

SiftWP connects through a dedicated SSH key, runs a full security scan, then sends an AI agent to investigate and fix what it safely can, pausing on anything risky and escalating what it can't reach.

SiftWP is a weekly WordPress security scanner that connects through a dedicated SSH key instead of a plugin — nothing installed inside WordPress, no added load on your site's PHP or database. Each week it runs a full scan of core files, database integrity, and known attack patterns, then hands findings to an AI agent that investigates before acting: low-risk, well-understood issues (a corrupted core file, a BOM-encoding bug, a known plugin conflict) get fixed automatically; anything touching credentials or site settings pauses and waits for your explicit approval; and anything outside WordPress's own scope — a server-level fix your host needs to make — gets escalated with a ready-to-send support ticket already drafted. SiftWP is built for site owners and agencies who want consultant-level security review without hiring a consultant or babysitting a dashboard. Every account starts with 100 free credits and a first scan on the house, so you see exactly what it finds before picking a plan. Paid plans run $9–$49/site/month depending on how hands-off you want fixes to be, plus a one-time $199 emergency cleanup for sites that are already compromised.