Skip to main content

Understanding security features on the Levamo dashboard

An overview of Monarx malware protection and the Advanced SiteShield security add-on on Levamo.

Overview

Every Levamo plan includes built-in malware protection, and users who want a deeper layer of protection can add Advanced SiteShield for additional vulnerability monitoring and virtual patching. Together, these two features cover both sides of WordPress security: catching malware that has already made it onto your site, and stopping known vulnerabilities from being exploited in the first place.

Monarx requires no setup and runs automatically on every site. Advanced SiteShield is an optional, paid add-on that must be added to your plan and activated per site before it starts protecting anything. Malware insurance through Monarx is also limited to certain plans and does not extend to staging sites, which is worth knowing before you rely on it.

In this article, you will find an overview of Monarx, step-by-step instructions for setting up and removing Advanced SiteShield, and a breakdown of what the Advanced SiteShield dashboard shows you.


Accessing the Security dashboard

Every site has its own Security area, where both Monarx and Advanced SiteShield are managed. To get there, go to Sites, click Manage site for the site you want, then click Security.


Monarx malware protection

Monarx is a malware scanning and removal service included on every Levamo plan at no extra cost. It works directly through the PHP engine on your environment, giving it a real-time view of site activity, and scan analysis happens in the cloud so it has virtually no impact on your site's performance.

Monarx is active on every site automatically. There is nothing to install or configure.

In the Security tab, you will see a summary of what Monarx is doing for your site. Click Open Monarx for more detail. This opens the Monarx dashboard, which has three areas:

  • Dashboard: The current protection status of your site, including how many files have been quarantined or removed if malware has been found

  • Details: The remediation status of any recently discovered malware

  • Help: A guide to the Monarx dashboard's features

Note:
Monarx also includes malware insurance, which covers free removal of any detected malware. This is available on Startup, Performance, and Enterprise plans. Starter plans and staging sites are not covered by malware insurance.


Advanced SiteShield

Advanced SiteShield is an optional add-on, priced at $4 per site per month, that protects your site against known WordPress vulnerabilities. It continuously monitors your site's plugins, themes, and core files, and automatically applies virtual patches to block exploit attempts against known vulnerabilities before the affected plugin or theme developer releases an official fix.

Unlike Monarx, Advanced SiteShield must be added to your plan and turned on for each site where you want to use it.


How to set up Advanced SiteShield

Step 1: Add Advanced SiteShield to your plan

Go to Billing, click View subscription, then click Edit plan. Scroll to Advanced SiteShield and click the + icon to add the quantity you need. Click Change plan to confirm.

Step 2: Activate it on your site

Go to Sites, click Manage site for the site you want, then click Security. Scroll to Advanced SiteShield and toggle it On.

Important:
If you do not have an available license, the toggle will be disabled and you will see a message to acquire one first. Complete Step 1 before attempting to activate the add-on on a site.

Turning on Advanced SiteShield installs a must-use security plugin (Patchstack) on your WordPress site, and threat protection becomes visible directly from the Levamo dashboard.

The Advanced SiteShield dashboard

Once activated, click Open Advanced SiteShield from the Security tab to open the full security center. It has three areas: Vulnerabilities, Packages, and Protection.

Vulnerabilities

Every detected vulnerability includes a priority level, so you can see at a glance which ones matter most. You can filter the feed to show only vulnerabilities that are actively exploited in the wild, search the full list, and sort by newest or by priority.

Packages

The Packages tab lists every component running on your site, including every plugin, every theme, WordPress core, your PHP version, and your database. For each package, you can see whether it is active, whether it has a known vulnerability, its current version, and the version available.

Built-in filters let you triage quickly: Update now, Vulnerable, Mitigated, Threats blocked, Deactivated, and Advised to replace. The last of these flags abandoned software that will not receive a security fix, which a version number alone cannot tell you.

Protection

The Protection tab shows the defense layers Advanced SiteShield runs on your site:

  • RapidMitigate virtual patching: Over 16,000 targeted mitigation rules that block exploit attempts against medium and high priority vulnerabilities, even before you have updated the affected plugin

  • Advanced hardening: Additional rules that block common malicious requests against WordPress

  • Community IP blocklist: IP addresses known to exploit vulnerabilities across the Patchstack network are blocked automatically, and threat data from your site helps protect other sites on the network

From this tab, you can view threats blocked over the last 7 days, 30 days, 6 months, or all time.

Tip:
If you want more hands-on control, the Protection tab also includes firewall settings for whitelisting trusted traffic, blocking IPs individually or by range, tuning auto-block behavior, and exempting specific user roles from the protection engine. None of this is required. Advanced SiteShield protects your site with sensible defaults out of the box.

How to remove Advanced SiteShield

Removing Advanced SiteShield is a two-step process: deactivate it on the site, then remove it from your plan.

Step 1: Deactivate on your site

Go to Sites, click Manage site for the site you want, then click Security. Toggle Advanced SiteShield off.

Step 2: Remove it from your plan

Go to Billing, click View subscription, then click Edit plan. Scroll to Advanced SiteShield and reduce the quantity to the amount you want.


Important information

Advanced SiteShield's data is refreshed based on the Patchstack API, which can occasionally lag due to caching. It may take up to an hour for the latest security data to appear after a change on your site.

The Patchstack plugin installed on your site includes a Log in button and a Change API Key link in its settings. These are intended for people with their own independent Patchstack account and are not needed for Advanced SiteShield to function on Levamo. You can ignore both.


Conclusion

Monarx and Advanced SiteShield work together to protect your site from malware and known vulnerabilities, with Monarx active by default and Advanced SiteShield available as an add-on for deeper visibility and control. If you have any questions about security on your site, our support team is available 24/7.

Did this answer your question?