Site Detail
Every tab on a single site, from credentials and inventory through quicksaves, backups and logs.
Opening a site gives you one page with six tab groups over twelve leaves. The leaf name is the URL segment, so /account/sites/135/backups is a bookmarkable address.
The header carries a ← Sites link, the site domain, the environment switcher, and on the right an edit button, a Sync site data button, an Open terminal button and the primary Login to WordPress →. Beneath it a meta line reads provider, account, core version, weekly visits, storage and environment.
The tab groups are Overview, Stats, Inventory, Users, History and Activity. Entering a group lands on its first leaf, and a second pill row picks the leaf inside groups that have more than one.
Production and staging
A segmented Production / Staging control sits beside the site name. Staging only renders when the site actually has a staging environment.
Switching environments changes almost everything on the page: credentials, the environment rows, plugins and themes, WordPress users, quicksaves, backups, snapshots, captures, registry coverage, files, logs, scheduled scripts and stats. The Timeline, Domains and Accounts cards are site-scoped and do not change.
Overview
A row of stat tiles across the top reads Visits / wk, Backups, Versions and Timeline, each clickable into its tab, plus a Visits · 14d sparkline that opens Stats. The backup and version counts are prefetched, so the tiles fill without you opening those tabs.
Credentials
The Credentials card lists Site URL, WP admin, Address, Username, Password, Port, Home directory, Database, DB user, DB password and the SSH command, dropping any that are empty. Operators get an Edit link that opens the environment connection dialog.
Click any row to copy it. The pill on the right reads Copy and flips to Copied ✓. Password rows are masked with a Show / Hide toggle. The Site URL and WP admin rows open the address in a new tab when clicked, and the Copy button beside them still copies.
Environment
The Environment card lists WordPress, PHP, Storage, Visits / wk, and Subsites on a multisite. Rows are click-to-copy.
Two rows are operator-only. Uptime monitor is a switch, reading On or Off; flipping it turns the site’s uptime monitor on or off, is administrator-only on the server as well, and is recorded on the site’s activity log. Managed updates reads On or Off, and below it an Update settings… link opens a dialog with the Managed updates toggle plus Excluded plugins and Excluded themes pickers.
Domains, Accounts, Deploy and Tools
The Domains card lists the domains attached to the site, with a Configure → link into the fleet Domains screen.
The Accounts card is headed “access & contacts”. Each row shows an account with Customer or Billing chips where they apply. Operators get a row menu with Set as customer contact, Set as billing contact, Open account and Remove from site. The customer and billing accounts cannot be removed until you reassign the role. A composer at the bottom takes an account name or email and a Share button, and operators also get Assign….
The Deploy card holds the three deploy links, covered below.
The Tools card holds the site system tools: Deploy defaults, Migrate backup…, Apply HTTPS…, Reset permissions, Maintenance mode…, Launch site… and, on Kinsta and Rocket.net sites, Configure domain mappings and Open phpMyAdmin. Below them sits the removal link, which reads Mark for removal… for operators and Request site deletion… for customers, plus Delete site permanently… for administrators.
Deploying between environments
The Deploy card offers Push staging → production, Pull production → staging and Push to another site….
All three open a confirm dialog that names the source and target and warns “This overwrites the target with a copy of the source. Anything on the target that isn’t in the copy will be lost.” The confirm button turns red whenever a production environment is the target.
There are no options to split files from database. A deploy is a whole-environment provider operation. Operators get progress tracking that polls the provider until it completes, then reloads the site.
Push to another site… searches other environments on the same provider account and offers Push here on each, then routes into the same confirm.
Login to WordPress and Sync data
Login to WordPress → in the header mints a magic login link for the current environment and opens the WordPress admin in a new tab. The same action is on every site row’s right-click menu.
The header’s sync button (title="Sync site data") starts a dock job that re-collects the site’s data from the host, then reloads the whole site page when it finishes. The same action is available in bulk from the Sites screen as Sync data.
Stats
Stats are Fathom Analytics. If the environment has no tracker configured, the tab says so.
A grouping dropdown offers Daily, Monthly and Yearly, and a range dropdown offers Last 7 days, Last 28 days, Last 90 days and This year. On the right, Sharing chips set the dashboard to Off, Private or Public; Private reveals a password field that saves as you type, and a Copy share link control appears once sharing is on.
Four tiles read Visitors, Pageviews, Avg time on site and Bounce rate. Below them is a Pageviews bar chart, zero-filled so empty periods still render, then Top pages and Referrers lists.
Inventory
Plugins and Themes
Both leaves render the same list. When updates are pending, an Update all (N) button appears; it runs the managed update, which takes a quicksave before and after. + Add installs a plugin or theme from Upload (drop a .zip), WordPress.org (search and install) or Envato (your purchase list).
Each row shows a status dot, the name with its slug underneath, the installed version, an update chip reading → 3.1.2 when a newer version is known, and actions: Update when one is pending, then Deactivate or Activate. Must-use plugins are labelled and cannot be toggled or deleted here.
Right-click a row for Update to
To roll back a plugin or theme, use the Versions tab rather than this list.
Domains
This leaf manages provider domain mappings, which is separate from DNS. It is available for Kinsta and Rocket.net sites. Add a domain with the Add domain field, then per row use Verify, Make primary or Delete. When verification records are outstanding, the row expands with the DNS records to add, each with its own Copy button.
Registry
The Registry leaf matches every installed component’s content hash against audits published on WP Registry.
A summary card shows chips for total, malware, critical, high, medium, low, clean, unaudited and not loaded. Clicking a chip filters the list; click it again or click total to clear. A risk headline says how many critical and high findings sit on code that WordPress actually loads, and a coverage line reads 142 / 168 components audited (85%).
Components are grouped into Plugins, Themes, MU-plugins and Loose files. Code WordPress loads sorts above code it does not, and deactivated components are dimmed below a Deactivated divider with a note that WordPress does not load them, so most findings cannot fire, though their files can still be reached directly over HTTP. A deactivated component can be deleted from its right-click menu.
Clicking an audited row opens the findings dialog with each finding’s severity, title, description, location, CVE and CVSS, code snippet and recommendation, plus a link to the public WP Registry page for that hash.
Files
A read-only file browser locked to the environment’s home directory. The toolbar shows breadcrumbs starting at Home, the note “Read-only · locked to the home directory”, and a Refresh button. Columns are Name, Size and Modified, with directories first and symlinks marked with a link chip.
Click a folder to descend and a file to preview it. Text files show their first 512 KB, images render inline, and binaries say so. Right-click a row for Open folder or View file, Copy path, and Delete… on regular files. There is no upload, rename or edit.
Users
The Users tab lists the WordPress users on the current environment. Each row shows a monogram, the username with the email beneath, a role chip and a Magic login button that signs you in as that user.
+ New user creates a user on the site. Pick one of administrator, editor, author, contributor or subscriber (the default), fill in username and email, and optionally a password, first and last name, and whether to email the new user.
Deleting a user requires reassignment. The dialog names who the content will be reassigned to before it runs.
History
Versions
Versions is the git-commit history of the site: quicksaves and update events on one timeline. + New quicksave takes one now.
Each row shows a short hash, a Quicksave or Update chip, a description such as “WP 6.8.1 · 42 components” or “6 components updated”, a relative timestamp, and Details and Rollback. Rollback on the row rolls the whole site back to that commit.
Details opens the quicksave dialog. It has two views. Components lists themes and plugins with New, Deleted or Updated badges, version before and after, and a per-component Rollback. Changed files lists each file with an A, M or D status chip and its added and removed line counts; clicking a file shows the diff with a Unified / Side-by-side toggle and a Restore this file button.
The dialog header also offers Preview in sandbox ↗, which opens the quicksave in a WordPress Playground sandbox, and Roll back site to
A component rollback asks which version you want: This version or Previous version, each labelled with its date and hash.
Backups
Backups are restic snapshots, taken daily at 3:00 AM UTC direct to Backblaze B2, with point-in-time restore to any date. Back up now takes one immediately.
Each row shows the snapshot id and its timestamp, with Browse & download and Restore….
Browse & download opens a two-pane dialog. The left pane is a lazily loaded file tree with checkboxes; checking a directory checks its whole subtree. Very large subtrees such as uploads are marked “omitted — still restorable” and cannot be selected, though they are still included in a restore. The right pane previews a file when you click its name, or shows your selection with a Download button. Downloads are packaged in the background and the link is emailed to you.
Restore… creates a point-in-time snapshot from that backup’s timestamp and delivers it to your email, rather than overwriting the site in place.
Snapshots
Snapshots are on-demand zips for the client, each with a 24-hour tokenized download link. Choose what to include with the filter dropdown, which offers Everything, Database, Themes, Plugins and Uploads, then click Create snapshot.
Each row shows the snapshot name, its id, a chip carrying the filter, the size and the created time, then the link state. While the link is live you get Copy link; once it expires you get New 24h link, which mints a fresh token. Download is always present. The 24-hour expiry is enforced on the server.
Captures
Captures are screenshots of the site’s configured pages taken over time. A History rail on the left lists captures newest first with the date, the git commit hash and a page count; a Show older footer pages further back. Selecting one shows its screenshots on the right, each with an Open full size ↗ link and click-to-zoom.
There is no side-by-side comparison here. Unexpected capture changes surface as integrity alerts by email.
Activity
Timeline
The Timeline is human notes on what happened and why. Write one in the composer, which accepts Markdown, and submit with Add entry or ⌘⏎.
+ Attach file diff lets you record a change: give a file path, the original content and the updated content, and the diff is computed for you. Attachments appear as chips reading the file name with its added and removed line counts, and clicking one opens the recorded hunks.
Each entry renders its Markdown, its author (falling back to System) and its timestamp, with Edit and a delete control. Export JSON downloads the whole timeline.
Automated actions written by the Manager, such as an uptime monitor change, appear here as System entries.
Logs
Logs has two modes: Live and Archive.
Live lists whatever log files the environment exposes in a left rail; the first is selected automatically. The right pane shows the last 1000 lines with line numbers and light syntax tinting.
Archive reads rotated logs kept in long-term storage. Filter by range with 7 days, 30 days, 90 days and All, and by type with All, Access and Error. Files are grouped by month; each row shows the date, a type chip, the filename and the size, with View and Download. Download hands back a time-limited signed link. View fetches and decompresses the file on the server and shows its last 1000 lines, because the storage bucket cannot be read directly from the browser.
Scheduled
Scheduled lists commands queued to run once on this environment. You create them from the terminal dock’s Schedule button, not from here.
Each card shows the first line of the command, the author, the scheduled time and a Cancel link. Clicking a card opens an editor for the code, date and time. These are one-off queued commands, not cron jobs, backups or scheduled reports.