Outpost
Use casesHow it worksPoliciesAccessAIIntegrationsPricingFAQ
WordPress

WordPress

CMS & Web

Monitor WordPress plugins, users, and admin access across every site

Continuous visibility into every WordPress site you run — installed plugins and themes, core version, every user and their role, and the accounts that should have been removed long ago.

A WordPress site is easy to run. Ten, fifty, or three hundred are not. Each one carries its own list of plugins, its own theme, its own core version, and its own set of users — and each accumulates quietly. A freelancer finishes a build and keeps an editor account. A marketing team installs a form plugin that nobody updates. An old agency address still holds administrator on a site you forgot existed. Each of these made sense at the time. Together they are an attack surface nobody can describe from memory.

The default WordPress experience makes this worse. Every answer lives inside a separate wp-admin. To learn which sites are still on an outdated core, which ones run a plugin with a known vulnerability, or who holds administrator where, you would log into each dashboard in turn — and still miss the site that was never on your list.

Outpost replaces that with a single, continuously-synced inventory. The Outpost plugin reports back from each site — installed plugins and their versions, active theme, core version, every user and the role they hold — and Outpost turns those reports into one fleet you can search and filter like the asset it is. Multisite networks report every sub-site.

Policies that apply to every site at once

Once every site is in one place, you can decide how every site should look and let Outpost enforce it. Require a plugin to be installed and active everywhere: your security plugin, your backup tool, your analytics. Forbid the plugins you have retired or never approved. Pin a minimum core version.

Policies reach users too. Require that every administrator signs in with a corporate email address, cap how many admins a site can have, or flag any administrator who has not enrolled in two-factor authentication. The moment a site drifts, you know — and every meaningful action on every site lands in one searchable audit log: a user creating another user, a role change, a plugin installed or activated, a theme switched, a core update, a login from a new location.

Catch WordPress access that outlives employment

The most dangerous WordPress account is the one that should already be gone. A contractor finished six months ago and still has an editor account on three sites. An account has not logged in for a year, but it is still active and still a way in. An administrator signed up with a personal email, or with a domain you have never heard of.

Outpost is built around catching exactly this. Because it links each WordPress account back to the person behind it, the moment someone is marked as departed, their lingering accounts across every site surface for review. And because the Outpost plugin accepts signed commands from your dashboard, the fix is one action away: disable the account on every site, destroy its active sessions, and block further logins — without opening a single wp-admin.

Want the full tour? See the WordPress product overview for fleet inventory, policies, audit log, and remote actions in detail.

What Outpost detects

Everything we surface from your WordPress workspace.

Plugins, themes, and core version

Outpost inventories every installed plugin and its version, the active theme, and the WordPress core version on each site, so you can see at a glance which sites are outdated, which run a plugin with a known vulnerability, and which carry plugins you never approved.

Users and roles

Every user on every site is synced with the role they hold — administrator, editor, author, and the rest — plus their email address and last login, so you can see exactly who has admin power where, across the whole fleet.

Policy drift and audit events

Outpost checks every site against the policies you set — required plugins, banned plugins, minimum core version, corporate-email admins, two-factor enrollment — and records every meaningful change in one searchable audit log spanning all your sites.

Assets we track

Outpost creates and maintains these asset types from your WordPress data.

wordpress

How it works

1

Connect

Install the Outpost plugin on each site and connect it with a per-site token. The plugin reports to Outpost over HTTPS and never needs your wp-admin credentials. Multisite networks report every sub-site.

2

Discover

Outpost inventories the site's plugins, themes, core version, users, and roles, and creates an asset you can search, filter, and review alongside every other site you manage.

3

Monitor

Plugins, users, and configuration are re-synced continuously, policies are re-evaluated on every change, and every meaningful action lands in the audit log with who did it, on which site, from where, and when.

4

Offboard

When a contractor or employee leaves, Outpost links their identity to the WordPress accounts they still hold on every site, so lingering editor and administrator access surfaces for review — and can be disabled everywhere in one action.

Frequently asked questions

Install the Outpost plugin on each site and it reports every installed plugin, its version, and whether it is active. Outpost combines those reports into one fleet-wide table you can filter by plugin, version, or site, so you can find every site running an outdated or unapproved plugin without opening a single wp-admin.

Outpost continuously syncs every user and role on every connected site and links each account to the person behind it. When someone is offboarded, their lingering administrator and editor accounts across all your sites are flagged for review, and you can disable them everywhere in one action — active sessions are destroyed and further logins blocked.

Yes. On a multisite network the Outpost plugin reports every sub-site, so you can track users and roles per site and see network-activated plugins alongside site-level ones.

Yes. The Outpost plugin accepts signed commands from your dashboard, so you can disable a user account, update a plugin or theme on one site or every site that runs it, and install, activate, deactivate, or delete plugins and themes without logging into each site.

Outpost

See your entire WordPress footprint in one place

Join the waitlist for early access to Outpost's WordPress integration and every other tool in your stack.

Explore more integrations