mainsecurity is WP Maintain’s built-in security layer. It is not an integration. It is the default that protects every managed site out of the box, before a host decides whether to bring another vendor into the Security lane at all.
Every other slot in WP Maintain follows the same rule: first-party when you want simplicity, bring-your-own when you want your rate, off when you do not need it. mainsecurity is the first-party side of that rule for security. No managed WordPress site sits unprotected while a host evaluates options, negotiates pricing, or decides on a provider.
What mainsecurity covers
mainsecurity handles the WordPress security fundamentals across your portfolio without any third-party API:
- Malware and vulnerability scanning across the sites you manage.
- Continuous security monitoring with signals surfaced into the same dashboard as health, performance, and updates.
- Early detection of hacked sites, suspicious changes, and known-vulnerable plugins and themes, before they turn into tickets.
- Hardening signals that flag the common exposure points attackers actually use.
It runs quietly in the background, on by default, with results visible to your team and ready for proof-of-care reporting.
Where mainsecurity sits in the security stack
WP Maintain runs a per-category integration model. Security is one lane, and you decide how to fill it.
Leave it on mainsecurity and every site is covered by our first-party layer at no extra vendor cost. Want deeper server-side defense or virtual patching? Plug in other APIs and run it as your layer across a managed portfolio, bring your existing relationship and pricing, or standardize on it for specific clients. When you bring a vendor, mainsecurity steps back so you are never paying for or running two engines against each other.
The point is that the choice is yours, and the gap is never yours. A host that does not want to source, license, and manage a security vendor does not have to. mainsecurity is already there.
Why it matters
The large majority of WordPress vulnerability reports trace back to outdated or nulled plugins and themes, and tens of thousands of sites are compromised every day. A security lane that is empty by default is a liability. mainsecurity makes the default safe, then hands you full control over what, if anything, you want to run on top of it.
First-party when you want simplicity. Bring-your-own when you want your rate. mainsecurity is how WP Maintain makes sure security is never the thing a host forgot to turn on.
Learn more about WP Maintain’s integration architecture and how to put your own vendor economics back in your hands.



