Patchstack automatically identifies and mitigates security vulnerabilities in WordPress plugins, themes, and core.
As of April 2026, Patchstack is a WordPress firewall plugin with 40K+ active installations and a 4.9/5 rating from 61 reviews. It has been downloaded 563K+ times in total. Requires WordPress 4.4+ and PHP 5.6+. Available on WordPress.org since 2021. Recently updated within the last 3 months. Downloads are up 72% this week. Support resolution rate: 0%. Top alternative: Wordfence Security – Firewall, Malware….
Patchstack is a powerful tool that helps identify security vulnerabilities within your websites’ plugins, themes, and WordPress core. It is powered by the WordPress ecosystem’s most active community of ethical hackers. Patchstack is trusted by leading WordPress experts such as Pagely, Cloudways, GridPane, Plesk, and others!
Patchstack is a security plugin for WordPress that finds WP core, plugin and theme vulnerabilities in your websites.
The free version includes up to 48-hour early warning for new vulnerabilities found by our security research community. It also allows you to automatically update vulnerable software, manage updates remotely, and get snapshot reports on your sites’ security status.
The paid version includes automatic vulnerability protection. Patchstack deploys hi…
Originally this was a 1 star review but triage team turned it around. Patchstack published CVE-2025-57923 and did not respond for a couple weeks while we actively tried to respond to a purported vulnerability.
However the Head of Threat Intelligence at Patchstack reached out to us directly. We were able to communicate directly, understand the underlying concerns and he helped us resolve this issue within hours. Very helpful. Triage team obviously doing their best. Much credit to them.
Patchstack has been a great tool for keeping my WordPress sites secure. I really like the early vulnerability alerts and the virtual patching feature—it gives me peace of mind knowing that known issues are blocked even before plugins are officially updated.
It’s lightweight, doesn’t slow down the site, and the dashboard makes it easy to monitor multiple installations.
That said, it’s not a complete security suite—so I still use it alongside a firewall. But as a vulnerability monitor and patching layer, it works very well.
Highly recommended.
Was talking to their AI support and it automatically switched to human who solved my issue by herself. Never saw this ! perfect support, perfect tool for security combined with CF
Patchstack is a must have for security. Their support is awesome too!
An excellent and valuable service that’s backed by a company that contributes a significant amount of resources and money directly back to the WordPress ecosystem.
| WordPress | 4.4+ requiredTested up to 6.9.4 |
| PHP | 5.6+ required |
To view the plugin changelog, go here.
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.