Features

What Sentro keeps track of

Sentro is built for the everyday work of maintaining a portfolio of WordPress sites. Here is what to expect from each part of it.

Maintenance

Update management

Sentro reads which core, plugin and theme updates are pending for every connected site, including the current and the new version. Pick what to update and run it per site or across several sites at once.

  • Pending updates listed per site and per plugin
  • Bulk actions across multiple sites
  • Automatic updates can be turned on or off per type
  • Changelog link before you update

Update safety

Every update can start with a restore point on the site itself and a screenshot of the page. Afterwards Sentro takes a second screenshot and compares the two, so a broken layout is caught before your client notices.

  • Restore point created automatically before an update
  • Before and after screenshots compared for visual differences
  • An update is blocked when the restore point cannot be created
  • Skip the safety net per update when you need to

Backups

Trigger a full backup or a database-only dump and follow whether each attempt succeeded. Every backup shows its date, type, size and status.

  • Run a backup manually whenever you need one
  • Full backup or database only
  • Download the archive through a one-time link
  • Failed backups stay visible until resolved

Monitoring

Monitoring

Every site is polled at a fixed interval through a lightweight health endpoint. We record the response time and track when a site was unreachable.

  • Uptime percentage over the last thirty days
  • Response time chart
  • Incident list with start and end time
  • Email alert as soon as a site goes down

Status pages

Every site gets a public status page with its uptime history and current incidents, shared through a link. Your client checks the facts without needing an account.

  • Public link per site
  • Uptime history and open incidents
  • No login required for visitors

Activity log

Everything Sentro or a team member does lands in a chronological log, with the user's name and the time. That makes it easy to see afterwards who did what.

  • Per site or across all sites
  • System actions clearly marked
  • Basis for the client report

Security

Security checks

Every check looks at a fixed list of items that most often go wrong in practice. Each line has a status and a short explanation of what to do about it.

  • SSL certificate validity and expiry
  • Debug mode and file editing
  • Outdated core, plugins and themes
  • One security score per site

Malware and integrity scans

The connector scans core files, plugins and themes for malware patterns and unexpected changes. Scans run automatically every night and you can start one manually at any time.

  • Automatic daily scan for every site
  • Manual scan per site whenever you want
  • Findings grouped by severity
  • Requires connector 2.2.0 or newer

Licences and renewals

Register the premium plugin and theme licences you manage, with their renewal dates. Sentro keeps the overview and emails you before a licence expires.

  • Renewal dates in one overview
  • Email reminder before a licence expires
  • Linked to the site the licence belongs to

Workflow

Client reports

Put together a monthly report per client with the updates run, backups made, uptime and security status. On Pro and Lifetime you can add your own logo and colour.

  • Choose a period and a client
  • Share via a link or print to PDF
  • White label with your own logo and colour
  • Sent automatically every month or quarter

Team and roles

Working with colleagues, you decide who can do what. Owners manage billing and keys, admins connect sites, and members carry out the maintenance work.

  • Owner, admin and member roles
  • Invitations by email
  • Every action traceable to a person

Tags and groups

Group sites with your own tags: per client, per host or per maintenance window. Filter the site list by tag and run bulk actions for a whole group at once.

  • Multiple tags per site
  • Filter and select by tag
  • Bulk updates for a complete group

Connector plugin

The connection runs through our own plugin with a locked-down REST namespace. Sentro reaches the site with signed requests, so you never share login details.

  • Dedicated key pair per site
  • HMAC-SHA256 signing
  • Disconnect a site in one action
Architecture

The dashboard is not a WordPress site

A management hub concentrates access: it knows every site, and it can change every site. That is why Sentro runs as a separate application with its own database instead of as a plugin inside another WordPress install.

Sentro hubYour WordPress site

Signed request from the hub to the site. The site never calls back.

No second WordPress installation to protect

A dashboard built as a WordPress plugin holds the keys to every client site inside a WordPress admin. That means a public login page, a plugin ecosystem around it, a theme layer, and an update cycle of its own — all of it in front of the credentials for every site you manage. One vulnerable plugin in that install is not one site’s problem, it is every site’s problem. Our hub is a separate application: no wp-admin, no public login for a WordPress instance, no third-party plugin code running next to your keys.

Keys are encrypted and never shown

Each connected site gets its own signing secret. It is stored encrypted and is never displayed in the interface, never included in a report, and never exported — not for team members, not for us. Keys are scoped per site, so one revoked key affects one site and nothing else. A site owner can revoke or rotate the key from their own WordPress admin at any time, without asking us and without touching the other sites.

Signed requests, one direction only

The hub calls the site; the site never calls back. Every request is signed with HMAC over the method, path, body, timestamp and a one-time value, so an intercepted request cannot be replayed. Requests are rate limited, and the connector only accepts what is signed with that site’s own secret. Within that, the site owner decides per site what is allowed: updates, plugin state, backups, scans. Anything not enabled is refused at the site, not merely hidden in the dashboard.

Speed is a security property too

Because the hub is not running inside WordPress, checking a hundred sites does not depend on a PHP admin page staying open, on WP-Cron firing, or on one slow site holding up the rest. Checks run on their own schedule and monitoring keeps running, so an expired certificate, a failed update or a site going down surfaces when it happens instead of when someone opens a slow overview page.

This reduces the attack surface, it does not remove it. The connector’s permissions and the visible audit trail exist so a site owner can verify what happened.

See it in action

The demo environment contains sample sites with updates, backups and alerts, so you can follow the workflow before connecting a site of your own.