Every WordPress site you run, in one dashboard.
KontrolWP gathers everything that needs your attention, from updates and broken links to comments and security warnings, and shows it in one place. Static sites get uptime checks and deployments too. No more logging in to each site.
Your dashboard, your Cloudflare account, behind Cloudflare Access.
Overview
AddFeatures
Everything you check on each site, checked for you.
KontrolWP checks your sites in the background and puts the work in one list, so you can fix things instead of hunting for them. Most of it is built for WordPress sites. Static sites get uptime checks, analytics, domain details, accessibility checks and deployments. You can switch off any check for any site.
Updates
Every WordPress, plugin and theme update from all your sites in one list. Run them with a click or on a schedule.
Details about UpdatesPlugins
Install, turn on, turn off or delete plugins, and set auto-updates, on one site or many at once.
Details about PluginsUsers
Everyone with a login on any of your sites, grouped by email. Add people, change roles, send password resets or remove them.
Details about UsersBroken links
Find broken links in your content, then remove them or jump straight to the editor. Scans run on their own schedule.
Details about Broken linksComments
Every comment waiting for moderation, from every site, with Approve, Spam and Trash right in the list.
Details about CommentsPosts and pages
Browse a site's posts, pages and custom post types by status, search them, and open the editor when you need to.
Details about Posts and pagesCode snippets
Add tracking codes and small scripts to a site's head, body or footer, and choose which pages they run on.
Details about Code snippetsMagic Login
Open any site's admin with a one-time link that works for 60 seconds. No passwords to look up.
Details about Magic LoginSecurity
See known vulnerabilities in WordPress and your plugins, rated by severity, plus one-click fixes for common security settings.
Details about SecurityAccessibility
A score out of 100 for each site, with issues ranked by impact and a daily scan. On WordPress, six of them have a one-click fix.
Details about AccessibilityPerformance
Google PageSpeed results for mobile and desktop, with Core Web Vitals from real visitors and a history of past tests.
Details about PerformanceSEO
Search Console numbers, titles and descriptions with a preview, social sharing tags, redirects and local business details, all in one tab.
Details about SEOAnalytics
Choose Umami or Google Analytics 4 for each site and see its visitors and pageviews on the site's page.
Details about AnalyticsDomain
DNS records and registration details for each domain, with a warning when one is due to expire within 30 days.
Details about DomainStatic sites
Add any website by its address, whether it is hosted on Cloudflare or somewhere else. You get uptime checks, its pages from the sitemap, and deployment history if you connect Cloudflare.
Details about Static sitesPrivacy
Your sites, your account, your keys.
KontrolWP is not a service you sign up for. You deploy it to your own Cloudflare account, so your site list and credentials stay there. Read the privacy policy.
You
Sign in through Cloudflare Access with the login methods you choose.
- Cloudflare Access
- Any browser
- Phone or desktop
KontrolWP
The dashboard runs as one Worker in your account, along with its own database and queue.
- Workers
- D1
- Queues
- Cron Triggers
Your sites
A WordPress site only answers requests signed with its own secret. Static sites need no plugin.
- KontrolWP Connect
- Static sites
- Any host
Locked down by default
Every request is checked against your Cloudflare Access login, so a mistake in setup still keeps people out.
Secrets stay encrypted
Each site's secret and your read-only Cloudflare token are stored encrypted, with a key only your Worker holds.
Sites never call home
KontrolWP only reaches out to your sites, so the dashboard can stay on a private address.
Get started
Up and running in three steps.
The database and queue are created for you on the first deploy.
Deploy
Click Deploy to Cloudflare and pick your account. Cloudflare copies the project and builds it.
Secure
The setup screen walks you through Cloudflare Access, so only you can open the dashboard.
Connect
Install the KontrolWP Connect plugin on a site, choose Add, and paste the site's address and Connection Key.
FAQ
Questions, answered.
What do I need to run KontrolWP?
A Cloudflare account and WordPress sites you can install a plugin on. KontrolWP uses Workers, D1, Queues and Cloudflare Access, all in your own account.
Does it check accessibility?
Yes, as a first pass. KontrolWP scans each page's HTML and gives the site a score out of 100. It can't judge color contrast, keyboard use or whether alt text is any good, so it doesn't replace a full WCAG review.
Where do the vulnerability reports come from?
From the Wordfence Intelligence feed. You add a free API key once in Settings, and KontrolWP matches your WordPress version and plugins against the feed. Each report shows the severity, CVE, fixed version and a link to the details. Themes aren't checked yet.
Can it manage static sites too?
Yes. Add the site's address and KontrolWP checks that it's up on every sync, and shows its analytics, SEO, accessibility, performance and domain details. Connecting Cloudflare is optional. It only adds deployment history, and sites hosted anywhere else work for everything else. Updates, plugins, users, links and comments are WordPress-only, so static sites don't have them.
What access does KontrolWP need to Cloudflare?
Only if you want deployment history, and then just a read-only API token, stored encrypted. KontrolWP reads deployments and builds and never changes anything in your account. Without the token, static sites still get uptime checks.
Does it work with any WordPress host?
Yes. Your sites don't have to be on Cloudflare. KontrolWP talks to each one over HTTPS through the KontrolWP Connect plugin, wherever it's hosted.
Can anyone else see my dashboard?
Only the people you allow in Cloudflare Access. KontrolWP checks their Access login on every request, and your sites never need to contact the dashboard.
How does a site connect?
The KontrolWP Connect plugin makes a Connection Key, shown under Settings, KontrolWP Connect. Paste it into the Add dialog along with the site's address. If you make a new key, the old one stops working right away.
Can updates run automatically?
Yes. Turn on Scheduled updates in Settings, then choose what to include and when it runs. Each site can follow that schedule, use its own, or run none. You can also leave out certain plugins everywhere or on one site. WordPress core updates stay off until you turn them on.
Can I turn features off for a single site?
Yes. Each site has switches for updates, broken links, analytics (once a provider is connected), security, accessibility and performance, all on by default. When one is off, scheduled scans skip that site and it is hidden from the site. Past results are kept, except for broken links, which are cleared when you turn that check off.
Will updating many sites at once overload them?
No. Each site works through its own queue, one update at a time, and a slow or broken site never holds up the others.
Does Magic Login skip two-factor authentication?
Only for that one sign-in. The link works once, expires after 60 seconds, and checks that the user is still an administrator. Normal password logins still ask for two-factor.
Take control of every WordPress site you run.
Deploy KontrolWP to your Cloudflare account and connect your first site.