Every WordPress site you run, in one dashboard.
KontrolWP pulls in what needs your attention across all your sites: updates, plugins, users, broken links, comments, known vulnerabilities and accessibility on WordPress, plus uptime and deployments for static sites on Cloudflare. Handle it from one place, without logging in to each site.
Your dashboard, your Cloudflare account, behind Cloudflare Access.
Overview
Add siteFeatures
Everything you check on each site, checked for you.
KontrolWP syncs every site in the background and puts the work in one list, so you fix things instead of hunting for them. Updates, plugins, users, links, comments, posts, security checks and accessibility fixes are for WordPress sites. Static sites get uptime, analytics, domain details, accessibility checks and deployments. Each site has switches to turn individual checks off.
Updates
Every core, plugin and theme update across all sites in one list, queued with one click or run on a schedule.
DetailsPlugins
Install, activate, deactivate and delete plugins, and set auto-updates, on one site or many at once.
DetailsUsers
Every user across all sites, grouped by email. Add people, change roles, send resets or remove them.
DetailsBroken links
Scan published content for broken and unresponsive links, then remove them or jump to the editor. Scans run on a schedule.
DetailsComments
Every comment held for moderation, from every site, with Approve, Spam and Trash in the list.
DetailsPosts and pages
Browse a WordPress site's posts, pages and custom post types by status, with search. View them or open the editor.
DetailsMagic Login
Open any site's admin with a one-time link that lasts 60 seconds. No passwords to look up.
DetailsSecurity
Known vulnerabilities in core and plugins, rated by CVSS, plus a Settings list with one-click hardening fixes.
DetailsAccessibility
A score out of 100 for each site, issues ranked by impact and a daily scan. On WordPress, six one-click fixes.
DetailsAnalytics
Connect Umami Cloud or your own Umami to see visitors, pageviews and bounce rate on each site's page.
DetailsDomain
DNS records and registration details for each site's domain, with a warning when it expires within 30 days.
DetailsStatic sites
Add a website on Cloudflare Workers by its address. Uptime on every sync, pages from the sitemap and deployment history.
DetailsPrivacy
Your sites, your account, your keys.
KontrolWP is not a service you sign up for. It is a Cloudflare Worker you deploy, so your site list and credentials never leave your own account.
You
Sign in through Cloudflare Access with the login methods you choose.
- Cloudflare Access
- Any browser
- Phone or desktop
KontrolWP
The dashboard and API run as one Worker, with a database and queue in your account.
- Workers
- D1
- Queues
- Cron Triggers
Your sites
WordPress sites answer only requests signed with that site's own secret. Static sites need no plugin.
- KontrolWP Connect
- Static sites
- Any host
Locked down by default
Every API call checks the Cloudflare Access token, so a misconfigured route still refuses access.
Secrets stay encrypted
Each WordPress site's secret and your read-only Cloudflare API token are encrypted in the database with a key only your Worker holds.
Sites never call home
KontrolWP only makes outbound requests, so the dashboard can live on a private hostname.
Get started
Up and running in three steps.
The database, queue and migrations are set up for you on the first deploy.
Deploy
Click Deploy to Cloudflare and pick your account. Cloudflare copies the project and builds it for you.
Secure
The setup screen walks you through turning on Cloudflare Access, so only you can open the dashboard.
Connect
Install KontrolWP Connect on a site, then choose Add site and paste the site's address and Connection Key.
FAQ
Questions, answered.
What do I need to run KontrolWP?
A Cloudflare account and WordPress sites you can install a plugin on. KontrolWP uses Workers, D1, Queues and Cloudflare Access, all in your own account.
Does it check accessibility?
Yes, as a first pass. KontrolWP scans each page's HTML and scores the site out of 100. It cannot judge color contrast, keyboard use or whether alt text is good, so it does not replace a full WCAG review.
Where do the vulnerability reports come from?
From the Wordfence Intelligence feed, which needs a free API key that you add once in KontrolWP's Settings. KontrolWP matches your WordPress version and plugins against it and shows severity, CVE, the fixed version and a link to the report. Themes are not checked yet.
Can it manage static sites too?
Yes, for sites hosted on Cloudflare Workers. Add the address and KontrolWP checks uptime on every sync, and shows analytics, domain details and deployments. Updates, plugins, users, links and comments are WordPress features, so static sites don't have them.
What access does KontrolWP need to Cloudflare?
Only for deployment history, and only if you choose to add it: a read-only Cloudflare API token, stored encrypted. KontrolWP reads deployments and builds and never changes anything in your account. Without the token, static sites still get uptime checks.
Does it work with any WordPress host?
Yes. Your sites don't need to be on Cloudflare. KontrolWP reaches each site over HTTPS through the KontrolWP Connect plugin, wherever it is hosted.
Can anyone else see my dashboard?
Only the people you allow in Cloudflare Access. KontrolWP checks the Access token on every request, and your sites never need to reach the dashboard.
How does a site connect?
KontrolWP Connect creates a Connection Key, shown under Settings, KontrolWP Connect. Paste it into Add site with the site's address. Creating a new key in the plugin stops the old one working straight away.
Can updates run automatically?
Yes. Turn on Scheduled updates in Settings, choose what to include and when it runs. Each site can follow that schedule, use its own or run none, and you can exclude plugins globally or on one site. WordPress updates stay off until you enable them.
Can I turn features off for a single site?
Yes. Each site has switches for updates, broken links, analytics (once Umami is connected), security checks and accessibility checks, all on by default. When one is off, scheduled scans skip that site and its tab is hidden. Analytics, security and accessibility results are kept. Turning off broken link checks clears that site's links.
Will updating many sites at once overload them?
No. Each site works through its own queue one update at a time, and a slow or broken site never holds up the others.
Does Magic Login skip two-factor authentication?
Only for that one sign-in. The link works once, expires after 60 seconds, and checks the user is still an administrator. Password logins keep their two-factor prompt.
Take control of every WordPress site you run.
Deploy KontrolWP to your Cloudflare account and connect your first site.