MultiCmsManager

For web agencies · WordPress & Joomla

Hear about the hack before your client does.

MultiCmsManager watches every site you look after from two sides: an agent inside the CMS that notices new admins, altered core files and PHP hidden in uploads, and checks from outside for downtime, expiring certificates, hijacked DNS and spam in the sitemap. At night it takes encrypted backups and updates plugins, rolling back on its own if something breaks.

We are onboarding agencies in small groups during the beta.

rossi-dental.example Tonight
  1. Critical New administrator “wp-sync” createdNo one was logged in
  2. Warning Sensitive file modified: .htaccessSize 1.2 KB → 3.9 KB
  3. Critical Executable file in uploadswp-content/uploads/2026/09/cache.php
  4. Sent Email and webhook sent to your team3 recipients
Still online. That is the problem.
  • WordPress 6.5+
  • Joomla 3.9 → 6
  • PHP 7.4+ (7.1+ on Joomla 3)
  • No new ports opened
  • Signed requests, both ways

§ 01Two sides of every site

Most tools look at a site from one side. Attacks use the other.

External monitors only see the home page. Security plugins live inside one site and are the first thing an attacker switches off. MultiCmsManager combines both views and keeps the evidence on its own servers.

Inside, with the agent

  • New administrators and role changes, the moment they happen
  • Core files compared with the official release, file by file
  • PHP hidden in upload folders, even disguised as .php.jpg
  • .htaccess, index.php, .user.ini and auto_prepend_file: where malware loads before the CMS does
  • Fatal PHP errors, and admin logins from IP addresses never seen before
  • Installed versions matched against known vulnerabilities

Outside, from our servers

  • Uptime and response time, plus a text check that catches defaced pages still answering 200 OK
  • SSL certificate and domain expiry, weeks ahead
  • DNS changes: a new nameserver is often the first sign of a hijack
  • Sitemaps full of pharma or casino URLs, and a robots.txt that hides the site from Google
  • Google, Spamhaus and other blacklists that put a red screen in front of visitors

§ 02Joomla, properly

Joomla isn’t an afterthought here.

Most multi-site dashboards are WordPress tools with a Joomla checkbox. Our Joomla agent is a native system plugin built on the same core as the WordPress one, so every feature ships for both on the same day.

Core integrity without official checksums
Joomla doesn’t publish file checksums, so we build them from the official Full Package of each version and compare every file on the site.
Read from Joomla itself
Super Users, extensions, pending updates and the native core auto-update setting come straight from the site, not from guesses on the front end.
Logins that behave like Joomla logins
One-click access uses the same flow as Joomla’s own passwordless login, so user plugins and action logs work as usual.
Even the sites left behind
A dedicated plugin for Joomla 3.9 and 3.10 runs even on PHP 7.1: monitoring, core integrity and backups for the sites nobody updates any more, with end-of-life warnings and the way to migrate them.

§ 03Tamper evidence

Proof, not a hunch.

When a core file changes, you see which one, compared with the official release of the exact version installed. Changed PHP in the core is critical. An edited template is just worth a look.

On a clean install: zero false positives across 3,336 WordPress files and 9,625 Joomla files in our tests.

Core integrity Joomla 6.1.3 · 9,625 files compared with the official release
libraries/src/Factory.php Modified Critical
plugins/system/sef/helper.php Not in the release Critical
templates/cassiopeia/index.php Modified Warning

§ 04Reputation

Spam pages don’t take a site down. They take its rankings.

Injected spam rarely touches the home page. It shows up as hundreds of new URLs in the sitemap, a robots.txt that hides the site from Google, or a blacklist entry that turns every visit into a red warning screen.

Sitemap

Sudden growth, links to other domains, URLs about pills, casinos or loans

robots.txt

Changes, and rules that block every search engine

Blacklists

Google Web Risk, Spamhaus DBL and ZEN, SURBL, SpamCop

DNS

New A, MX or nameserver records

SEO shield: compares what Googlebot receives, verified even from inside the site where cloaking can’t hide, with what a visitor from Google and a mobile visitor see. Conditional redirects and hidden links surface, and an optional AI opinion explains what to clean.

§ 05Safe updates

Updates that roll themselves back when they break a site.

Many updates change the database too: rolling back only the files leaves a site half-broken. Before each update MultiCmsManager saves the plugin’s folder and the tables it may change; if the pages stop working afterwards, it puts everything back.

  • A full backup no older than a day, then a restore point with files and tables
  • The home page and pages you choose, checked before and after: errors, missing text, lost styles, PHP fatal errors
  • Automatic rollback of files and database, then the pages are checked again
  • Levels per site: manual, security only, full; at night, in the site’s own timezone
  • A 48-hour delay for non-security releases and waves across the whole platform: a release that breaks sites stops for everyone
  • Expired licences: no failed attempts, just an alert

Today for WordPress plugins and themes. Joomla extensions and staging come next.

Safe update studio-rossi.example · tonight at 02:14
Site backup Tonight, 01:30 OK
Restore point Plugin folder + 3 tables OK
Shop Builder 8.1 → 8.2 Updated OK
Page checks PHP fatal error on /shop/ Error
Rollback Back to 8.1 in 4 seconds OK

§ 06Backups

Backups nobody can read or delete.

Database and files are compressed and encrypted on the client’s server, then uploaded straight to European storage. Even shared hosting copes: the work runs in short steps.

Encrypted before they leave

AES-256 with a different key for every backup: nothing readable stays on the site or in storage.

Incremental, yet complete

After the first one only changed files are sent, and every backup still restores in one pass, with no chain to rebuild.

Scheduled your way

Several schedules per site, say everything monthly and the database nightly, each with its own retention. Keep important backups forever.

Protected from deletion

Storage-level Object Lock: not even stolen credentials can delete them before they expire.

One-click restore

Database, files or both put back on the site from the dashboard, after a backup of the site as it is. Or download them as .sql.gz and .tar.gz.

Client-held keys, when needed

For demanding clients, backups can be locked with a key the client keeps: without that file nobody, us included, can open them.

§ 07One-click admin

Open any client’s admin in one click. Safely.

No shared password vault, no forgotten admin accounts. The platform asks the site for a login link that works once, for 60 seconds, and only on that domain.

  • Single-use token, valid 60 seconds, stored only as a hash
  • Issued through a signed request; the link can’t point anywhere else
  • Recorded on the platform and in the site’s own activity log
  • The site owner can switch it off in the plugin settings

§ 08Set up in minutes

Three steps. The first one already works.

  1. 1

    Add the site

    Paste the URL. Uptime, SSL, DNS, domain, sitemap and blacklist checks start straight away, no plugin needed.

  2. 2

    Install the agent

    A lightweight plugin for WordPress or Joomla. It opens no new ports and only answers requests signed with that site’s own key.

  3. 3

    Paste the code

    A one-time code connects the site. From then on you get inventory, security events and integrity checks.

    MCM1.eyJ1IjoiaHR0cHM6Ly9hcHAu…

§ 09Where it fits

What you’d otherwise stitch together from three tools.

WordPress-only dashboardsExternal scannersMultiCmsManager
WordPress and Joomla in one dashboard Rarely No Yes
Sees inside the site: new admins, core files, uploads Yes No Yes
Sees outside: uptime, DNS, blacklists, sitemap spam Partly Yes Yes
Core integrity for Joomla Rarely No Yes
One-click admin login Yes No Yes
Backups encrypted on the site, incremental Partly No Yes
Updates that roll back the database too Rarely No Yes
Joomla 3 and 4 still in production No Partly Yes

Based on the public feature pages of widely used tools, September 2026. Features vary by plan.

§ 10Security of the platform itself

Built like something you’d let into two hundred client sites.

No new ports opened

The agent only answers requests signed with HMAC-SHA256, with a timestamp and a single-use nonce.

Signed replies

Responses are signed too, so a firewall page or a cached error can never be mistaken for good news.

Hashes, not files

For sensitive files like your configuration, only fingerprints leave the site. Never their contents.

Nothing runs on page views

On normal visits the agent only listens for fatal errors. Heavy work runs in short steps sized for shared hosting.

Tied to your platform

Every downloaded plugin accepts only the platform it came from: a forged connection code cannot hand a site to anyone else.

Agencies kept apart

Each agency sees and controls only its own sites, and two-factor login is mandatory for every account. Automated tests check it on every release.

In development

What we’re building next.

In development

Second copy and test restores

A copy of the backups in a second storage and an automatic test restore every month, so you know they work before you need them.

In development

Staging and visual checks

Updates tried on a copy first, screenshots before and after, and safe updates for Joomla extensions too.

In development

Reports and client access

White-label monthly reports and read-only access for your clients.

§ 11Pricing

Priced per site, like it should be.

Pay for the sites you monitor. Add-ons only for the sites that need them.

Monitor

from $1.49 per site / month

Everything on this page that’s available today.

  • WordPress and Joomla
  • Uptime, SSL, DNS, domain, sitemap and blacklists
  • Security events and core integrity
  • Vulnerability matching
  • Safe updates with automatic rollback
  • One-click admin login
  • Email and webhook alerts
Get early access

SEO shield

from $1.99 per site / month

For sites where search traffic is the business.

  • Googlebot, visitors and mobile compared
  • AI opinion on cloaking and hidden links
  • 30 AI checks per month included

Backups

from $4.90 per 50 GB / month

Storage shared by all your sites.

  • Encrypted on the site before upload
  • Incremental, one-pass restore
  • One-click restore to the site
  • Several schedules per site
  • Protected from deletion

Planned launch pricing. Final prices will be confirmed before any billing starts.

§ 12FAQ

Questions agencies ask us.

Do I have to install a plugin?

No. Uptime, SSL, DNS, domain expiry, sitemap and blacklist checks only need the URL. The plugin adds everything that can only be seen from inside: new admins, core and file integrity, vulnerabilities, one-click login.

Will the agent slow my clients’ sites down?

On normal page views it only registers a handler for fatal errors. File scans and integrity checks run when the platform asks, in steps of a few seconds sized for shared hosting.

What if an attacker removes the plugin?

The platform notices: after three failed contacts you get an alert, and the outside checks keep running. The last known state stays on our servers.

Which versions are supported?

WordPress 6.5 or later with PHP 7.4 or later; Joomla 4, 5 and 6, plus Joomla 3.9 and 3.10 with a dedicated plugin that runs even on PHP 7.1.

What if an update breaks the site?

Before updating we save the plugin’s folder and the tables it may change, and check the pages. If errors, missing text or PHP fatal errors appear afterwards, we put files and database back and alert you. For three days you can also roll back by hand.

Where do backups go, and who can read them?

They are encrypted on the site before they leave and stay encrypted in European storage, locked against deletion. Each backup has its own key, kept encrypted by the platform. If a client asks, their backups can be locked with a key they keep: we store only the public half, and without their file nobody can open them.

Where does vulnerability data come from?

Wordfence Intelligence for WordPress core, plugins and themes, and the Joomla Security Centre for the Joomla core.

Can my clients see their own sites?

Read-only access for end clients is on the roadmap, together with white-label monthly reports.

Get early access.

We’re inviting agencies in small groups, so we can set up the first sites together and fix what you find.