Free Forever: 1 website, complete monitoring
SteadWeave Free includes complete monitoring for one website, free forever. There is no trial period and no expiration.
SteadWeave Companion is the complete WordPress plugin, not a separate “Lite” or feature-locked edition. Paid plans are available when you need to monitor more websites.
SteadWeave Companion is the lightweight WordPress-side connector for the SteadWeave external monitoring service.
The Companion does not perform the central monitoring workload locally. After a WordPress administrator explicitly starts setup and confirms the external-service disclosure, the plugin connects the site to SteadWeave. After pairing, authenticated technical heartbeats let the service evaluate WordPress health, software versions, update availability and other website-assurance signals.
The PHP, JavaScript, CSS, translations, documentation and bundled image assets distributed in this
WordPress.org plugin package are licensed under GPLv2 or later. The SteadWeave name and source-identifying marks may also be protected by applicable trademark law; those trademark rights are separate from, and do not restrict, the GPL license granted for the copies of the bundled assets distributed with this plugin. See
ASSET-LICENSE.txt and
LICENSE.txt.
SteadWeave is a separate SaaS service. Service plans may differ by the number of websites that can be managed. The Companion does not hide premium PHP code or unlock local plugin functionality with a license key.
What the Companion does
- Provides a request-first secure pairing flow.
- Creates a cryptographic installation identity used to verify control of the WordPress installation.
- Stores issued access credentials locally using authenticated encryption when supported by the server.
- Sends authenticated technical heartbeats only after pairing.
- Advertises locally available Smart Fix capabilities to the paired service.
- Receives bounded, authenticated Smart Fix commands only after pairing and only after an authorized SteadWeave account user explicitly requests Assisted Remediation.
- Can update supported SEO metadata through Yoast SEO, Rank Math, AIOSEO or SEOPress when one supported provider is detected unambiguously.
- Can replace exact verified HTTP hyperlink references in published WordPress post content without requiring an SEO plugin.
- Verifies Smart Fix targets and current values, reports structured results, and supports bounded preflight and rollback safeguards.
- Reports WordPress/PHP versions, plugin/theme inventory and update state, site URLs, limited server context and WordPress cron state used by the monitoring service.
- Receives SteadWeave branding and the customer dashboard URL as part of authenticated service responses.
- Provides connection diagnostics and an administrator-only recovery path.
- Stops scheduled authenticated telemetry when pairing is reset or the plugin is deactivated.
- Integrates with WordPress privacy-policy, personal-data export and personal-data erasure tools for the locally stored enrollment email.
The plugin does not add analytics, advertising trackers, marketing pixels or public-site credits.
The Companion does not download or execute arbitrary PHP or JavaScript from SteadWeave, does not install plugins or themes remotely, and does not expose a general-purpose remote code execution mechanism.
Security hardening
SteadWeave Companion includes application-layer security controls for its own REST and administration surface:
- a WAF-like REST pre-filter for malformed requests, oversized payloads, scanner user agents and high-confidence SQLi/XSS/path-traversal/XXE patterns;
- strict machine-secret validation plus authenticated encryption at rest (libsodium secretbox, or AES-256-GCM fallback) for recoverable access/enrollment credentials;
- token-bucket rate limiting per endpoint/IP and per installation or enrollment-credential identity, plus progressive HMAC-authentication lockout;
- standard rate-limit response metadata (
X-RateLimit-* and Retry-After on 429 responses);
- a structured local JSON security event log with configurable retention, secret redaction and an HMAC-SHA-256 tamper-evident hash chain;
- administrator-only security configuration and filtered CSV/JSON log export under SteadWeave → Security;
- a nonce-based Content Security Policy for Companion administration pages, with Report-only mode enabled by default for safe rollout;
- optional site-wide XML-RPC hardening when XML-RPC is not required by another integration.
The Companion does not generate public-site HTML views, so its CSP applies to its WordPress administration pages. A network-edge WAF/DDoS service, reverse-proxy/site-wide CSP, TLS/server hardening, database ACLs and off-host SIEM/log retention remain infrastructure responsibilities. Detailed configuration and test guidance is included in
docs/security-en_US.md and
docs/security-it_IT.md.
- Install and activate SteadWeave Companion.
- Open SteadWeave in the WordPress administration menu.
- Review the external-service disclosure and linked Privacy Notice and Terms of Service.
- Enter the email address to use for setup notifications.
- Explicitly confirm the external-service connection.
- Select Start secure setup.
- Complete the guided setup on app.steadweave.com.
- Return to WordPress and verify that the connection status becomes Connected.
No SteadWeave password, API token or secret credential needs to be copied by email during the normal pairing flow.