A product of Varry LLC

Know your WordPress fleet is healthy. Before your visitors do.

WPTracked is the quiet marshal keeping the WordPress frontier safe. An automated, strictly read-only server and WordPress health auditor that runs on your own infrastructure via a Devin outpost.

The Lawless Frontier of Silent Drift

Websites rarely fail loudly. They degrade quietly until the damage is already done.

Unpatched Plugins and CVEs

New vulnerabilities (CISA KEV) drop daily. Without a watchful eye, a forgotten slider plugin becomes the backdoor.

Weak File Permissions

Configuration files left world-readable or password root SSH enabled. The digital equivalent of leaving the vault unlocked.

Expiring Certs and Brute-Force Noise

TLS certificates lapsing into invalidity, disks filling with intrusion logs. You need a scout to read the signs before the raid.

The Marshal’s Rounds

A comprehensive sweep from the bedrock OS to the weather-vane on the saloon roof.

1. Host and Infrastructure

  • Disk space and inode usage tracking
  • TLS/SSL certificate validity checks
  • Pending OS updates and kernel reboots

2. WordPress Core and Config

  • WP Core checksum verification
  • Security best-practices audit (wp-config.php)
  • Weak file permissions detection

3. Vulnerability Scouting

  • Theme and plugin update availability
  • CISA KEV (Known Exploited Vulnerabilities) mapping
  • Abandoned or withdrawn plugin flags

4. Perimeter Defense

  • SSH configuration audit (no root password logins)
  • Log analysis for brute-force patterns
  • Intrusion attempt metrics

The Four-Step Posse

Executed on your own server through a Devin outpost.

1

Collect

The Devin outpost script boots on your VPS. It surveys the landscape, locating Nginx/Apache roots and WordPress installations without human intervention.

2

Scan

It performs a strictly read-only interrogation. Queries WP-CLI, parses system logs, and compares installed versions against the CISA KEV catalog.

3

Render

Raw data is forged into a branded report: a rich HTML body and a portable PDF summary of the fleet’s health.

4

Send

Dispatched via your mail carrier of choice. Fully provider-agnostic: EmailIt, SMTP, SendGrid, Mailgun, or Resend.

Strictly Read-Only

WPTracked is an observer. It never modifies files, never updates databases, and never alters configs.

  • Fail-closed architecture
  • No secrets logged
  • Locked and idempotent runs

The Bounty

Receive grouped HTML emails with attached PDF artifacts. Instantly see if your fleet is [HEALTHY] or needs an [ALERT] response.

High Noon, Every Day

Schedule it your way with standard cron, a systemd timer, or Devin Automation. Toggle checks per server, and restrict scope to server-only or server plus WordPress.

Wanted

Future Capabilities

Today WPTracked is purely a scout. Next up: an opt-in approved automated updates mode that applies known-safe security patches and emails the summary.

Not yet available — coming soon to the frontier.

WPTracked is built and maintained by Varry LLC.

Transmit Inquiry

Questions about deploying WPTracked, partnerships, or Varry platforms? Reach headquarters or send a brief below.

Transmit Inquiry