A deep security pass across the whole platform

Stricter database access rules with uniform MFA enforcement, hardened request validation on every site-facing check, per-account rate limits, checksum-verified plugin updates, and integrity-pinned dashboard scripts.


July 1, 2026 · Formitor

A monitoring tool runs code on your clients’ sites and holds the map of your whole portfolio. That earns it a periodic, unglamorous, top-to-bottom security review. We just finished one. Nothing here adds a feature; all of it narrows what an attacker could do.

What changed

Stricter database access rules. Access policies were tightened across the platform, including uniform MFA enforcement on all account data: the protection applies everywhere, not just on the obvious tables.

Hardened request validation. Every server-side, site-facing check now validates its requests more strictly, shrinking the surface a malicious or compromised endpoint could poke at.

Per-account rate limits. The AI assistant and support tickets are now rate-limited per account, closing off abuse and cost-amplification paths.

Integrity-verified plugin updates. Each plugin release is now checksum-verified before installing. When your fleet pulls an update, the bytes are proven to be the bytes we shipped. Supply-chain tampering between our release and your site’s install fails the check and doesn’t install.

Integrity-pinned dashboard scripts. The dashboard’s third-party scripts are SRI-pinned to exact versions and hashes, so a compromised CDN cannot ship altered JavaScript into your session.

What you need to do

Nothing. Every change is server-side or ships through the normal plugin update flow.

We publish these notes because trust in a monitoring product shouldn’t be vibes-based. If you want the design principles behind the plugin’s security model, they’re documented on the security page.

Keep reading

Product update · Jul 10, 2026

Connect an AI agent to Formitor over MCP

Generate a read-only token and let Claude or any MCP-capable agent list your sites, ask what's broken right now, pull a site's full status, and read recent alerts.

Read post
Product update · Jul 7, 2026

Hijack forms: live-test any client form straight to your own inbox

Flip on Hijack forms from the admin bar, enter your email, and every notification you trigger while testing goes to you instead of the client. Auto-disables after the window you pick.

Read post
Product update · Jun 12, 2026

Mail Log: search every form test result across every site

A searchable, cross-site view of every check result. Filter by site, form, delivery status or date range, or free-text search by email, subject, error message, or source page. Matching filters in wp-admin too.

Read post
Product update · Jun 5, 2026

Deep browser checks: a real browser fills your form, and you get the screenshot when it fails

Tier-3 deep checks are live for Pro subscribers. A headless browser fills out the form and clicks Submit like a visitor would, catching what server-side checks can't see, with a screenshot of the exact moment it got stuck.

Read post
Product update · Jun 2, 2026

Update the Formitor plugin on your whole fleet from one button

One click pushes the latest plugin to every connected site with a per-site result, sites keep themselves current automatically afterward, and outdated sites are flagged on the dashboard.

Read post
Product update · May 28, 2026

Pause controls at every level, and a 7-day history on every form

Pause a form for 1h, 4h, 24h or until you resume; pause a whole site while it's being worked on. Timed pauses resume themselves. Plus a History view of every form's last 7 days of checks.

Read post

Catch the failure before the client does.

Free plan: 2 sites, every feature, no card. See what it finds.