Second copy and test restores
A copy of the backups in a second storage and an automatic test restore every month, so you know they work before you need them.
For web agencies · WordPress & Joomla
MultiCmsManager watches every site you look after from two sides: an agent inside the CMS that notices new admins, altered core files and PHP hidden in uploads, and checks from outside for downtime, expiring certificates, hijacked DNS and spam in the sitemap. At night it takes encrypted backups and updates plugins, rolling back on its own if something breaks.
We are onboarding agencies in small groups during the beta.
§ 01Two sides of every site
External monitors only see the home page. Security plugins live inside one site and are the first thing an attacker switches off. MultiCmsManager combines both views and keeps the evidence on its own servers.
.php.jpg.htaccess, index.php, .user.ini and auto_prepend_file: where malware loads before the CMS does§ 02Joomla, properly
Most multi-site dashboards are WordPress tools with a Joomla checkbox. Our Joomla agent is a native system plugin built on the same core as the WordPress one, so every feature ships for both on the same day.
§ 03Tamper evidence
When a core file changes, you see which one, compared with the official release of the exact version installed. Changed PHP in the core is critical. An edited template is just worth a look.
On a clean install: zero false positives across 3,336 WordPress files and 9,625 Joomla files in our tests.
| libraries/src/Factory.php | Modified | Critical |
| plugins/system/sef/helper.php | Not in the release | Critical |
| templates/cassiopeia/index.php | Modified | Warning |
§ 04Reputation
Injected spam rarely touches the home page. It shows up as hundreds of new URLs in the sitemap, a robots.txt that hides the site from Google, or a blacklist entry that turns every visit into a red warning screen.
Sudden growth, links to other domains, URLs about pills, casinos or loans
Changes, and rules that block every search engine
Google Web Risk, Spamhaus DBL and ZEN, SURBL, SpamCop
New A, MX or nameserver records
SEO shield: compares what Googlebot receives, verified even from inside the site where cloaking can’t hide, with what a visitor from Google and a mobile visitor see. Conditional redirects and hidden links surface, and an optional AI opinion explains what to clean.
§ 05Safe updates
Many updates change the database too: rolling back only the files leaves a site half-broken. Before each update MultiCmsManager saves the plugin’s folder and the tables it may change; if the pages stop working afterwards, it puts everything back.
Today for WordPress plugins and themes. Joomla extensions and staging come next.
| Site backup | Tonight, 01:30 | OK |
| Restore point | Plugin folder + 3 tables | OK |
| Shop Builder 8.1 → 8.2 | Updated | OK |
| Page checks | PHP fatal error on /shop/ | Error |
| Rollback | Back to 8.1 in 4 seconds | OK |
§ 06Backups
Database and files are compressed and encrypted on the client’s server, then uploaded straight to European storage. Even shared hosting copes: the work runs in short steps.
AES-256 with a different key for every backup: nothing readable stays on the site or in storage.
After the first one only changed files are sent, and every backup still restores in one pass, with no chain to rebuild.
Several schedules per site, say everything monthly and the database nightly, each with its own retention. Keep important backups forever.
Storage-level Object Lock: not even stolen credentials can delete them before they expire.
Database, files or both put back on the site from the dashboard, after a backup of the site as it is. Or download them as .sql.gz and .tar.gz.
For demanding clients, backups can be locked with a key the client keeps: without that file nobody, us included, can open them.
§ 07One-click admin
No shared password vault, no forgotten admin accounts. The platform asks the site for a login link that works once, for 60 seconds, and only on that domain.
§ 08Set up in minutes
Paste the URL. Uptime, SSL, DNS, domain, sitemap and blacklist checks start straight away, no plugin needed.
A lightweight plugin for WordPress or Joomla. It opens no new ports and only answers requests signed with that site’s own key.
A one-time code connects the site. From then on you get inventory, security events and integrity checks.
MCM1.eyJ1IjoiaHR0cHM6Ly9hcHAu… All features
§ 09Where it fits
| WordPress-only dashboards | External scanners | MultiCmsManager | |
|---|---|---|---|
| WordPress and Joomla in one dashboard | Rarely | No | Yes |
| Sees inside the site: new admins, core files, uploads | Yes | No | Yes |
| Sees outside: uptime, DNS, blacklists, sitemap spam | Partly | Yes | Yes |
| Core integrity for Joomla | Rarely | No | Yes |
| One-click admin login | Yes | No | Yes |
| Backups encrypted on the site, incremental | Partly | No | Yes |
| Updates that roll back the database too | Rarely | No | Yes |
| Joomla 3 and 4 still in production | No | Partly | Yes |
Based on the public feature pages of widely used tools, September 2026. Features vary by plan.
§ 10Security of the platform itself
The agent only answers requests signed with HMAC-SHA256, with a timestamp and a single-use nonce.
Responses are signed too, so a firewall page or a cached error can never be mistaken for good news.
For sensitive files like your configuration, only fingerprints leave the site. Never their contents.
On normal visits the agent only listens for fatal errors. Heavy work runs in short steps sized for shared hosting.
Every downloaded plugin accepts only the platform it came from: a forged connection code cannot hand a site to anyone else.
Each agency sees and controls only its own sites, and two-factor login is mandatory for every account. Automated tests check it on every release.
In development
A copy of the backups in a second storage and an automatic test restore every month, so you know they work before you need them.
Updates tried on a copy first, screenshots before and after, and safe updates for Joomla extensions too.
White-label monthly reports and read-only access for your clients.
§ 11Pricing
Pay for the sites you monitor. Add-ons only for the sites that need them.
from $1.49 per site / month
Everything on this page that’s available today.
from $1.99 per site / month
For sites where search traffic is the business.
from $4.90 per 50 GB / month
Storage shared by all your sites.
Planned launch pricing. Final prices will be confirmed before any billing starts.
§ 12FAQ
No. Uptime, SSL, DNS, domain expiry, sitemap and blacklist checks only need the URL. The plugin adds everything that can only be seen from inside: new admins, core and file integrity, vulnerabilities, one-click login.
On normal page views it only registers a handler for fatal errors. File scans and integrity checks run when the platform asks, in steps of a few seconds sized for shared hosting.
The platform notices: after three failed contacts you get an alert, and the outside checks keep running. The last known state stays on our servers.
WordPress 6.5 or later with PHP 7.4 or later; Joomla 4, 5 and 6, plus Joomla 3.9 and 3.10 with a dedicated plugin that runs even on PHP 7.1.
Before updating we save the plugin’s folder and the tables it may change, and check the pages. If errors, missing text or PHP fatal errors appear afterwards, we put files and database back and alert you. For three days you can also roll back by hand.
They are encrypted on the site before they leave and stay encrypted in European storage, locked against deletion. Each backup has its own key, kept encrypted by the platform. If a client asks, their backups can be locked with a key they keep: we store only the public half, and without their file nobody can open them.
Wordfence Intelligence for WordPress core, plugins and themes, and the Joomla Security Centre for the Joomla core.
Read-only access for end clients is on the roadmap, together with white-label monthly reports.
We’re inviting agencies in small groups, so we can set up the first sites together and fix what you find.