Catch issues across every client site, before they email you.
Guardian Gaze for agencies brings code-level WordPress security to every site you manage. Bulk Pro licences, one dashboard, regular scans, plain-English findings, and the option to escalate to the RedSecLabs research team.
One hacked client site costs more than a year of monitoring.
Agencies live with risk that solo site owners don't, many clients, many WordPress installs, and a reputation that one ugly compromise can damage for months.
"Did this client get hacked again?"
Without scheduled scanning across every site, you don't know about a compromise until someone notices. Often that someone is the client.
Each clean-up eats a week.
Investigating a hacked WordPress site (finding every backdoor, every reinfection path, every modified file) takes time you weren't planning to spend.
Catch it before the call.
With Guardian Gaze running on every client site, you get scan results and alerts when something looks wrong, before the client sees it.
Everything in Pro, times your site count.
Available now
Included in Agency Starter today
- โ Bulk Pro licence keys (10+ sites)
- โ Volume discounts (10 to 20% off)
- โ All Pro features on every site
- โ Keys delivered to your dashboard instantly
- โ Export licence keys as CSV
- โ Priority support (4h SLA)
- โ Same plain-English findings as Pro
In development
Coming in 2026
- โ Multi-site central dashboard
- โ Client-facing security reports
- โ Bulk scan scheduling
- โ White-label report branding
- โ Agency billing consolidation
From purchase to protected, in four steps.
Buy bulk licences
Purchase the Agency Starter plan with 10+ Pro licences at a volume discount. Keys are delivered to your dashboard instantly.
Assign to client sites
Add each client site to your dashboard. One Pro licence key is automatically assigned per site, no manual activation needed.
Schedule and triage
Guardian Gaze scans on your schedule. Results appear in plain English so you can triage at a glance, not debug code.
Escalate if critical
Anything the scanner flags as critical can be escalated to the RedSecLabs research team for expert review.
Start with 10 sites. Scale as you grow.
10 Pro licence keys from $1,341/year (10% off). 20+ sites gets you 15% off, 50 sites 20% off.
Security is a cost centre until a client can see it
Most agencies absorb WordPress security as invisible overhead. It gets done because it has to be, it never appears on an invoice, and it is the first thing cut when a retainer comes under pressure, precisely because the client has never seen evidence that it happens.
That is a positioning problem rather than a technical one. The work is real, it takes time, and it prevents outcomes that would cost the client far more than the retainer. What is missing is a document that makes it visible in language the client understands.
White-label reporting is the mechanism. A monthly report under your branding showing what was scanned, what was found, what was blocked and what was fixed turns an invisible cost into a defensible line item, and often into something you can charge for separately rather than absorb.
The problems become administrative, not technical
At three sites, security is a task. At twenty it is a process, and the failure mode is not missing a finding: it is a dashboard nobody has opened in three weeks because opening it costs twenty minutes.
So the tooling that matters at scale is unglamorous. Configuration sync pushes one hardening profile across the fleet rather than configuring each site by hand. Bulk scheduling handles scans across the estate and staggers them so twenty sites are not all scanned in the same hour. Digest emails summarise what changed across the whole estate in something readable over coffee.
One dashboard across sites is the difference between reviewing security and intending to. Pro covers up to five sites; beyond that, Agency licensing is cheaper per site and adds the fleet tooling.
The free plugin is a business development tool
The free tier is a complete scanner: all four detection layers including the database, permanently, with no account. That makes it genuinely useful for winning work rather than a limited demo.
Running a free scan on a prospect's site produces specific evidenced findings you can show them, which is a far stronger pitch than describing your process. Agencies use exactly this to win audits and migrations, and we would rather that happened than gate the scanner behind a licence.
For an existing client it settles the recurring argument about whether the security line item does anything. Findings with file paths and severity are hard to wave away in either direction, which is also why the report is worth sending when it comes back clean.
Volume pricing, no per-seat charge
Agency licences start at 25 sites, with volume bands applied automatically at checkout rather than negotiated. The discount widens with fleet size, so the per-site cost falls as the estate grows.
There is no per-seat charge. Everyone at the agency who needs the dashboard has one, because per-seat pricing encourages password sharing and then penalises you for it.
Licences count active sites rather than binding to specific domains, so when a client leaves you reassign the slot. Agency rosters change constantly, and a licence that punishes that is one you end up working around.
Common questions
Can we white-label the reports?
Yes, on Agency. Your branding, written for a non-technical reader, forwardable to a client without an editing pass to strip ours out.
What is the minimum for Agency licensing?
25 sites. Below that, buying Pro per site is cheaper and you would not use the fleet tooling anyway.
Can we use the free plugin to audit prospects?
Yes, and we would encourage it. The free tier runs all four detection layers including the database scanner, so a prospect audit produces real evidenced findings rather than a sales demo.
Do we pay per seat for our team?
No. Licensing counts monitored sites rather than users, so everyone who needs the dashboard has one.
What happens when a client leaves?
Reassign the slot. Licences count active sites rather than binding to specific domains, because agency rosters change constantly.
How do we configure twenty sites without doing it twenty times?
Configuration sync pushes a hardening profile across the fleet and keeps new sites consistent from the day they are added. Bulk scheduling handles scans and staggers them across the estate.

