Update every client site without breaking one.
WP Nexus runs updates, security scans and backups across your whole WordPress fleet — with rollback that fires automatically when something goes wrong, and an audit trail that shows exactly what happened.
No card required
Every change reversible
Agency workspace
Change readiness
Sites in scope
12
Ready to update
9
Held back
3
Compatibility checked
Verified against the target release
Approval outstanding
Needs sign-off before it runs
Restore point
No verified backup attached yet
Example view. Figures are illustrative.
Automatic
rollback on failed updates
A rollback artifact is retained before anything is touched. If post-update health checks fail, the previous release is restored and verified.
Works at 500
when WordPress is down
A recovery channel that runs independently of WordPress. When every REST route is failing, it still reports database, disk and version state.
Every change
attributable and reviewable
Who ran it, against which site, with what result. Destructive actions require step-up confirmation and leave an immutable record.
Stop finding out from the client.
Most fleet tools tell you an update succeeded. Nexus proves the site still works afterwards — and puts it back if it does not.
One view of the fleet
Health, security findings, backup state, versions and pending work across every client site — without opening thirty wp-admin tabs.
Updates that fail safe
Updates run behind a preflight that refuses to proceed when recovery is unavailable, then verify health before calling the change done.
Evidence your client can read
Backups with verified restores, scan history, and a change log you can put in front of a client without translating it first.
Automation should tell you when it is unsure.
A tool that hides its limits is the one that breaks a client site quietly. Nexus is explicit about the difference between a plan and an execution, a check that passed and one that was skipped, a backup taken and a restore actually verified.
Read the security modelCredentials never reach the browser
Site keys, tokens and provider payloads stay server-side. The interface only ever receives safe projections.
Failure states stay visible
Stale, unavailable, denied and ambiguous are shown as themselves — never quietly rendered as success.
Destructive actions need a person
Deletions and restores require step-up confirmation and leave an immutable record of who approved them.
Bring us your most fragile client site.
We will walk through how Nexus would handle it. No subscription starts from this conversation.