Born from the work that happens after “scan complete.”
PressPatrol is being built around evidence, containment, verification, and respect for the systems it monitors.
PressPatrol began with a real, high-pressure WordPress multisite recovery. The webroot held roughly 489,000 files. Routine cache, sitemaps, backup logs, premium plugins, custom code, and legacy residue sat beside genuine attacker artifacts. A simple “suspicious file” counter was not enough.
The operator’s standard
A careful response has to preserve evidence, separate known-good noise from malicious behavior, avoid breaking production, quarantine only what can be justified, and verify the site afterward. Those principles are the product.
Evidence first
A finding should say what changed and why it is suspicious before recommending action.
Contain precisely
Move the exact malicious file or attacker-created folder—not a broad parent directory full of legitimate content.
Prove recovery
Recheck core, services, endpoints, identities, and the live path after remediation.
Built for calm operations
PressPatrol is for people responsible for WordPress: business owners, agencies, developers, and infrastructure teams. The goal is not to create more security anxiety. It is to shorten the distance between a meaningful change and a confident decision.