Help & FAQ

Straight answers to the questions we hear most. Can't find yours? We're one email away.

How do I install the Geco Connector on my site?

Add your site in the dashboard and choose auto-install: enter an administrator username and password (or application password) and we install and activate the connector plugin for you. Prefer to do it yourself? Download the connector zip from the add-site screen and upload it in wp-admin under Plugins → Add New → Upload Plugin, then activate it. Either way, the site pairs with your dashboard automatically.

Is the connection between my site and Geco WPM safe?

Yes. Every request between your dashboard and your site is signed with HMAC using a secret unique to that site, and travels over HTTPS. Requests are timestamped, so intercepted requests can't be replayed, and a request with an invalid signature is simply rejected by the connector.

How are my WordPress admin credentials stored?

Credentials you provide for auto-install are encrypted at rest with AES-256-GCM before they ever touch the database. They're only decrypted transiently to perform the action you asked for, and you can remove them at any time from the site's settings.

My site uses two-factor authentication. Can I still connect it?

Yes — use manual install. Auto-install signs in the way a person would, so 2FA will block it. Instead, download the connector zip, upload it in wp-admin yourself, and activate it. The site pairs with your dashboard without us ever needing your password.

Auto-install failed. What now?

Fall back to manual install: download the connector zip from the add-site screen and upload it under Plugins → Add New → Upload Plugin in wp-admin. Auto-install can fail for lots of ordinary reasons — 2FA, a custom login URL, a security plugin, or a host that blocks automated logins — and manual install works around all of them.

How do rollbacks work?

Before we update a plugin or theme, we record the version you're on. If the update causes trouble, open the site's update history and click roll back — we reinstall the previous version from the WordPress.org repository in one click. No FTP, no backups to restore.

How often do you check my sites?

Uptime and response-time checks hit your homepage every 5 minutes. Full rescans — plugin, theme and core inventory, vulnerability matching, security grading and screenshots — run every 6 hours, and you can trigger one manually any time.

Which WordPress and PHP versions are supported?

The connector supports WordPress 5.5 or newer running PHP 7.4 or newer, and is tested up to WordPress 6.7. If you're on something older, updating WordPress itself is the first thing we'd recommend anyway.

Does Geco WPM support WordPress multisite?

Not yet. The connector currently supports standard single-site WordPress installs. Multisite support is on the roadmap — if it matters to you, tell us and we'll bump it up.

How do I disconnect a site?

Open the site's settings in your dashboard and remove it — monitoring stops immediately and stored data for that site is deleted. Then deactivate and delete the Geco Connector plugin in wp-admin. Your WordPress site is untouched either way.

How do I delete my account and data?

Delete your account from workspace settings, or email us and we'll do it for you. All of your account data — sites, scan history, screenshots and stored credentials — is permanently deleted within 30 days.

What does "free for unlimited sites" actually mean?

Exactly what it says: the core platform — connecting sites, updates and rollbacks, security scans and grades, uptime and broken-link monitoring, SEO audits, screenshots and team workspaces — is free with no site cap. Optional add-ons cost £1 per site per month each, and you only pay for the sites you enable them on.

Still stuck? Check the documentation or contact support.

Help & FAQ · Geco WPM