MultiCmsManager

New administrators

Instant alerts when a new administrator appears

The first step of almost every successful attack is one extra administrator account. Knowing at that moment changes everything.

The problem

A “wp-sync” user at three in the morning.

Attackers who exploit a plugin vulnerability almost always create an administrator so they can come back whenever they like. The account has a believable name and nobody notices it for weeks.

Security plugins inside the site are the first thing the attacker disables.

How it works

The agent sees the change, the platform keeps it.

  1. 1

    Event on the site

    The agent catches new users, role changes and administrator logins.

  2. 2

    Sent at once

    The event goes straight to the platform, signed. If sending fails it is picked up at the next sync.

  3. 3

    Alert

    A new administrator triggers a critical alert with username, email and time.

In detail

What’s tracked.

  • New WordPress administrators and Joomla super users
  • Role changes that grant administrator rights
  • Administrator logins from IP addresses never seen before
  • Up-to-date list of every site’s administrators in the dashboard
  • Evidence stays on our servers even if the plugin is removed

FAQ

Frequently asked questions

What if the attacker disables the plugin?

The event has already left for the platform. And if the site stops answering the agent, you get an alert after three attempts.

Am I alerted when I create an administrator myself?

Yes, every new administrator is reported. If it was you, just acknowledge it.

Try it on your clients’ sites.

During the beta we welcome agencies in small groups and set up the first sites together.