Skip to content

Everything it watches, including the gaps.

Every module, as the console has it. Where something needs the agent on your server, it says so — a feature list with no boundaries on it is a feature list nobody believes.

Three depths, none of them about money.

What Servertorch can tell you depends on how much of it you install. Moving deeper takes about two minutes and never needs SSH.

Agentless

Nothing to install

Point Servertorch at a URL. Everything here is measured from the outside, the way your visitors see it.

No CPU, memory, disk, traffic or attack data — none of that is visible from outside.

PHP agent

One file in your web root

Upload a single PHP file. It works on shared hosting, needs no SSH, no root, and no extensions — PHP 7.2 and up.

WordPress plugin and theme inventory needs the WordPress connector.

WordPress connector

A plugin, installed the usual way

The same agent, packaged as a WordPress plugin, plus everything that only makes sense inside WordPress.

Monitoring

What we check from the outside, with no agent.

Uptime & response time

Checks as often as every 30 seconds, with DNS, connect, TLS handshake and time to first byte measured separately. Failures collapse into one incident with a start, an end, a timeline — and a plain-English “why it is marked down”.

In every plan

TLS certificates

Expiry, chain completeness, hostname match and grade, checked continuously. You hear about an expiry weeks ahead, not from a visitor.

DNS monitoring

Records as they were, with the date each one moved. The most common “the site is down” that is nobody’s server.

Security headers

Each missing or weak header graded, with the exact line for Apache, Nginx or your CDN that fixes it.

Blocklist monitoring

Spam and malware lists, Safe Browsing included, so you learn your domain was listed before your email starts bouncing.

Origin exposure

Works out which CDN you are behind and whether your origin still answers directly — the misconfiguration that quietly makes a CDN decorative.

Agent insight

What the agent inside the site reports.

Traffic analytics

Every request from the server’s own log: path, status, response time and the real visitor IP behind Cloudflare. A live view, people separated from bots, server errors and the slowest pages.

Needs the agent on the site

Stack & vulnerabilities

PHP, web server, database, CMS, plugins and packages — discovered, not declared — matched against published advisories with the version that fixes each one.

Needs the agent on the site

Server posture

PHP settings that should be off, files that are writable when they should not be, and for WordPress, database hardening checks.

Needs the agent on the site

Security

Detection and blocking.

Attack detection

A request firewall inside the site: SQL injection, XSS, traversal, scanners and brute force, each with the attacker’s own request and an explanation of what was being tried.

Needs the agent on the site

IP blocking

Block an address or range straight from the evidence, and let the firewall refuse attacks rather than only record them. Enforced on your server.

Needs the agent on the site

File integrity & malware

A hash of every file, compared on a schedule. Changed, added and deleted files with excerpts, and malware signatures on anything executable — a web shell in uploads/ shows the matched line.

Needs the agent on the site

Privacy readiness (DPDP)

Trackers before consent, a named grievance officer, retention statements, forms collecting personal data, cookie behaviour. Rechecked weekly, emailed only on change. Findings and fixes, never a verdict.

Code audit

Scanning the code a monitored site is deployed from.

Code audit

Connect GitHub or Bitbucket and scan the repository behind your site for secrets, vulnerable code and dependencies. Findings show only once the repository is verified as yours — the agent matches deployed files against the repository, or you commit a token file.

Scheduled code scans

Scan tracked branches daily or weekly without anyone pressing a button.

Scan on push

A GitHub or Bitbucket webhook queues a scan whenever a tracked branch is pushed.

Deep code analysis

Adds Semgrep, Gitleaks and npm audit to the built-in rules and Composer advisories.

Explain & fix for code

An AI explanation and suggested fix for one code finding. Also needs AI analysis.

Intelligence & reporting

Explanations and scheduled summaries.

AI analysis & Nekoba

Nekoba, the assistant, answers questions about your own data — “why was the shop slow on Tuesday?” — and AI triage explains a suspicious file and how to fix it. Metered in credits per month.

Reports

Uptime, incidents and security for any period, as a page or a download, and scheduled to your inbox weekly or monthly.

Account & integrations

People, integrations and branding.

API access

Bearer-token access to the same JSON API the console uses, for your own dashboards and scripts.

Slack, Teams, Telegram & webhooks

Slack, Microsoft Teams, Telegram and signed webhooks, per site and per severity, alongside email and the in-app centre.

Team members

Owners, managers and viewers. A viewer login is how a client sees their own uptime without being able to change anything.

White label

Your colour and logo on the console and reports, so an agency’s clients see the agency.

Assisted support

Grant our team time-boxed access to look at your data with you. You approve it, it expires, and it is logged.

For agencies

Responsible for sites you don't own.

One client never sees another

Separate companies, separate logins, separate data — enforced in every query, not just hidden in the interface.

Reports with your name on them

With white label, the monthly report a client receives carries your logo and colours.

How agencies use Servertorch

Or, by the question you are asking.

Is it up, and was it up?

The question that gets a monitoring tool bought, and the one most tools answer with a green dot and no evidence.

Timing broken into four parts
DNS, connect, TLS and first byte, separately — because “slow” has four causes and three different fixes.
Uptime that states its basis
A percentage with the window, the check count and the downtime it came from. A bare 99.9% is unfalsifiable.

Who is visiting, and who is attacking?

Read from the access log by the agent, so it is your server’s own record rather than a tag a visitor can block.

What was attempted, not just blocked
“412 attempts on /wp-login.php from 203.0.113.9” is evidence; “brute force detected” is a mood.
Real visitor IPs behind any CDN
Cloudflare, Fastly and the rest are unwrapped rather than reported as the visitor.

Has anything changed that shouldn’t have?

The question you cannot answer after the fact unless something was watching before.

Files, with the diff
A finding is readable — the changed lines — rather than a filename and a hash.
DNS and certificates
Every record change dated, every certificate watched to expiry.

Would we survive being asked?

India’s DPDP penalties begin on 13 May 2027. This part of the product exists because of that date.

A score with its denominator
Checks that could not run are excluded and counted, and the report says how much a web request can see at all.
Never a compliance verdict
No field in the data model holds one. Findings and fixes; the legal opinion stays with your lawyer.

See it against a site you know.

A feature list is a claim. The free readiness check runs the same product on your own domain in about fifteen seconds; the demo puts all of it on your sites.

No tracking cookies here

We only use the cookies needed to sign you in and keep forms safe — no analytics, no ads, nothing to accept.

Cookie notice