New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Help centre

Your WordPress support questions, answered.

Clear answers about BugShield pricing, maintenance plans, one-off fixes, monitoring, backups, security and account support.

General

What is BugShield?

BugShield is a WordPress care platform. You can submit one-off bug fixes, subscribe to a maintenance plan, store site credentials in an encrypted Vault, and track everything from one dashboard.

Do I need a maintenance plan to use BugShield?

No. You can create a free account, add your site, and pay per fix. Maintenance plans add monitoring, backups, included fixes, and subscriber support.

Is BugShield only for WordPress?

Yes. BugShield is built specifically for WordPress and WooCommerce sites. Our developers, monitoring, and backups are all designed around how WordPress works.

How does the Password Vault work?

Vault items are encrypted and tied to your site, not your user account. When a developer needs access, they request credentials through BugShield and every redemption is logged.

Pricing

How much does WordPress support cost?

BugShield WordPress support pricing is £49.99 for a one-off task. Shield Light is £99 per month per site, and Shield Pro is £199 per month per site with unlimited bug fixes.

Do I need a subscription to get WordPress support?

No. Choose a One-off Task when you need one WordPress problem fixed without a subscription. Your account, Password Vault, developer chat, and fix history remain available if you choose a monthly plan later.

What counts as one bug fix?

A single reported issue with a clear resolution, like a broken checkout, an error page where your site should be, or something looking wrong on the page. If a request turns out to be several unrelated problems, your developer will tell you up front before any extra charge.

What is included with a One-off Task?

A One-off Task includes one dedicated WordPress bug fix, direct chat with the developer handling it, secure credential sharing through the Password Vault, and a saved history of the work. You see the confirmed price before work begins.

What do the monthly maintenance plans include?

Shield Light and Shield Pro include WordPress bug fixes, off-site backups, 24/7 monitoring, developer chat, the Password Vault, and activity history. Shield Pro adds unlimited fixes, daily and on-demand backups, malware protection, and priority support.

Can I switch between Shield Light and Shield Pro?

Yes, upgrade from your dashboard at any time. Upgrades apply straight away. If you need to move from Pro to Light, changes take effect from your next billing date.

Do plans cover multiple sites?

Plans are per website, since backups, monitoring, and fixes all belong to a single site. You can hold different plans on different sites under one account, and switch between them any time.

How does billing work?

A One-off Task is charged once at the confirmed price for that fix. Shield Light and Shield Pro are billed monthly for each subscribed website, so different sites in your account can use different support options.

Can I cancel a monthly plan at any time?

Yes. There is no long-term contract. Cancel from your billing settings and your plan remains active until the end of the period you have already paid for.

What is your refund policy?

If we cannot fix a one-off issue, you get a full refund. Subscriptions can be cancelled any time and remain active until the end of the paid period.

One-off WordPress Support

What is one-off WordPress support?

One-off WordPress support is help with a specific problem or technical task without joining a monthly maintenance plan. You approve the price, work directly with a BugShield developer, and track the request until the agreed issue is resolved.

What is included with one-off WordPress support?

Every request includes one clearly scoped fix, a confirmed price before payment, direct developer chat, secure credential sharing through the Password Vault, tracked progress, and a saved history of the work.

How much does one-off WordPress support cost?

Most common WordPress fixes cost £49.99. Malware removal starts at £99.99 because it requires a wider security review. Use the quote wizard to see the price for your issue before submitting the request.

Which WordPress problems can you fix?

We can help with critical errors, white screens, plugin and theme conflicts, broken layouts, login problems, contact forms, WooCommerce checkout issues, payment failures, email problems, and many other WordPress faults.

Do I need a maintenance plan to request support?

No. One-off WordPress support is available without a subscription. You can pay for a single agreed fix and only move to Shield Light or Shield Pro later if you decide that ongoing monitoring, backups, and included fixes would help.

Do I get a quote before paying?

Yes. Use the one-off WordPress support quote wizard to choose the closest issue and see the price before you pay. If the request needs clarification, we agree the scope and cost first.

Can you work on a WordPress site you did not build?

Yes. You do not need to be an existing customer and we do not need to have built the website. Describe the problem and provide access through your site Password Vault when the assigned developer asks for it.

How do I share my WordPress login securely?

Add WordPress, hosting, or SFTP details to the encrypted Password Vault in your BugShield workspace. Credentials stay attached to the correct site instead of being sent through email. Read the Password Vault guide for the full process.

What if you cannot fix it?

If we cannot complete the agreed one-off fix, you receive a full refund. If investigation shows that the request has a different or wider scope, we explain the options before carrying out additional work.

Can I upgrade to a maintenance plan later?

Yes. Your BugShield account, site, Password Vault, conversations, and fix history remain in place. You can add Shield Light or Shield Pro later without recreating the workspace.

WordPress Care Plan

What is a WordPress care plan?

A WordPress care plan is a monthly service that keeps monitoring, backups, support, and website records organised around one site. Shield Light also includes two WordPress bug fixes each month, handled by a BugShield developer.

What does Shield Light include?

Shield Light includes two bug fixes each month, weekly off-site backups, 24/7 monitoring, Core Web Vitals checks, plugin-health and file-integrity checks, a complete activity log, subscriber support, and a secure Password Vault.

How much does Shield Light cost?

Shield Light costs £99 per WordPress site each month. The price includes monitoring, weekly backups, two developer fixes, subscriber support, and the site workspace. You can review the plan price before subscribing and cancel from your billing settings.

Is Shield Light suitable for a small business website?

Yes. Shield Light is designed for generally stable business, brochure, blog, lead-generation, and marketing sites that benefit from continuous monitoring, weekly backups, and occasional developer fixes.

Does Shield Light include WordPress bug fixes?

Yes. Shield Light includes two WordPress bug fixes per billing month. You can use them for issues such as broken forms, plugin conflicts, display problems, login errors, or WordPress dashboard faults.

What happens if I use both included fixes before the month ends?

You can purchase another one-off fix at the standard rate or move the site to Shield Pro for unlimited WordPress bug fixes. The available options and price are shown before you approve anything.

Do unused fixes roll over?

Your two included fixes refresh at the start of each billing month. This keeps Shield Light focused on providing current monthly care alongside monitoring, backups, and subscriber support.

Does Shield Light include WordPress monitoring and backups?

Yes. Monitoring runs around the clock and covers signals including uptime, response time, SSL, plugin health, file integrity, and Core Web Vitals. A full off-site WordPress backup is created every week.

Is the BugShield WordPress plugin required for Shield Light?

Yes. The BugShield plugin securely connects the site to your account so Shield Light can collect inside-the-site monitoring signals, create backups, and maintain an accurate activity history.

Can I cancel Shield Light at any time?

Yes. You can cancel Shield Light from your billing settings at any time. The WordPress care plan remains active until the end of the period you have already paid for.

Unlimited WordPress Support

What is unlimited WordPress support?

Unlimited WordPress support gives one site ongoing access to WordPress bug fixes without a monthly request allowance. Shield Pro also keeps monitoring, backups, malware protection, secure access, conversations, and completed work organised in the same workspace.

What does Shield Pro unlimited WordPress support include?

Shield Pro includes unlimited WordPress bug fixes, 24/7 monitoring, daily and on-demand off-site backups, malware detection and prevention, malware cleanup, Core Web Vitals checks, a complete activity log, subscriber support, and priority response for critical requests.

How much does Shield Pro cost?

Shield Pro costs £199 per WordPress site each month. The monthly price includes unlimited bug fixes and the ongoing monitoring, backup, security, support, and workspace features included with the plan.

Are WordPress bug fixes really unlimited on Shield Pro?

Yes. You can submit as many WordPress bug fixes as the subscribed site needs, with each distinct problem raised as its own request. This keeps every investigation, conversation, and completed fix clear on your site board.

What WordPress problems can I submit?

You can submit WordPress problems such as plugin or theme conflicts, broken layouts, forms that have stopped sending, login faults, dashboard errors, WooCommerce checkout issues, payment problems, and other bugs affecting the subscribed site.

Does Shield Pro include WordPress monitoring and backups?

Yes. Monitoring runs around the clock and covers signals including uptime, response time, SSL, plugin health, file integrity, security, and Core Web Vitals. Full off-site backups run daily, and you can create an additional backup before an important change.

Does unlimited WordPress support include malware help?

Yes. Shield Pro includes malware detection and prevention alongside the wider monitoring suite. If malicious code is found on the subscribed site, investigation and cleanup are included in the plan.

How quickly will BugShield respond to a critical request?

Shield Pro includes priority handling and a one-hour response window for critical requests. Monitoring remains active around the clock so site signals continue to be recorded 24/7.

Is the BugShield WordPress plugin required for Shield Pro?

Yes. The BugShield plugin securely connects the site to your account so Shield Pro can collect inside-the-site monitoring signals, create backups, run security checks, and maintain an accurate activity history.

Can I cancel Shield Pro or move to Shield Light?

Yes. You can cancel or change the plan from your billing settings. A move to Shield Light takes effect from your next billing date, and your existing site workspace, Password Vault, conversations, and fix history remain in place.

WordPress Maintenance Plans

What is included in a WordPress maintenance plan?

Both Shield Light and Shield Pro include 24/7 monitoring, off-site backups, Core Web Vitals checks, a full activity log, subscriber support chat, and WordPress bug fixes. Shield Pro adds unlimited fixes, daily and on-demand backups, malware detection and prevention, and priority support.

Which WordPress maintenance plan should I choose?

Shield Light is a good fit for sites that need dependable monitoring, weekly backups, and up to two fixes each month. Shield Pro suits business-critical or frequently changing sites that benefit from unlimited fixes, daily backups, malware protection, and priority support.

How much do BugShield maintenance plans cost?

Shield Light costs £99 per month per site, and Shield Pro costs £199 per month per site. Each site has its own subscription, so you can choose the level of cover that suits it.

Are bug fixes included?

Yes. Shield Light includes two bug fixes per month, while Shield Pro includes unlimited bug fixes. You can submit requests, follow progress, and chat with the assigned developer from your BugShield dashboard.

How often is my site backed up?

Shield Light creates an automatic off-site backup each week. Shield Pro creates one each day and also lets you run an on-demand backup before an important change.

What does 24/7 monitoring cover?

BugShield monitors uptime, response time, SSL and domain expiry, plugin health, file integrity, Core Web Vitals, technical SEO, and site errors. Alerts and results are available in your dashboard.

Can I restore a backup myself?

Yes. Choose a restore point from your backup library and start the restore from your dashboard. You can also download backups, and the BugShield team is available if you need help with a rollback.

Why do I need the BugShield WordPress plugin?

The plugin securely connects your site to BugShield so monitoring, backups, plugin health checks, file integrity checks, and security scans can run. It is required on every site with an active maintenance plan.

Does subscriber support use my fix allowance?

No. Subscriber support covers general questions, access coordination, and plan help without using your monthly bug fix allowance. Fix requests remain separate in your workspace.

Can I use different plans across multiple sites?

Yes. Each site has its own subscription, and you can manage them together from one account. For example, you could use Shield Light for a brochure site and Shield Pro for a busy WooCommerce store.

Features

What WordPress maintenance services does BugShield include?

BugShield combines 24/7 monitoring, off-site backups, security checks, Core Web Vitals checks, activity logging, bug fixes, and direct developer support. Everything is organised in a separate workspace for each WordPress site.

What can I do with a free BugShield account?

Create an account, add your WordPress site, store credentials in the Password Vault, and submit one-off fix requests. Monitoring, backups, and included fix allowances come with Shield Light or Shield Pro.

How do fix requests and developer chat work?

You describe the issue, confirm the quote or use a plan-included fix, and get matched with a BugShield developer. You can chat with them in the dashboard until the work is done, and the conversation is kept with the request history.

Are bug fixes included with WordPress maintenance?

Yes. Shield Light includes two bug fixes per month, while Shield Pro includes unlimited bug fixes. You can submit each request, follow its status, and chat with the assigned developer from your dashboard.

Is the Password Vault encrypted?

Yes. Vault items are encrypted and tied to the site, not your login alone. Developers request access through BugShield when they need it, and every redemption is recorded in your activity log.

How do monitoring and alerts work?

BugShield checks uptime every five minutes and runs scheduled checks for security, WordPress and PHP health, plugins, DNS, email delivery, Core Web Vitals, technical SEO, and site errors. When something needs attention, you receive an alert and can review the details in your monitoring dashboard.

What does the WordPress activity log record?

The activity log records important WordPress changes such as logins, user and role changes, core, plugin, and theme changes, content activity, selected WooCommerce events, backups, monitoring results, fix requests, and Vault access. You can search and filter the timeline for the selected site.

How often are backups created?

Shield Light creates an automatic off-site WordPress backup every week. Shield Pro creates one every day and also lets you run an on-demand backup before an important change. Restore points can be downloaded or restored from your dashboard.

Do I need the plugin for every feature?

One-off fixes and the Vault work without the plugin. 24/7 monitoring, cloud backups, plugin health, and related maintenance features need the BugShield WordPress plugin connected on that site.

Can I manage more than one WordPress site?

Yes. Each domain gets its own workspace for fixes, vault items, plans, and logs. Switch between sites from one account whenever you need to.

Can I use BugShield without a maintenance plan?

Yes. You can use the Password Vault and request one-off WordPress bug fixes without subscribing. A maintenance plan adds monitoring, automatic backups, activity logging, subscriber support, and included fixes.

Monitoring

What does the BugShield WordPress monitoring service include?

Uptime checks every five minutes, response time tracking, WordPress and PHP environment checks, cron and database health, DNS change alerts, email delivery monitoring, file integrity, security scans, plugin health, Core Web Vitals, technical SEO checks, debug log analysis, and performance trends. Results show in one dashboard per site.

How often does BugShield monitor my WordPress site?

Uptime and response-time checks run every five minutes. Other checks run on schedules suited to each signal, from frequent WordPress activity delivery and hourly environment checks to daily health checks. Shield Pro malware scans run daily, and the latest results appear in your dashboard.

Do I need the WordPress plugin for monitoring?

Yes. Outside checks such as uptime work alongside the BugShield plugin, which lets us read plugin health, error logs, and other inside-the-site signals. Install it when you start Shield Light or Shield Pro.

Will the monitoring plugin slow down my website?

BugShield keeps external checks such as uptime away from your WordPress server and schedules inside-the-site checks so monitoring work stays lightweight. Performance and Core Web Vitals results also help you spot slowdowns over time.

How do alerts work?

When something needs attention, BugShield sends an in-app notification and email for downtime and critical security issues. Every event is also written to your site activity log so you can review what happened later.

Is monitoring included on both Shield Light and Shield Pro?

Yes. Both plans include the full monitoring suite. Shield Pro adds malware prevention, priority response, daily and on-demand backups, and unlimited fixes on top. Compare plans on the pricing page.

Can I monitor more than one WordPress website?

Yes. Add each website to your BugShield account and give each site its own Shield Light or Shield Pro plan. Every site gets a separate monitoring dashboard, alerts, activity history, and health results.

Does WordPress monitoring include security and malware checks?

Yes. Both Shield plans include security checks, detailed file integrity monitoring, plugin health, and alerts for suspicious changes. Shield Pro adds daily malware scans, active prevention, and priority response when a security issue appears.

Does BugShield monitor Core Web Vitals?

Yes. BugShield tracks Core Web Vitals and page performance on mobile and desktop. Your dashboard keeps the results together with response-time trends so you can see when site speed improves or starts to decline.

What happens when monitoring finds a problem?

You get an alert with clear context in the dashboard, and our team gets it too. On a maintenance plan we start work straight away and chat with you until it is resolved. Monitoring does not change your site without telling you.

What WordPress and PHP environment details are monitored?

BugShield tracks your WordPress and PHP versions, memory limits, upload limits, related runtime settings, and whether WordPress can connect to its database. PHP lifecycle alerts show when the installed version is approaching or has reached end of life.

Does BugShield monitor WordPress cron and database health?

Yes. Cron monitoring checks scheduled-task health, overdue events, queue size, and Action Scheduler failures when they can be detected. Database monitoring reviews total and table sizes, autoloaded options, transients, and database connectivity.

How do DNS and email delivery monitoring work?

BugShield compares important DNS records with a known-good baseline and alerts you when they change. Email monitoring checks delivery, inbox or spam placement, latency, recent failures, and the SPF, DKIM, DMARC, and MX records used by your domain.

What does WordPress file integrity monitoring check?

File integrity monitoring compares WordPress core files with official checksums, reviews wp-config.php permissions, and detects unexpected changes to .htaccess. These checks help identify altered files or unsafe access settings that need investigation.

Backups

What do BugShield WordPress backups include?

Each full backup includes your database, media uploads, themes, plugins, WordPress core, and configuration files needed for a complete restore. Every archive is listed in your dashboard with its date, size, and type.

How often are WordPress backups created?

Shield Light runs automatic weekly backups. Shield Pro runs automatic daily backups and lets you trigger an on-demand backup before a big change. Compare schedules on the pricing page.

Where are backups stored?

Off-site, on separate infrastructure from your hosting. If your server fails, gets hacked, or your hosting account is suspended, your backups stay available.

How does a WordPress backup restore work?

Choose a restore point in your dashboard and click Restore. BugShield automatically restores that backup to your connected WordPress site, with progress shown in your dashboard until the restore is complete.

Do I need the WordPress plugin for backups?

Yes. Cloud backups need the BugShield plugin connected on that site so we can collect a full archive safely. Install it when you start Shield Light or Shield Pro.

Can I download my backups?

Yes. You can download backup archives from your BugShield dashboard whenever you want to keep a separate copy.

Can I create a backup before a WordPress update?

Shield Pro lets you run an on-demand backup before updating WordPress, changing plugins, or making another major change. Shield Light follows its automatic weekly schedule.

Do backups include WooCommerce products and orders?

Yes. Products, orders, customer records, settings, and other WooCommerce data stored in your WordPress database are included as they exist when the backup is created. Product images and other uploads are included too.

Are WordPress backups stored off-site?

Yes. BugShield stores backups on infrastructure separate from your web hosting, so a hosting failure, compromised server, or suspended hosting account does not remove the same copies you may need for recovery.

Are backups encrypted?

Backup data is encrypted in transit before it leaves your WordPress site for off-site storage.

Can BugShield restore a site after a hack or failed update?

Yes. You can restore a known good backup directly from your dashboard, or ask the BugShield team for help with the recovery and the issue that caused the failure.

Is a database-only backup enough for WordPress?

A database-only copy does not include your media, themes, plugins, WordPress core, or configuration files. BugShield creates full-site archives so the files and database needed for a complete restore are kept together.

Security

What do BugShield WordPress security services include?

BugShield WordPress security services include plugin and theme inventory checks, known-vulnerability awareness, WordPress hardening, security monitoring, encrypted credential storage, activity logging, and developer support. Shield Pro adds active malware prevention and cleanup under the plan.

How does BugShield check plugins for security problems?

The BugShield dashboard keeps an inventory of installed plugins and themes, their current versions, available updates, and known vulnerability findings. This makes it clear which software needs attention and helps security patches get prioritised.

Does WordPress security monitoring run all the time?

Yes. BugShield monitors your connected WordPress site around the clock. Checks run on schedules suited to uptime, plugin health, file integrity, SSL, and other security signals, with alerts when something needs attention.

How does the Password Vault stay secure?

Vault items are encrypted and tied to the relevant website. Developers only receive access when they are actively working on that site, and every credential redemption is recorded in your activity history.

Do developers keep access after a fix?

No. Access is only while work is in progress. When the fix is complete, developer access ends automatically.

What is the difference between Shield Light and Shield Pro for security?

Both plans include monitoring, plugin health checks, activity history, developer support, and the encrypted Password Vault. Shield Pro adds active malware prevention, malware cleanup under the plan, and priority support. Compare them on the pricing page.

What happens if my WordPress site is already hacked?

BugShield can assess the damage, remove malicious code and backdoors, close the entry point, and verify the site is clean. Malware cleanup is included with Shield Pro, or you can request a one-off malware removal.

Will BugShield security checks slow down my website?

The BugShield connection is designed to stay lightweight. Scheduled checks run without loading a security dashboard inside WordPress, while results and alerts are presented in your external BugShield workspace.

Can I protect more than one WordPress website?

Yes. Add multiple WordPress sites to one BugShield account and switch between their monitoring, plugin health, Vault items, activity logs, and fix requests. Each maintenance subscription belongs to one site.

Do I need a maintenance plan to use the Password Vault?

No. The encrypted Password Vault is available for one-off fixes as well as maintenance plans. A maintenance plan adds ongoing monitoring, backups, plugin health checks, included fixes, and subscriber support for that site.

XSS2Shell

What is XSS2Shell?

XSS2Shell (CVE-2026-64638) is a WordPress vulnerability that starts as XSS on the login screen and can escalate to remote code execution if a logged-in administrator is socially engineered. WordPress shipped fixes for maintained branches. Use our free XSS2Shell checker to test your site.

How does the XSS2Shell checker work?

The XSS2Shell checker sends one non-destructive failed-login probe and reads the public response for the vulnerable reflection behaviour. If that response does not provide a clear answer, it uses the publicly detected WordPress version as a fallback.

Is the XSS2Shell checker free?

Yes. The BugShield XSS2Shell checker is free to use and does not require an account, payment, or plugin installation.

Is the XSS2Shell check safe for my website?

The check is designed to be non-destructive. It does not log in, create users, upload plugins, execute the remote-code chain, or change website content. Only test websites you own or have permission to assess.

Which WordPress versions are patched against XSS2Shell?

WordPress patched XSS2Shell in 7.0.3 and released matching fixes for older maintained branches back to 4.7.34. Update to the latest release available for your branch. The complete minimum-version table is on the XSS2Shell checker page.

What does a Likely vulnerable result mean?

Likely vulnerable means the login page reflected the XSS2Shell probe, or the detected WordPress version falls within a vulnerable range. Update WordPress immediately, then run the checker again.

What does a Not vulnerable result mean?

Not vulnerable means the checker did not find the reflection and did not identify a WordPress version in the known vulnerable ranges. Keep WordPress current because this result is specific to XSS2Shell and is not a complete security audit.

Why might the XSS2Shell checker fail to reach a site?

A firewall, bot challenge, hidden login URL, network timeout, or unavailable website can prevent the check from completing. Confirm the installed version under Dashboard > Updates and compare it with the patched-version table.

Does a vulnerable result mean my WordPress site was hacked?

No. It means the vulnerable behaviour or an affected version was detected. It does not prove exploitation. If the site was exposed, review administrator accounts, Application Passwords, plugins, logs, and unexpected file changes.

Can the XSS2Shell checker find other WordPress vulnerabilities?

No. This checker is focused on XSS2Shell and CVE-2026-64638. Use the WordPress site health scan for a broader review of public software, security, SSL, performance, and SEO signals.

What should I do after updating a vulnerable WordPress site?

Rerun the XSS2Shell checker, revoke unfamiliar Application Passwords, review administrator users, and inspect wp-content/plugins for unknown folders. If anything looks suspicious, request WordPress malware removal.

Still stuck? Contact our team or browse the Knowledge Base .

Need a fix rather than another answer?

Tell us what is happening, receive a confirmed price and speak directly with the developer handling the repair.

Request a Fix