The AI operations layer for WordPress agencies
Run 100 WordPress sites like you run 10.
Developer Sentinel diagnoses, fixes, updates and optimizes across your whole portfolio. Every change is human-gated, snapshotted, and rolled back automatically if the site stops rendering — and the AI never gets a shell, raw SQL, or access to your server.
No card required · 5 free scans · Bring your own AI key
Where Sentinel can help.
Connect the platforms your clients actually run on. Every write is approval-gated and reversible, whichever one it lands on.
WordPress
The full agent. Reads debug.log, Site Health, plugin and theme state, then proposes a labelled fix you approve — snapshotted and reversible in one click. Connect with the companion plugin, or plugin-less over the REST API.
- Diagnose & fix
- Bulk updates
- CVE & malware sweeps
- One-click rollback
Shopify
Connected through the Admin API with your own credentials. The agent reads products, orders and customers on its own, and product writes go through the same approval gate as everything else.
- Products, orders & customers
- Gated product writes
- Credentials encrypted
- No app install
WooCommerce
Store operations on top of the WordPress agent: checkout and Action Scheduler health, price, stock, SKU and sale-date edits, variations, coupons and order status — each one gated and snapshot-reversible.
- Checkout health
- Catalog & stock edits
- Coupons & order status
- Snapshot rollback
From the first ticket to the monthly retainer — covered.
Built for CTOs of one. Sentinel catches the incident, resolves it with your approval, and hands your client the proof at the end of the month.
Find the incident before your client emails you.
Scheduled health sweeps surface CVE matches, malware & core-integrity heuristics, and fatal errors — and open the incident automatically.
Diagnose, propose, approve — in one thread.
Sentinel pulls real evidence (debug.log, HTTP probes, plugin state), reasons to root cause, and proposes a labelled fix. Staging first when possible.
Send the client-ready report on the 1st.
White-label PDF with every incident, what changed, and time-to-fix — so care plans renew instead of getting questioned.
Clients churn at month six — because care plans look like an invoice with nothing behind them.
They aren't leaving because the site broke. They're leaving because every month they get a bill and no proof that anyone was watching.
Clients can't see what you do for $40/mo.
WordPress admin shows no history. Updates run silently. Invoices without proof feel like overhead.
Every incident starts at 2 a.m.
SSH in, tail logs, deactivate plugins one by one. Three hours later it works — with no record of what changed.
25 sites, no single pane of glass.
Checking the portfolio means 25 logins. You find out about the broken site when the client tells you.
The vulnerability is already public.
Published Tuesday, exploited at scale by Friday. The breach response costs more than a year of retainer.
One $99 plan replaces $2,000+ in monthly dev time.
Based on a 25-site portfolio, six incidents a month, and a $95/hr senior WordPress rate.
- 6 incidents × ~3 hrs investigation
- $95/hr senior WordPress dev rate
- Slack threads, no audit trail
- Reactive only — fires already burning
- 7-minute average resolution
- Proactive sweeps catch issues first
- Every fix logged and reversible
- White-label PDF reports
- ~$1,184 per site, per year recovered
- ~210 dev hours back per year
- Resell at $20/site/mo → +$6k/mo revenue
A senior WordPress engineer, on call for every site you run.
Not a chatbot wrapper. The agent reads real evidence from your sites, reasons to root cause, and proposes a labelled fix you approve before anything runs.
Diagnose any incident
Reads debug.log, Site Health, .htaccess, plugin/theme state, HTTP headers, and recent changes. Binary-searches plugin conflicts. Root-causes WSOD, 500s, REST failures, and login loops.
Fix safely, with approval
Toggle plugins, edit content and SEO meta, clear stale .maintenance, patch .htaccess. Every action labelled Safe / Needs-approval / Risky — snapshotted and reversible in one click.
WooCommerce operations
Checkout and Action Scheduler health, product edits (price, stock, SKU, sale dates), variations, featured images, and SEO meta across Yoast, RankMath, SEOPress, and AIOSEO.
Content and page builds
Update titles, excerpts, and bodies on posts, pages, and products. Build new pages with builder-aware, theme-aware sections — no copy-paste from a chat window into wp-admin.
Proactive watch
Scheduled sweeps for malware & core-integrity heuristics and CVE matches against your installed plugin versions.
Performance triage
Autoload bloat detection, cron analysis (stuck vs missing handlers), and on-demand HTTP request logging so you can see exactly where the time went.
You hear about a compromised plugin before your client does.
Every connected site reports the exact versions it is running. Advisories are matched against affected version ranges — not fuzzy plugin-name guesses — so what reaches you is a real hit, not noise.
Runs on every plan · free included
Across 40 sites, "outdated" is invisible until it's an outage.
Sentinel keeps a live version inventory of every plugin, theme, and PHP runtime you're responsible for. One list tells you which sites are behind, which are running an end-of-life PHP, and which have a published CVE against a version you actually have installed.
| Site | Plugins | Themes | PHP | CVE | Health |
|---|---|---|---|---|---|
| northgate-dental.com | 19 outdated | 1 | 7.4 EOL | 2 | 41 |
| harbourlaw.co.uk | 6 outdated | 0 | 8.1 | 0 | 78 |
| shop.velocitybikes.com | 11 outdated | 2 | 8.0 | 1 | 63 |
| clinicaverde.es | 0 outdated | 0 | 8.2 | 0 | 96 |
| studio-mercer.com | 3 outdated | 1 | 8.2 | 0 | 88 |
Exact plugin, theme, and core versions pulled from the site itself — not a guess from the public HTML.
Just pushed updates? Hit Rescan and the counts, CVE matches, and health score rewrite in seconds.
Email on new critical findings, or keep it silent and read it in the dashboard. Your call, per workspace.
Stop logging into twenty wp-admins to find out nothing is wrong.
Every site reports in on its own: health score, pending updates, matched CVEs, malware and core-integrity scans, and PHP end-of-life. One row per client, refreshed on each sweep, rescannable on demand.
| site | health | cve | updates | last scan |
|---|---|---|---|---|
| kalimera-clinic.gr | 96 | 0 | 2 | 2h ago |
| atlas-legal.com | 71 | 1 | 9 | 1h ago |
| northwind-shop.eu | 44 | 3 | 19 | 12m ago |
| studio-verde.it | 88 | 0 | 4 | 3h ago |
| harbor-books.co.uk | 92 | 0 | 0 | 40m ago |
Email when a CVE hits or a site goes down — toggled per workspace, never spammy.
Audit log, HTTP log and activity trail for anything the agent or a teammate did.
Branded monthly summaries generated from the same data, sent without you writing them.
Put the boring fixes on autopilot. Keep the veto.
- 01Policy
You choose what may run alone
Per site, per action type. Everything outside the policy still stops and waits for a human click.
- 02Verify
The site is re-checked immediately
Rendering, status codes, and the pages that actually earn money — checked the second a change lands.
- 03Rollback
Failed check restores the snapshot
No pager, no 2 a.m. call. The incident records what ran, what broke, and what was put back.
The slowest thing on your client's site is a 4 MB photo nobody resized.
Drop images into the dashboard and they compress to WebP in your own browser — transparency intact, nothing uploaded to a third-party service. Inside WordPress, the same engine bulk-compresses the whole Media Library and squeezes every new upload on the way in.
Included on every paid and lifetime plan
Custom PHP without the functions.php roulette.
Ask for the tweak in plain words — “hide shipping methods when free shipping applies”, “disable XML-RPC” — and the agent writes the snippet. It lands as a managed snippet you can toggle or remove, and it never executes until you approve it.
- Human-gated by default
Snippet actions sit on the permanent no-autopilot list. Every create, edit or toggle waits for your approval — no policy can override it.
- Kill switch on everything
Each snippet is enabled or disabled with one switch. A bad change is a toggle, not an FTP session at midnight.
- Reversible, not surgical
Snippets never touch functions.php on disk. They live managed and removable — roll back without editing theme files.
Built for the tickets that ruin your week.
Six classes of WordPress emergency that Sentinel resolves end to end.
Outdated plugin with an active CVE
Flags the vulnerable plugin, proposes the update, takes a snapshot, and verifies the site still renders after.
White screen of death after a deploy
Tails fatal.log, identifies the offending plugin or theme, and offers a one-click safe-mode rollback.
WooCommerce emails not sending
Inspects SMTP config, sends a probe, reads bounce headers, and proposes the exact mailer and DNS change.
The site is suddenly slow
Runs TTFB probes, finds the slow query or external API call, and recommends fixes with measured deltas.
Bulk plugin updates across 25 sites
Queues updates per site, runs them with approval, and posts one client-ready report of what changed.
Proactive health sweeps
Scheduled scans open incidents before your client emails you — CVE matches, malware & core-integrity heuristics, and fatal errors.
From "white screen" to fixed, in one conversation.
Four steps, roughly 90 seconds of setup.
Connect
Install the companion plugin and paste the pairing token. Onboarding warns you if a WAF or bot rule will block the round-trip.
Report
Describe the issue in plain English — or let scheduled health sweeps surface it for you.
Diagnose
The agent runs read-only diagnostics, reproduces the failure, and explains the root cause in plain language.
Approve & verify
Approve the proposed fix. Staging first when available, then production, then a re-run of the failing check.
Nothing runs on production without you.
Real evidence, not guesses
Site Health, debug.log tails, HTTP probes, plugin/theme state, and WAF headers — then reasoning to a root cause.
Approval-gated remediation
Every action is labelled Safe, Needs-approval, or Risky. Nothing runs on production without an explicit approval in the audit log.
One-click rollback
Each action snapshots prior state. Reverse a plugin toggle, .htaccess edit, or theme switch in one click — staging-first whenever possible.
The people actually keeping WordPress sites alive.
If you make money keeping other people's WordPress sites running, this was built for you.
Solo freelancers and care-plan operators
You're the whole ops team. Sentinel kills the 2 a.m. firefight and turns your care plan into something the client can see — a white-label monthly report with every incident and minute saved.
Small WordPress agencies
One pane of glass across the portfolio. Juniors handle L1 because the agent gathers the evidence and proposes the labelled fix — senior just approves. Audit log on every action.
WooCommerce store owners
Product, inventory, and SEO edits without hiring a dev for every small change. Checkout health checks catch Action Scheduler backlogs before customers do.
Not the right fit: enterprise multi-region ops, fully autonomous self-healing, or anyone who wants AI pushing to production unattended. Every Sentinel action requires a human approval — by design.
You already did the work. Sentinel makes sure it gets billed.
Most care-plan work disappears into Slack threads and goodwill. Here every fix is attached to a client, priced as it happens, and payable from a link you send in one click.
- 01Assign
Every incident belongs to a client before it belongs to an invoice.
- 02Itemize
Time and actions land on the bill while the fix is happening.
- 03Send link
Client pays from a hosted checkout link — no chasing, no PDF ping-pong.
- 04Report
A branded monthly recap lands in their inbox with your logo on it.
Your AI key. Your model. Your bill — at cost.
Sentinel doesn't resell tokens or mark up inference. Plug in your own OpenAI, Anthropic, Google — or a single FinalRouter key that reaches every model — and the agent uses it for every diagnosis.
Your keys, your account
Paste an OpenAI, Anthropic, Google, or FinalRouter API key in workspace settings. Inference is billed directly by the provider — no token markup, no surprise bills from us.
Any frontier model, per incident
Default to fast and cheap for triage. Switch a single incident to a frontier model when the bug is gnarly — without changing your workspace default.
Data stays on your terms
Evidence is sent only to the provider you chose, under your account's data-handling agreement. Swap providers per incident, per workspace, or per client.
Paste your key
Workspace Settings → AI Providers. Keys are encrypted at rest and scoped to that single workspace.
Sentinel calls the provider directly
Prompt and evidence go straight to the provider you chose. No shared pool, no raw prompt logging, no training on your data.
Revoke any time
Clear the key to stop all inference immediately, or revoke it in the provider console. Existing audit logs are preserved.
Pays for itself in week one.
Every plan starts free — 1 site and 5 scans, no card. Upgrade when you connect site number two. Cancel anytime.
- Up to 5 sites · 3 seats
- 200 scans/mo · 500 AI messages/mo (fair-use cap)
- Guided fixes with one-click approval
- CVE watch + scheduled health sweeps
- Auto-rollback on failed verification
- Rescan-on-demand + outdated inventory
- Bring your own AI key — required
- Email support
- Up to 25 sites · 10 seats
- 1,000 scans/mo · 2,500 AI messages/mo (fair-use cap)
- Approval-policy autopilot per site
- White-label PDF reports + client portal
- Assign incidents to clients, bill per fix
- Payment links + itemized invoices
- Bulk image optimizer across the fleet
- Priority support
- Up to 100 sites · up to 25 seats
- 5,000 scans/mo · 10,000 AI messages/mo (fair-use cap)
- Fleet-wide autopilot + bulk actions
- Full audit log export + SSO-ready access
- Custom alert routing (Slack, webhooks)
- Multi-brand white-labeling
- Onboarding + migration assistance
- Dedicated support channel
Free forever tier: 1 site, 5 lifetime scans, diagnosis only, 1 seat. Every plan runs on your own AI key (BYOK, required) under fair-use limits, and every fix stays human-gated, verified and reversible.
Pay once. Run WordPress on autopilot for the rest of your career.
One incident on a client site costs more than this. The lifetime deal is $69 — the same platform agencies pay $29 to $249 a month for, with no renewal date attached. When the codes are gone, this page goes back to subscriptions only.
- 5 sites and 1 seat per code — stack up to 4 codes for 50 sites and 10 seats
- 200 scans/mo, every month, forever
- Bring your own AI key — required (fair-use limits apply)
- Every fix human-gated, verified, and auto-rolled-back if it breaks
- All future updates included — no upgrade invoice, ever
Secure checkout · instant workspace activation
Keys, data, and who can see what.
Where are my API keys stored?
Encrypted at rest, scoped to a single workspace. Keys are never written to logs and never returned to the browser after save — you see a masked preview only.
Who can see or use my key?
Only workspace owners and admins can paste, rotate, or clear keys. The decrypted key is loaded into memory only for the duration of a single AI call.
What data gets sent to the AI provider?
Only the evidence needed for the current incident: your prompt, relevant debug.log tails, plugin/theme state, probe results, and Site Health output. No database contents or customer PII.
Does Sentinel use my prompts for anything else?
No. We don't train on your prompts, read them for analytics, or share keys with third parties. Inference goes from our backend straight to the provider you chose.
Do the providers train on my data?
By default, paid OpenAI, Anthropic, and Google API calls are not used for training. You're bound by the provider's data-processing agreement on your own account.
What happens when I revoke a key?
Clearing it stops all future calls within seconds. Revoking it in the provider console is stronger — the next call returns a 401. Past audit logs are preserved.