Security by design

Your WordPress password stays with WordPress.

PressMender starts read-only. If you later choose to connect WordPress, access is separate, limited, revocable and used only for features you request.

1

Public audit

PressMender reads a sample of pages that any visitor can already see. No login, plugin or website change is required.

2

You approve access

Install the lightweight connector and continue to WordPress. WordPress asks you to approve a separate Application Password.

3

Review every change

Paid actions are prepared as previews. PressMender applies only the fields you explicitly approve and keeps before-and-after data for rollback.

What PressMender never asks for

We do not ask you to type your normal WordPress administrator password into PressMender. We do not edit theme or plugin files, and a free audit cannot write to your website.

How connected access is protected

The connection uses a dedicated WordPress Application Password, encrypted at rest. Requests are limited to public HTTPS WordPress sites and authenticated requests are not followed through redirects. The connector also checks the connected user’s WordPress permissions before reading or changing content.

Approval and rollback

A recommendation is not permission to change your site. PressMender creates an approval preview first. Write actions require an active paid plan and your explicit approval. Supported changes retain the previous values so they can be rolled back.

Revoke access whenever you want

Disconnect the site from PressMender or revoke the PressMender Application Password from your WordPress user profile. Account deletion removes PressMender’s stored account, connection and product data according to our Privacy Policy.

Responsible limits

No software can remove every risk from website changes. PressMender uses compatibility checks, narrow permissions and approval gates, but business-critical WordPress sites should still maintain independent hosting backups.

See what PressMender finds first.

Run a read-only public audit without installing anything.

Audit my site

Security questions or a vulnerability report? Email security@pressmender.com.