← All solutions

Solutions · Catalyst Sentinel

Catalyst Sentinel

The security and recovery layer we run on every WordPress site we manage — including this one.


Our own WordPress integrity and defacement monitor. It captures a known-good baseline of your site — approved admins, active plugins and theme, high-risk file hashes, and the rendered output of your critical pages — then watches for anything that changes without permission.

It was built to answer one question honestly: did something on your site just change that shouldn’t have — and can we get you back to normal fast if it did?


01 · Dashboard

One score for your whole security posture.

See exactly what’s pulling your score down, and fix each item with one click. No vague “you might be at risk” messaging — a concrete checklist, in order of what actually matters.


Catalyst Sentinel dashboard showing an 84/100 security score and a checklist of what would raise it

Dashboard — one score, a plain checklist of what’s pulling it down, and one-click fixes. Click to enlarge.

02 · Hardening

Controlled, reversible security measures.

Toggle real protections on and off — file editor lockdown, XML-RPC, public registration, PHP execution in uploads. Nothing fires automatically, and every change can be switched straight back.


Catalyst Sentinel hardening screen with reversible one-click security toggles

Hardening — recommended measures and what’s already active. Click to enlarge.

03 · Recovery Vault

Backups verified before we’d ever trust one.

Every backup gets a SHA-256 hash and AES-256 encryption, and a real “Verify” step that proves it actually restores clean — not just that a file exists somewhere.


Catalyst Sentinel Recovery Vault showing an encrypted, verified backup with a passed status

Recovery Vault — encrypted, hashed, and verified before it’s ever trusted. Click to enlarge.

04 · Integrity Monitor

Know exactly what changed.

A known-good baseline of your approved admins, active plugins, theme, and critical files — one place to see what drifted from it, and decide whether that was actually you.


Catalyst Sentinel Integrity Monitor showing the approved-admin baseline

Integrity Monitor — the known-good baseline everything else is measured against. Click to enlarge.


  • Defaced pages and injected content — even when the files look untouched
  • Hidden spam links and SEO poisoning in page output
  • New or elevated administrator accounts you didn’t create
  • Plugins or themes activated, swapped, or modified off-baseline
  • Changes to wp-config.php, .htaccess, and other high-risk files
  • PHP files appearing where they shouldn’t, like the uploads folder

  • Continuous drift detection — a known-good snapshot of your admins, plugins, theme, and core files, checked automatically, plus page-content scanning that catches defacement and hidden spam links a normal backup plugin would never notice.
  • A single security score — one number for your whole posture, with a plain checklist of exactly what’s pulling it down and a one-click fix for each item.
  • Plain-language alerts, sorted by what matters — every finding gets a severity and a category, tracked on a cleanup board so nothing quietly falls through the cracks.
  • One-click lockdown — if something looks wrong, disable the file editor, force every admin to log back in, and block PHP files hiding in uploads, in seconds, without touching anything else.
  • Passkey-protected sensitive actions — WebAuthn step-up on the settings and roles screens where real damage happens, so a stolen password alone isn’t enough.
  • Quarantine, never delete — suspicious files are moved out of harm’s way, not destroyed, so nothing is ever lost to a false alarm.
  • Guided recovery — a step-by-step cleanup checklist built for the specific incident, not a generic “reinstall WordPress” article.
  • Two-person approval on the risky stuff — deleting a page, a user, or a batch of media can require a second set of eyes, with a full log of who did what and a one-click undo.
  • Backups verified before they’re trusted — test-restored into an isolated copy of your database before we’d recommend using one, so a recovery is proven safe first.
  • A break-glass way back in — a separate emergency admin identity that never uses a normal password, for the case where every other login is compromised.
  • Built for managing many sites, not just one — save a security policy once and apply it across every client site we watch, instead of configuring each one by hand.

Baseline

On day one it records a known-good snapshot: approved admins, active plugins and theme, high-risk file hashes, and the rendered HTML of your critical pages.

Watch

It re-checks on a schedule and flags anything that has drifted from that baseline — with a severity, a category, and a spot on the cleanup board.

Recover

Quarantine instead of delete, backups proven safe before use, and a break-glass admin to get back in when every other login is gone.


Want this watching your site?

Talk to our team