New · SSL and domain expiry

One panel for all your WordPress installations

Updates, security with real CVEs, uptime, backups and certificate and domain expiry — in a single panel, for people who look after someone else's WordPress sites.

Bulk updates AI-powered scans Automatic backups
Start for free · 5 sites includedExplore the features
5 sites free forever. No credit card.
Connect your first site in a couple of minutes.
Preview · sample fleet
60suptime check
DB + filebackup and restore
AES-256encrypted credentials
01Features
20 modules · 1 panel

Everything you need to run the fleet

One panel instead of dozens of logins. Monitor, update and secure every site from here.

24/7 uptime monitoring

99.98%

External check every minute. But “it responds” is not enough: WordPress returns 200 even when it is dead. Helm looks inside the page.

Database error or critical screen
Blank page served with a 200
Your keyword gone from the page
−30 days1 downtime · 52stoday

Safe updates, in bulk

Core, plugins and themes across the fleet in one click. Helm backs up first, checks the site still responds afterwards and rolls back on its own if anything breaks.

woocommerce9.8.1 9.9.0
elementor3.30.2 3.31.0
wordpress-seo25.1 25.2

Security with real CVEs

Known vulnerabilities from the Wordfence Intelligence feed, not generic advice: affected component, version and a fix you can apply fleet-wide.

outdated plugin · known CVEHigh
xmlrpc.php exposedMedium
missing X-Frame-Options headerLow

AI copilot

Helm AI

Ask in plain language what is going on across the fleet. The copilot answers on real data and proposes actions: nothing runs until you confirm.

> which sites have plugins with known CVEs?
3 sites affected — studio-rossi.it, shop-verde.com, clinica-sole.it. The patch is available for all of them: I can update them with a backup first.

Expiries you see coming

HTTPS certificates and domains have a date, written months in advance. We warn you at 30, 14, 7, 3 and 1 day — and two months ahead for the domain.

HTTPS86 days
Domain41 days

Traffic for every site

Visits over the last 30 days, right next to the site status — no separate analytics panel to open per client.

12,480visits · 30 days

Performance, measured by Google

The PageSpeed score every week, with its history — and below it, what to do to raise it, with the estimated saving next to each item.

99out of 100 · mobile

Public API

API

Keys with the scopes you choose, rate limiting and documentation: updates, backups, security and uptime from your own code.

$ GET /api/v1/sites
200 · 24 sites

Automatic backups

Database and files, hourly or daily, with restore and configurable retention.

One-click wp-admin login

Get into any site without shared passwords: single-use token valid for 60 seconds.

Client-ready reports

Automatic monthly summary with the site's real numbers and an AI-written recap.

Telegram + email alerts

Real-time alerts on downtime, vulnerabilities and failed backups, without the noise.

Team and clients with roles

25 granular permissions, a client role and access limited to assigned sites only.

Plugins across many sites

Search wordpress.org and install or update across the whole fleet in one go.

Unified activity log

Who did what and when, including changes made outside of Helm.

Maintenance mode

Put a site in maintenance with your own message: uptime stats stay clean.

Broken links

Dead links in your content, grouped by address and fixed in one click.

Backups verified nightly

We re-read the copies and check they hold up: a broken archive surfaces early.

It sees other people's updates too

Made from wp-admin or automatically: we tell you, and for 48 hours you can roll back.

Articles written and published

Text and images generated and filed into WordPress, as drafts or scheduled.

And everything else, in full

The complete list of what the panel does today. No “coming soon”: if it is written here, it is in.

Monitoring

  • External check every minute, with a confirmation threshold before the alert
  • Recognises WordPress error screens and blank pages
  • A keyword that must — or must not — appear on the page
  • Availability measured over time, with twelve months of history
  • HTTPS certificate and domain expiry, with staged warnings
  • Response times, incident log and an on-demand check
  • PageSpeed performance, with the fixes and their estimated saving

Security

  • Known vulnerabilities from the Wordfence Intelligence feed, with CVE and affected version
  • Security score per site and fleet average
  • Plain-language explanation and ordered remediation steps
  • Fixes applied from the panel, after your confirmation
  • An “ignore” rule that survives later scans
  • WordPress users: who they are, their role, who to block

Updates

  • Core, plugins and themes across the fleet in one operation
  • Automatic backup before every update
  • Checks the site responds afterwards, and rolls back if it doesn't
  • Auto-update configurable plugin by plugin
  • Install from wordpress.org across several sites at once
  • Activate, deactivate and delete plugins remotely
  • Covers updates made from wp-admin, from the command line, or automatically by WordPress
  • A verification page of your choosing: after an update we check the checkout, not just the homepage
  • A «Roll back» button, for 48 hours, on anything updated without going through Helm

Backup and restore

  • Database and files, on an hourly or daily schedule
  • Configurable retention, site by site
  • Restore from the panel, in chunks, without FTP
  • Archive download through an expiring link
  • Storage included in the plan, always visible
  • Nightly verification: every copy is re-read and checked, incremental chains included
  • No size ceiling: it prepares in slices and resumes where it left off
  • Incremental archives: after the first one, only what actually changed is saved
  • wp-config.php inside the archive, for the day you have to rebuild elsewhere

Content

  • An article written, illustrated and filed into WordPress
  • Images generated and uploaded to the media library
  • Draft, immediate publication or scheduling
  • Automatic editorial plan with a monthly spending cap
  • Credit estimate shown before you generate
  • Broken links in your content: grouped by address, fixed in one click inside WordPress

Team, clients and integrations

  • 25 granular permissions and a read-only client role
  • Access limited to the sites assigned to each person
  • Monthly report with a public link to send to the client
  • Email and Telegram notifications, chosen by category
  • Public API with keys, scopes and rate limits
  • Unified activity log, including changes made outside Helm
  • Reports and emails with your brand: name, logo, colour and closing line.
Everything you have just read is already in the free five-site plan.Try it now
02How it works
setup ≈ 3 min

Up and running in three steps

[ 01 ]

Connect your sites with the Helm connector

Install the connector plugin and Helm detects core, plugins and themes in seconds.

$ wp plugin install helm-connector --activate
[ 02 ]

Monitor, update and secure

A single panel for updates, scans and backups across the whole fleet.

$ helm update --all --backup-first
[ 03 ]

Get alerts when it really matters

Instant notifications when a site goes down or a new vulnerability shows up.

alert Telegram · @agency-ops · 12:04:31
03 Helm AI

A security copilot for every site

The AI analyzes every installation, recognizes known vulnerabilities and explains them in plain language — with practical steps to fix them. No CVEs to decipher: just what happened and what to do.

Plain-language explanations, no technical jargon
Fix steps ordered by priority
Fixes you can apply straight from the panel
MediumXML-RPC vulnerability
studio-rossi.it
/xmlrpc.php · exposed endpoint
AI explanation

The XML-RPC endpoint is active and can be exploited for password brute-force attacks or to amplify requests (pingbacks). If you don’t use external apps or the WordPress mobile app, it’s best to disable it.

Disable XML-RPC if you don’t need it
Alternatively, restrict access by IP
Enable login attempt monitoring
scan · 2 min ago · 14 checks
04AI content
2-5 credits per article

It writes the articles, and publishes them

Describe the topic and Helm writes the piece, generates the images and places it on WordPress: draft, published or scheduled. Or describe nothing — it reads the categories and what has already been published, and picks a new subject that fits the site.

It writes the articles, and publishes them
01
Choose, or let it choose

One field for the topic. Leave it empty and Helm looks at what the site is about, avoiding what it has already published.

02
Four settings, not twenty

Length, tone, how many images, where it lands. Title, excerpt, tags and image prompts are the AI's job.

03
It lands where you need it

A draft to review, published straight away, or scheduled for a date — using WordPress's own scheduling.

Images generated and uploaded to the media library, cover included
Categories, tags, excerpt and permalink decided by the AI
Automatic editorial plan: N articles every X days, with a spending cap
Transparent cost, before you press
Article2-5 credits depending on length
Image3 credits each

The quote is shown in the panel before generating. If something fails, the credits come back.

05Pricing
no credit card required

A plan for every agency size

Plan / 01
Free
€0
forever
5 WordPress sites
Site checks every 5 minutes
5 AI requests per month
1 GB backup storage
Centralized updates
Security scans
AI copilot
Not included: Helm AI — site actions
Not included: Backup & restore (DB + files)
Telegram notifications
Not included: Multi-user with permissions
Not included: Client reports with AI summary
Not included: Reports and emails with your brand
Not included: Public API with keys and scopes
Not included: AI-generated articles and images
Not included: Priority support
Start for free
Most popular
Plan / 02
Pro
€19/month
billed monthly
10 WordPress sites
Site checks every minute
50 AI requests per month
10 GB backup storage
Centralized updates
Security scans
AI copilot
Helm AI — site actions
Backup & restore (DB + files)
Telegram notifications
Not included: Multi-user with permissions
Not included: Client reports with AI summary
Not included: Reports and emails with your brand
Public API with keys and scopes
Not included: AI-generated articles and images
Not included: Priority support
Try Pro
Plan / 03
Agency
€69/month
billed monthly
50 WordPress sites
Site checks every minute
200 AI requests per month
50 GB backup storage
Centralized updates
Security scans
AI copilot
Helm AI — site actions
Backup & restore (DB + files)
Telegram notifications
Multi-user with permissions
Client reports with AI summary
Reports and emails with your brand
Public API with keys and scopes
AI-generated articles and images
Priority support
Try Agency

Extra AI credits available in packs — pay only for the scans you use.

06FAQ
before you start

The questions everyone asks

How do I connect a WordPress site to Helm?

You install the Helm connector on the site and link it to the panel: within seconds Helm detects core, plugins, themes and security status. Every request between Helm and the site is signed, and credentials are encrypted with AES-256.

Do I need a credit card to try it?

No. The Free plan includes 5 sites forever with no credit card: uptime monitoring checked every five minutes, centralized updates, security scans and the AI copilot. Paid plans check every minute and add backups, client reports and your own brand.

What happens if an update breaks a site?

Helm backs up the database before updating, then checks that the site still responds. If it does not, plugins and themes are automatically rolled back to the previous version and you get an alert.

Where do backups go and can I restore them?

Backups include the database and wp-content files and are kept on S3-compatible storage with configurable retention. Restores run from the panel and, before overwriting the database, Helm saves an automatic point to return to.

How does Helm know about vulnerabilities?

Helm syncs the Wordfence Intelligence feed daily and matches installed versions against vulnerable ranges offline. Each finding shows the component, severity, CVE and the version that fixes it.

Can the AI change my sites on its own?

No. The copilot can only propose actions from a closed list of operations: nothing runs without your explicit confirmation, and Helm still backs up before risky operations.

$ helm init

Start for free, 5 sites included

No credit card required. Connect your first sites and manage your fleet in minutes.

Helm — multi-site WordPress management for agencies