Overview #
PatchStack is our vulnerability protection layer: it detects known security holes in your plugins, themes, and WordPress core, and applies virtual patches before an update exists. It is part of the Xponent security standard, licensed by Xponent and included with your plan.
What’s Included #
- PatchStack license: managed by Xponent, included with your plan
- Virtual patching: vulnerable code is neutralized even when the vendor hasn’t released a fix yet
- Vulnerability detection: continuous scanning of your installed plugins and themes
- Central dashboard: one panel covering every protected site
How Patching Works #
- Detect: PatchStack matches your installed plugins against a live vulnerability database.
- Protect: a virtual patch is applied instantly, no update required.
- Update: when the vendor ships a real fix, it is installed via managed updates and the virtual patch is retired.
The Xponent Standard #
| Practice | Why |
|---|---|
| Every site patched | Virtual patches close holes in hours, not days |
| No user action | You never see a security panel: it just works |
| CleanTalk covers spam | Anti-spam and patching are separate layers, no overlap |
| Logged and visible | Protection status visible in the Xpulse dashboard |