Connecting a site
Two ways to connect a WordPress site. One takes five minutes, the other sees more.
Upload the connector plugin in wp-admin and the site is in your dashboard before the page reloads. Add one scoped SSH key on the server and WebCrew can also check files, update faster with a full restore point, and help clean a site that was compromised.
Free for one site. No card. Nothing on the site changes by connecting it.
Side by side
What each connection needs, and what it unlocks
Connector plugin
Needs: administrator access to wp-admin. Nothing else.- Uptime 24/7 from two regions, health score, versions of core, PHP, theme and plugins
- Unknown administrators, known vulnerabilities per plugin, core-file integrity through WordPress
- Updates with a restore point and the code difference kept; one-click login
- The assistant and your own AI tools over MCP
Five minutes. The plugin is the only thing installed; deleting it disconnects the site. Works on any host, including managed hosts without shell access.
SSH
Needs: one public key added for the site's own user on the server.- Everything the connector does
- File-level integrity: every file compared, not only what WordPress reports; changed and added files listed with their time
- Updates and restore points at file and database level, so the way back covers the whole site
- Cleanup help when a site is compromised; staging copies later
Ten minutes. The key is scoped to the site's user, never root, and is revoked from your dashboard at any time. Needs a host that allows SSH keys.
Step by step
Connecting with the plugin
Download the connector
In the dashboard, choose Add a site. You get a zip with your account key already inside. One zip works for every site on your account, so an agency downloads it once.
Upload it like any plugin
Plugins → Add New → Upload, choose the zip, install, activate. The site appears in your dashboard the moment it activates. Nothing to configure, no key to paste.
Read the first check
Uptime from two regions starts within minutes. The first full check, with versions, integrity, administrators and vulnerabilities, follows within the hour, and the site has a health score.
Connecting with SSH
Copy the key
Add a site → SSH shows a public key made for your account. Copy it.
Add it for the site's user
In the hosting panel or in ~/.ssh/authorized_keys for the user that owns the WordPress files. Never root. Where that page is in cPanel, Plesk, DirectAdmin and the others.
Enter host, user and path
WebCrew connects, finds WordPress, and runs the first file-level check. The connector plugin is not needed; you can keep it for the wp-admin assistant later.
Your hosting panel
Where the SSH keys page is in your panel, step by step
Every panel puts the keys page somewhere else. Pick yours for the exact clicks, the host, user and path to enter, and what to do if your plan has SSH switched off.
The first hour
What happens after you connect, and what does not
Connecting reads. Nothing on the site changes on the first day unless you set a schedule. Updates run when you tell them to, the assistant drafts, and the site keeps running exactly as before.
| Within | What runs |
|---|---|
| Minutes | Uptime checks from two regions; the site shows in your dashboard. |
| The first hour | Versions, core integrity, administrators, plugin vulnerabilities, certificate. Health score calculated. With SSH: every file compared. |
| Around the clock after | Uptime continuously; the security and version checks repeat during the day. Findings that appear or disappear are listed as changes. |
| Never | A change to content, settings or code without a person approving it first. |
When a site is compromised
We help clean it. We do not promise it stays clean.
With SSH, WebCrew can replace changed core files, remove administrators nobody created, and update or remove the plugin that let the attacker in, with a restore point before each step. No tool can guarantee a site never gets hacked again, and we do not write that anywhere.
What the security scan checksQuestions
Before you connect
Do I have to choose one?
No. A site can have both. The plugin gives the wp-admin assistant a home; SSH gives the file-level checks, cleanup and the full restore point. Start with whichever your host allows today.
Is the SSH key safe?
It is a key pair made for your account; the private half never leaves WebCrew's infrastructure in the EU. You add it for the site's own user, never root, and revoke it from the dashboard at any time. Every action taken over it is in the site's log.
My host does not allow SSH.
Use the connector plugin. Monitoring, security scan, vulnerability matching, updates with a restore point and the assistant all work through it. File-level cleanup then becomes a list of steps for you or the host.
What about staging sites?
Connect them too; staging copies are not billed. Updates tested on a copy before the live site follows are coming soon and will use the SSH connection.
How do I disconnect?
Delete the plugin, or remove the key in the dashboard. The site's history stays until you delete the site there too. Nothing on the site depends on WebCrew to keep working.
Connect the first site now. The first check is done within the hour.
Free for one site. No card.