New administrators
Instant alerts when a new administrator appears
The first step of almost every successful attack is one extra administrator account. Knowing at that moment changes everything.
The problem
A “wp-sync” user at three in the morning.
Attackers who exploit a plugin vulnerability almost always create an administrator so they can come back whenever they like. The account has a believable name and nobody notices it for weeks.
Security plugins inside the site are the first thing the attacker disables.
How it works
The agent sees the change, the platform keeps it.
- 1
Event on the site
The agent catches new users, role changes and administrator logins.
- 2
Sent at once
The event goes straight to the platform, signed. If sending fails it is picked up at the next sync.
- 3
Alert
A new administrator triggers a critical alert with username, email and time.
In detail
What’s tracked.
- New WordPress administrators and Joomla super users
- Role changes that grant administrator rights
- Administrator logins from IP addresses never seen before
- Up-to-date list of every site’s administrators in the dashboard
- Evidence stays on our servers even if the plugin is removed
FAQ
Frequently asked questions
What if the attacker disables the plugin?
The event has already left for the platform. And if the site stops answering the agent, you get an alert after three attempts.
Am I alerted when I create an administrator myself?
Yes, every new administrator is reported. If it was you, just acknowledge it.
Related features
Goes well with
Try it on your clients’ sites.
During the beta we welcome agencies in small groups and set up the first sites together.