What you need

A WebCrew account and one of two things: administrator access to the WordPress site (for the connector plugin), or the ability to add an SSH key for the site's user on the server (recommended). Nothing is installed on your hosting beyond the plugin or the key. The connection page compares the two side by side.

Way 1: the connector plugin

Step 1: download the connector

In the dashboard, choose Add a site. You get a zip file with your account key already inside it. One zip works for every site on your account, so an agency downloads it once.

Step 2: upload it like any plugin

In the site's wp-admin, go to Plugins → Add New → Upload, choose the zip, install and activate. The moment it activates, the site appears in your dashboard. There is nothing to configure on the site and no key to paste.

Way 2: SSH (recommended)

Step 1: copy the key

Add a site → SSH shows a public key made for your account. Copy it.

Step 2: add it for the site's user

In the hosting panel's SSH keys page, or in ~/.ssh/authorized_keys for the user that owns the WordPress files. Never root. There is a guide per panel: cPanel, Plesk, DirectAdmin, Cloudways, Kinsta, WP Engine, SiteGround, Hostinger, RunCloud, Ploi and a server without a panel. Then enter host, user and path in the dashboard. WebCrew connects, finds WordPress and runs the first file-level check.

Step 3, either way: read the first check

Uptime checks from the EU and the US start within minutes. The first full check, with versions, core integrity, administrators and known vulnerabilities, follows within the hour, and the site has a health score and, if anything was found, one or two findings with the action that resolves each.

What starts when, after connecting
WithinWhat runs
MinutesUptime checks from two regions; the site shows in your dashboard.
The first hourVersions, core integrity, administrators, plugin vulnerabilities, certificate. Health score calculated. With SSH: every file compared.
Around the clock afterUptime continuously; the security and version checks repeat during the day. Findings that appear or disappear are listed as changes.
Nothing on the site is changed by connecting it. Updates wait for your approval.

Removing a site

Deactivate or delete the connector plugin, or remove the SSH key in the dashboard, and the site is disconnected. Its history stays in your dashboard until you delete the site there too. Nothing on the site depends on WebCrew to keep working.

Moving from another tool

WebCrew connects a site from today onward. It does not import another tool's logs, backups or history, so you can keep the old tool running alongside for a month and compare what each one finds.