Xponent Docs

The manual for your managed site.

Docs Category: Security & Governance

Backups & Restores

Last Updated: August 31, 2026

Overview Every Xponent site is backed up automatically. If anything goes wrong (a bad update, an accident, or a security incident) we can restore your site to a known-good state. The Xponent Backup Standard Item Standard Schedule Automated daily backups (more frequent on the higher tiers) What’s included Full site: database, files, uploads, plugins Verification...

Fatal Error Catcher: Auto-Heal & Crash Logs

Last Updated: August 31, 2026

Overview A fatal error in a plugin can white-screen a site in seconds. XPulse includes a fatal error catcher that detects crashes, keeps the site online, and notifies the team: turning a potential outage into a logged incident. The Alerts Alert Meaning Auto-Healed Fatal Crash (critical) A fatal error was caught and the offending plugin...

How Xponent Secures Your Site

Last Updated: August 31, 2026

Overview Security on Xponent is layered and mostly invisible to you: we handle it so you can run your business. This article explains the layers protecting your site and what your role is. The Security Layers Layer What it does Managed infrastructure Isolated GridPane containers, hardened server baseline, automatic core updates Patchstack protection Real-time vulnerability...

Security Headers: The Complete Set

Last Updated: August 31, 2026

Overview Security headers are HTTP response headers that tell browsers how to behave: blocking downgrade attacks, clickjacking, content injection, and MIME-sniffing. XPulse audits your site for the recommended set; when any are missing, the site is flagged. The Alert SECURITY_HEADERS (warning): not all recommended security headers are present. The 6 Headers the Audit Checks Header...

SSL Certificates & HTTPS

Last Updated: August 31, 2026

Overview SSL (Secure Sockets Layer) encrypts the connection between your visitors and your site (the padlock in the browser bar). All Xponent sites run HTTPS with auto-renewing certificates. There is nothing you need to do. Common Situations Situation What happens You add a domain/subdomain We issue a new certificate for it You move DNS to...

Vulnerability Scanner: Outdated-Plugin Detection

Last Updated: August 31, 2026

Overview Keeping plugins current is the single most effective WordPress security practice: most real-world exploits target known vulnerabilities in outdated plugins. Xpulse monitors your plugin update status using WordPress’s own update data and flags anything that needs attention, with no third-party feeds and no API keys. The Alerts Alert Meaning Plugin Update Feed Unavailable (warning)...