Start trial

Case study: ManageWP Blocks 11.9M+ Threats in 6 Months with Patchstack

ManageWP blocks 11.9M+ vulnerabilities with their Patchstack-powered add-on, freeing up countless hours for agency owners.

PublishedAugust 24, 2026
Lana Rafaela avatar
Lana Rafaela
Product Marketing Manager at Patchstack

11.9M+

Threats blocked by Patchstack in 6 months

Zero

Hours of sleep lost

Run one WordPress site and a vulnerability is a single bad day. Run an agency, and it’s a portfolio-wide panic event that results in lost sleep and enough caffeine to take down a horse.

Updates can’t close that gap alone, especially when attackers weaponize the most-targeted vulnerabilities in a median of five hours, and nearly half have no update available the moment they go public. WordPress.org’s “Protect the Shire” policy, live since June 2026, adds up to a 24-hour hold on every plugin and theme release before it reaches sites.

For an agency, that’s not fifty separate problems to triage. It’s one portfolio-wide exposure, and it needed a portfolio-wide answer. ManageWP recognized Patchstack as the right partner in preventing damage, resulting in 11.9M+ threats blocked in the last 6 months of our partnership. 

Agencies need more than vulnerability visibility. They need protection that works at scale. By partnering with Patchstack, we’re giving our customers proactive security directly inside ManageWP, helping them stay ahead of emerging threats across their entire portfolio. Blocking more than 11.9 million threats in six months proves what’s possible when security is built into the workflow.

Predrag Zdravkovic @ ManageWP

The solution: Vulnerability protection as an add-on

Patchstack has been powering ManageWP’s Vulnerability Protection since February 2026, as a native add-on inside the ManageWP dashboard. 

Agencies see every client site’s vulnerability exposure in one view and turn on protection across the whole portfolio – no per-site logins, no code changes, no waiting on an update to ship.

Patchstack in ManageWP dashboard

For ManageWP’s team and their agency customers, that means:

1️⃣

Vulnerability protection activates as an add-on inside the existing ManageWP dashboard – no separate tool to log into.

2️⃣

Every protected site gets mitigation rules applied automatically the moment a vulnerability is identified, closing the gap before a patch exists or clears WordPress.org’s review window.

3️⃣

Agencies get one portfolio-wide view of exposure across every client site, instead of triaging site by site while the clock runs.

The results

Over 6 months, Patchstack blocked 11.9M+ threats across sites protected through ManageWP’s Vulnerability Protection add-on – without a single one needing an emergency update or a manual patch.

  • 11.9M+ threats blocked in 6 months
  • Zero code changes on any protected client site
  • One dashboard view across the full client portfolio, replacing site-by-site triage

What’s next for ManageWP and Patchstack?

Fewer 2 am tickets, fewer client calls about a hacked site – that’s what happens when protection covers the whole portfolio, not just the sites someone remembered to update. 

And with our two teams working closely together to swap notes, test edge cases, and show up in person to make preventive security work, ManageWP’s users are in good hands. 

Want to turn client maintenance plans into a secure, high-converting add-on? Let’s talk about how Patchstack can help.

trusted security partner for

logo/affiliate/hostinger

Like it? Share it.

Related articles