verified after each change — auto-rollback on regression |No shell, no raw SQL, no server access for the AI |Bring your own AI key |Run 100 sites like you run 10 |Every fix human-gated & reversible |Verified after each change — auto-rollback on regression |No shell, no raw SQL, no server access for the AI |Bring your own AI key |Run 100 sites like you run 10 |Every fix human-gated & reversible |Verified after each change — auto-rollback on regression |No shell, no raw SQL, no server access for the AI |Bring your own AI key |

Where Sentinel can help.

Connect the platforms your clients actually run on. Every write is approval-gated and reversible, whichever one it lands on.

WordPress

Every plan

The full agent. Reads debug.log, Site Health, plugin and theme state, then proposes a labelled fix you approve — snapshotted and reversible in one click. Connect with the companion plugin, or plugin-less over the REST API.

  • Diagnose & fix
  • Bulk updates
  • CVE & malware sweeps
  • One-click rollback

Shopify

Paid & lifetime plans

Connected through the Admin API with your own credentials. The agent reads products, orders and customers on its own, and product writes go through the same approval gate as everything else.

  • Products, orders & customers
  • Gated product writes
  • Credentials encrypted
  • No app install

WooCommerce

Every plan

Store operations on top of the WordPress agent: checkout and Action Scheduler health, price, stock, SKU and sale-date edits, variations, coupons and order status — each one gated and snapshot-reversible.

  • Checkout health
  • Catalog & stock edits
  • Coupons & order status
  • Snapshot rollback

From the first ticket to the monthly retainer — covered.

Built for CTOs of one. Sentinel catches the incident, resolves it with your approval, and hands your client the proof at the end of the month.

01·Catch it first

Find the incident before your client emails you.

Scheduled health sweeps surface CVE matches, malware & core-integrity heuristics, and fatal errors — and open the incident automatically.

02·Resolve it cleanly

Diagnose, propose, approve — in one thread.

Sentinel pulls real evidence (debug.log, HTTP probes, plugin state), reasons to root cause, and proposes a labelled fix. Staging first when possible.

03·Prove the value

Send the client-ready report on the 1st.

White-label PDF with every incident, what changed, and time-to-fix — so care plans renew instead of getting questioned.

Clients churn at month six — because care plans look like an invoice with nothing behind them.

They aren't leaving because the site broke. They're leaving because every month they get a bill and no proof that anyone was watching.

Invisible work

Clients can't see what you do for $40/mo.

WordPress admin shows no history. Updates run silently. Invoices without proof feel like overhead.

$4,800
ARR lost when one $400/mo retainer cancels.
Reactive firefighting

Every incident starts at 2 a.m.

SSH in, tail logs, deactivate plugins one by one. Three hours later it works — with no record of what changed.

3 hrs
Average incident burned at a $95/hr dev rate.
Flying blind

25 sites, no single pane of glass.

Checking the portfolio means 25 logins. You find out about the broken site when the client tells you.

10 hrs
Ops drag per month at ~25 min per manual check.
Silent CVEs

The vulnerability is already public.

Published Tuesday, exploited at scale by Friday. The breach response costs more than a year of retainer.

1 / qtr
Sites compromised per quarter on unmonitored portfolios.

One $99 plan replaces $2,000+ in monthly dev time.

Based on a 25-site portfolio, six incidents a month, and a $95/hr senior WordPress rate.

Traditional retainer
$2,565/mo
  • 6 incidents × ~3 hrs investigation
  • $95/hr senior WordPress dev rate
  • Slack threads, no audit trail
  • Reactive only — fires already burning
With Sentinel
$99/mo
  • 7-minute average resolution
  • Proactive sweeps catch issues first
  • Every fix logged and reversible
  • White-label PDF reports
Net savings
$29,592/yr
  • ~$1,184 per site, per year recovered
  • ~210 dev hours back per year
  • Resell at $20/site/mo → +$6k/mo revenue

A senior WordPress engineer, on call for every site you run.

Not a chatbot wrapper. The agent reads real evidence from your sites, reasons to root cause, and proposes a labelled fix you approve before anything runs.

Diagnose any incident

Reads debug.log, Site Health, .htaccess, plugin/theme state, HTTP headers, and recent changes. Binary-searches plugin conflicts. Root-causes WSOD, 500s, REST failures, and login loops.

Fix safely, with approval

Toggle plugins, edit content and SEO meta, clear stale .maintenance, patch .htaccess. Every action labelled Safe / Needs-approval / Risky — snapshotted and reversible in one click.

WooCommerce operations

Checkout and Action Scheduler health, product edits (price, stock, SKU, sale dates), variations, featured images, and SEO meta across Yoast, RankMath, SEOPress, and AIOSEO.

Content and page builds

Update titles, excerpts, and bodies on posts, pages, and products. Build new pages with builder-aware, theme-aware sections — no copy-paste from a chat window into wp-admin.

Proactive watch

Scheduled sweeps for malware & core-integrity heuristics and CVE matches against your installed plugin versions.

Performance triage

Autoload bloat detection, cron analysis (stuck vs missing handlers), and on-demand HTTP request logging so you can see exactly where the time went.

01Live inventory of every plugin version
02Range-accurate CVE matching, refreshed hourly
03Critical hits open an incident by themselves

You hear about a compromised plugin before your client does.

Every connected site reports the exact versions it is running. Advisories are matched against affected version ranges — not fuzzy plugin-name guesses — so what reaches you is a real hit, not noise.

Runs on every plan · free included

feed · matched against your fleet
CRITICALelementor-pro< 3.11.7
HIGHwp-file-manager≤ 6.9
HIGHwpforms-lite< 1.8.4
MEDIUMwoocommerce< 8.2.1
incident opened · awaiting your approval

Across 40 sites, "outdated" is invisible until it's an outage.

Sentinel keeps a live version inventory of every plugin, theme, and PHP runtime you're responsible for. One list tells you which sites are behind, which are running an end-of-life PHP, and which have a published CVE against a version you actually have installed.

Scheduled sweep · rescan on demand
SitePluginsThemesPHPCVEHealth
northgate-dental.com19 outdated17.4 EOL241
harbourlaw.co.uk6 outdated08.1078
shop.velocitybikes.com11 outdated28.0163
clinicaverde.es0 outdated08.2096
studio-mercer.com3 outdated18.2088
Version inventory

Exact plugin, theme, and core versions pulled from the site itself — not a guess from the public HTML.

Rescan on demand

Just pushed updates? Hit Rescan and the counts, CVE matches, and health score rewrite in seconds.

Alerts you control

Email on new critical findings, or keep it silent and read it in the dashboard. Your call, per workspace.

Stop logging into twenty wp-admins to find out nothing is wrong.

Every site reports in on its own: health score, pending updates, matched CVEs, malware and core-integrity scans, and PHP end-of-life. One row per client, refreshed on each sweep, rescannable on demand.

sitehealthcveupdateslast scan
kalimera-clinic.gr96022h ago
atlas-legal.com71191h ago
northwind-shop.eu4431912m ago
studio-verde.it88043h ago
harbor-books.co.uk920040m ago
Alerts you choose

Email when a CVE hits or a site goes down — toggled per workspace, never spammy.

Every action on record

Audit log, HTTP log and activity trail for anything the agent or a teammate did.

Client-ready reports

Branded monthly summaries generated from the same data, sent without you writing them.

Put the boring fixes on autopilot. Keep the veto.

approve verify rollback
  1. 01
    Policy

    You choose what may run alone

    Per site, per action type. Everything outside the policy still stops and waits for a human click.

  2. 02
    Verify

    The site is re-checked immediately

    Rendering, status codes, and the pages that actually earn money — checked the second a change lands.

  3. 03
    Rollback

    Failed check restores the snapshot

    No pager, no 2 a.m. call. The incident records what ran, what broke, and what was put back.

The slowest thing on your client's site is a 4 MB photo nobody resized.

Drop images into the dashboard and they compress to WebP in your own browser — transparency intact, nothing uploaded to a third-party service. Inside WordPress, the same engine bulk-compresses the whole Media Library and squeezes every new upload on the way in.

−87%typical weight removed from an unoptimized media library

Included on every paid and lifetime plan

media library · compressed in-browser
hero-banner.png4.2 MB 318 KB
team-photo.jpg1.8 MB 241 KB
product-01.jpg960 KB 144 KB
logo-strip.png412 KB 78 KB
7.3 MB → 781 KB · 6.5 MB saved
php · css · js — managed snippets
hide-shipping-when-free.php awaiting your approval
1// Hide other rates when free shipping
2add_filter('woocommerce_package_rates', fn($rates) =>
3 array_filter($rates, fn($r) => $r->method_id !== 'free_shipping')
4 ?: $rates
5);
proposed by agent · nothing runs until you say soapprove / reject
0
theme files edited
1-click
disable any snippet
100%
human-approved
Code snippets

Custom PHP without the functions.php roulette.

Ask for the tweak in plain words — “hide shipping methods when free shipping applies”, “disable XML-RPC” — and the agent writes the snippet. It lands as a managed snippet you can toggle or remove, and it never executes until you approve it.

  • Human-gated by default

    Snippet actions sit on the permanent no-autopilot list. Every create, edit or toggle waits for your approval — no policy can override it.

  • Kill switch on everything

    Each snippet is enabled or disabled with one switch. A bad change is a toggle, not an FTP session at midnight.

  • Reversible, not surgical

    Snippets never touch functions.php on disk. They live managed and removable — roll back without editing theme files.

Built for the tickets that ruin your week.

Six classes of WordPress emergency that Sentinel resolves end to end.

Security

Outdated plugin with an active CVE

Flags the vulnerable plugin, proposes the update, takes a snapshot, and verifies the site still renders after.

Outage

White screen of death after a deploy

Tails fatal.log, identifies the offending plugin or theme, and offers a one-click safe-mode rollback.

Email

WooCommerce emails not sending

Inspects SMTP config, sends a probe, reads bounce headers, and proposes the exact mailer and DNS change.

Performance

The site is suddenly slow

Runs TTFB probes, finds the slow query or external API call, and recommends fixes with measured deltas.

Maintenance

Bulk plugin updates across 25 sites

Queues updates per site, runs them with approval, and posts one client-ready report of what changed.

Monitoring

Proactive health sweeps

Scheduled scans open incidents before your client emails you — CVE matches, malware & core-integrity heuristics, and fatal errors.

From "white screen" to fixed, in one conversation.

Four steps, roughly 90 seconds of setup.

01

Connect

Install the companion plugin and paste the pairing token. Onboarding warns you if a WAF or bot rule will block the round-trip.

02

Report

Describe the issue in plain English — or let scheduled health sweeps surface it for you.

03

Diagnose

The agent runs read-only diagnostics, reproduces the failure, and explains the root cause in plain language.

04

Approve & verify

Approve the proposed fix. Staging first when available, then production, then a re-run of the failing check.

Nothing runs on production without you.

Real evidence, not guesses

Site Health, debug.log tails, HTTP probes, plugin/theme state, and WAF headers — then reasoning to a root cause.

Approval-gated remediation

Every action is labelled Safe, Needs-approval, or Risky. Nothing runs on production without an explicit approval in the audit log.

One-click rollback

Each action snapshots prior state. Reverse a plugin toggle, .htaccess edit, or theme switch in one click — staging-first whenever possible.

The people actually keeping WordPress sites alive.

If you make money keeping other people's WordPress sites running, this was built for you.

Primary fit

Solo freelancers and care-plan operators

5–30 sites

You're the whole ops team. Sentinel kills the 2 a.m. firefight and turns your care plan into something the client can see — a white-label monthly report with every incident and minute saved.

Strong fit

Small WordPress agencies

1–10 devs, 25–150 sites

One pane of glass across the portfolio. Juniors handle L1 because the agent gathers the evidence and proposes the labelled fix — senior just approves. Audit log on every action.

Great fit

WooCommerce store owners

1–3 stores

Product, inventory, and SEO edits without hiring a dev for every small change. Checkout health checks catch Action Scheduler backlogs before customers do.

Not the right fit: enterprise multi-region ops, fully autonomous self-healing, or anyone who wants AI pushing to production unattended. Every Sentinel action requires a human approval — by design.

You already did the work. Sentinel makes sure it gets billed.

Most care-plan work disappears into Slack threads and goodwill. Here every fix is attached to a client, priced as it happens, and payable from a link you send in one click.

  1. 01
    Assign

    Every incident belongs to a client before it belongs to an invoice.

  2. 02
    Itemize

    Time and actions land on the bill while the fix is happening.

  3. 03
    Send link

    Client pays from a hosted checkout link — no chasing, no PDF ping-pong.

  4. 04
    Report

    A branded monthly recap lands in their inbox with your logo on it.

Incident #4172payable
client · northgate dental
Critical CVE patched — elementor-pro0.5h$45
Checkout 500 root-caused & fixed1.25h$112
Snapshot + verified rollback test0.25h$22
Total$179
Payment link sent
NG
Northgate — August report
your logo · your colours
12
incidents
4.5h
saved
3
CVEs
White-label · sent monthly

Your AI key. Your model. Your bill — at cost.

Sentinel doesn't resell tokens or mark up inference. Plug in your own OpenAI, Anthropic, Google — or a single FinalRouter key that reaches every model — and the agent uses it for every diagnosis.

Your keys, your account

Paste an OpenAI, Anthropic, Google, or FinalRouter API key in workspace settings. Inference is billed directly by the provider — no token markup, no surprise bills from us.

Any frontier model, per incident

Default to fast and cheap for triage. Switch a single incident to a frontier model when the bug is gnarly — without changing your workspace default.

Data stays on your terms

Evidence is sent only to the provider you chose, under your account's data-handling agreement. Swap providers per incident, per workspace, or per client.

01

Paste your key

Workspace Settings → AI Providers. Keys are encrypted at rest and scoped to that single workspace.

02

Sentinel calls the provider directly

Prompt and evidence go straight to the provider you chose. No shared pool, no raw prompt logging, no training on your data.

03

Revoke any time

Clear the key to stop all inference immediately, or revoke it in the provider console. Existing audit logs are preserved.

OpenAI · GPT-5 familyAnthropic · Claude Opus, Sonnet, HaikuGoogle · Gemini 2.5 Pro, FlashFinalRouter · one key, every model

Pays for itself in week one.

Every plan starts free — 1 site and 5 scans, no card. Upgrade when you connect site number two. Cancel anytime.

Pro
$29/mo
For freelancers and small studios
  • Up to 5 sites · 3 seats
  • 200 scans/mo · 500 AI messages/mo (fair-use cap)
  • Guided fixes with one-click approval
  • CVE watch + scheduled health sweeps
  • Auto-rollback on failed verification
  • Rescan-on-demand + outdated inventory
  • Bring your own AI key — required
  • Email support
Agency
Most popular
$99/mo
For teams running a client portfolio
  • Up to 25 sites · 10 seats
  • 1,000 scans/mo · 2,500 AI messages/mo (fair-use cap)
  • Approval-policy autopilot per site
  • White-label PDF reports + client portal
  • Assign incidents to clients, bill per fix
  • Payment links + itemized invoices
  • Bulk image optimizer across the fleet
  • Priority support
Studio
$249/mo
For hosts and portfolio operators
  • Up to 100 sites · up to 25 seats
  • 5,000 scans/mo · 10,000 AI messages/mo (fair-use cap)
  • Fleet-wide autopilot + bulk actions
  • Full audit log export + SSO-ready access
  • Custom alert routing (Slack, webhooks)
  • Multi-brand white-labeling
  • Onboarding + migration assistance
  • Dedicated support channel

Free forever tier: 1 site, 5 lifetime scans, diagnosis only, 1 seat. Every plan runs on your own AI key (BYOK, required) under fair-use limits, and every fix stays human-gated, verified and reversible.

One-time offer · limited

Pay once. Run WordPress on autopilot for the rest of your career.

One incident on a client site costs more than this. The lifetime deal is $69 — the same platform agencies pay $29 to $249 a month for, with no renewal date attached. When the codes are gone, this page goes back to subscriptions only.

  • 5 sites and 1 seat per code — stack up to 4 codes for 50 sites and 10 seats
  • 200 scans/mo, every month, forever
  • Bring your own AI key — required (fair-use limits apply)
  • Every fix human-gated, verified, and auto-rolled-back if it breaks
  • All future updates included — no upgrade invoice, ever
Lifetime access
$69one-time
Stackable up to 4 codes · BYOK · 60-day refund window
Versus $348/yr on Pro — the lifetime code pays for itself in under three months and never bills again.

Secure checkout · instant workspace activation

Keys, data, and who can see what.

Where are my API keys stored?

Encrypted at rest, scoped to a single workspace. Keys are never written to logs and never returned to the browser after save — you see a masked preview only.

Who can see or use my key?

Only workspace owners and admins can paste, rotate, or clear keys. The decrypted key is loaded into memory only for the duration of a single AI call.

What data gets sent to the AI provider?

Only the evidence needed for the current incident: your prompt, relevant debug.log tails, plugin/theme state, probe results, and Site Health output. No database contents or customer PII.

Does Sentinel use my prompts for anything else?

No. We don't train on your prompts, read them for analytics, or share keys with third parties. Inference goes from our backend straight to the provider you chose.

Do the providers train on my data?

By default, paid OpenAI, Anthropic, and Google API calls are not used for training. You're bound by the provider's data-processing agreement on your own account.

What happens when I revoke a key?

Clearing it stops all future calls within seconds. Revoking it in the provider console is stronger — the next call returns a 401. Past audit logs are preserved.

Get started

Connect your first site in 90 seconds.

Install the companion plugin, paste the pairing token, and let Sentinel run a baseline scan. The first incident usually pays for the year.