Public audit
PressMender reads a sample of pages that any visitor can already see. No login, plugin or website change is required.
PressMender starts read-only. If you later choose to connect WordPress, access is separate, limited, revocable and used only for features you request.
PressMender reads a sample of pages that any visitor can already see. No login, plugin or website change is required.
Install the lightweight connector and continue to WordPress. WordPress asks you to approve a separate Application Password.
Paid actions are prepared as previews. PressMender applies only the fields you explicitly approve and keeps before-and-after data for rollback.
We do not ask you to type your normal WordPress administrator password into PressMender. We do not edit theme or plugin files, and a free audit cannot write to your website.
The connection uses a dedicated WordPress Application Password, encrypted at rest. Requests are limited to public HTTPS WordPress sites and authenticated requests are not followed through redirects. The connector also checks the connected user’s WordPress permissions before reading or changing content.
A recommendation is not permission to change your site. PressMender creates an approval preview first. Write actions require an active paid plan and your explicit approval. Supported changes retain the previous values so they can be rolled back.
Disconnect the site from PressMender or revoke the PressMender Application Password from your WordPress user profile. Account deletion removes PressMender’s stored account, connection and product data according to our Privacy Policy.
No software can remove every risk from website changes. PressMender uses compatibility checks, narrow permissions and approval gates, but business-critical WordPress sites should still maintain independent hosting backups.
Run a read-only public audit without installing anything.
Security questions or a vulnerability report? Email security@pressmender.com.