PatchOn Agent
PatchOn is an AI service that runs your WordPress plugin, theme, and core updates for you. It reproduces your production site in a staging environment, lets AI verify whether each update can be applied safely, and applies only the updates that pass every check to production. If an update ever fails, one click restores your site. This plugin acts as the agent connecting your WordPress site to PatchOn. Getting Started This plugin requires the PatchOn service (patchon.jp) and does not function on its own. Activation alone performs no external communication and does not redirect you. Clicking “Start PatchOn” on the welcome screen opens a consent dialog describing the data that will be sent; confirming it with “Agree and Start” registers your site anonymously and, if updates are available, starts the first inspect-and-update run. No account is required to get started — you need one only to: view detailed inspection results configure automatic updates use paid features Main Features Pre-inspection — in a staging environment, AI compares before / after screenshots of your site to detect layout breakage and fatal errors Inspect and update — a manual run goes from inspection to production rollout in one action, applying only updates that passed every check Automatic updates with inspection — the site is inspected on a schedule and only updates that passed every check are applied Backups — taken automatically right before each update and downloadable for a plan-based retention period One-click restore — if an applied update fails, one click puts your site back to the pre-update backup This plugin (the free distribution on WordPress.org) does not write patched code to your site files, even when it detects a problem. AI auto-repair, which fixes the code causing a problem found during a pre-inspection, is provided by the separately distributed PatchOn Agent Pro extension plugin (available to paid plan subscribers). This plugin writes to your site files in only two cases: applying the updates themselves through the standard WordPress upgrader, and the one-click restore, which runs only on your explicit request and writes your own backed-up plugins, themes, MU plugins, and wp-content drop-ins (and your database) back to the site. Data Sent Once you have consented on the consent screen, running a “Pre-inspection” or “Apply update” sends the following data to PatchOn and related external services. See the Privacy Policy for details. Site URL / WordPress version / PHP version / DB version List and versions of installed plugins, themes, and MU plugins List of available updates (names and versions of plugins, themes, and WordPress core). While the site is connected, this is sent automatically once a day Site files prior to update application, used for the pre-update backup: wp-config.php, active and to-be-updated plugins and themes, MU plugins, and wp-content drop-ins (such as object-cache.php) Contents of WordPress debug.log (used to detect issues) A full copy of your site’s database, taken during a pre-inspection and reused as the pre-update backup. It may include personal data stored on your site, such as member accounts or contact-form submissions External services This plugin depends on the following external services. No external communication is performed merely by activating the plugin; it starts only after you explicitly click the “Agree and Start” button on the consent screen shown on first use. PatchOn API (https://patchon.jp and its subdomains) The backend for all inspection, repair, update, and database-dump operations. Two host names are used, both operated by Rocketa Inc. and routed to PatchOn’s infrastructure: https://patchon.jp/api/* — site registration, pre-inspection control, apply-update control, billing https://dump.patchon.jp/* — database-dump control endpoints and signed-URL chunk uploads for pre-inspections and pre-update backups Provider: Rocketa Inc. (rocketa.co.jp) When data is sent: On click of the “Agree and Start” consent button (one-time): anonymous site registration and UUID issuance Once a day while connected (daily check-in): the list of available updates and plugin version When the user runs a “Pre-inspection”, or when automatic updates run their scheduled inspection: list of plugins / themes, debug.log, full database copy When the user runs an “Apply update”, or when automatic updates apply an update that passed every check: a backup (site files and a full database copy) and the application result When the user runs the one-click restore after a failed update: restore control requests and progress status (the backed-up files and database themselves are downloaded from cloud storage at that time, not sent) What is sent: see the “Data Sent” section above Terms of Service: https://patchon.jp/terms Privacy Policy: https://patchon.jp/privacy-policy Subprocessors: https://patchon.jp/subprocessors AWS S3 (Tokyo region, accessed via PatchOn) Storage destination for the site backup (zip) and the database copy (uploaded in chunks). Uploads and downloads are performed only against pre-signed URLs issued by PatchOn on a per-request basis. The customer site does not hold any S3 credentials. During a one-click restore, the backed-up site files and database chunks are downloaded from S3 in the same way. Provider: Amazon Web Services, Inc. Endpoint: https://*.s3.ap-northeast-1.amazonaws.com (pre-signed URLs only) When data is sent: when the user runs a “Pre-inspection” (database copy) or an “Apply update” (backup: site files and database copy) What is sent: site files (zip) and a full copy of the database AWS Privacy: https://aws.amazon.com/privacy/
Top keywords
- site23×2.63%
- patchon17×1.94%
- update12×1.37%
- updates12×1.37%
- database10×1.14%
- only9×1.03%
- sent9×1.03%
- files8×0.91%
- https8×0.91%
- jp8×0.91%
- copy7×0.80%
- data7×0.80%
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!