The Tech Dragon / Plugins / WP Infrastructure Steward

WP Infrastructure

Steward.

Client-Safe AdminInfrastructure Control

Give clients WordPress admin access. Keep control of the infrastructure.

Infrastructure Steward gives agencies and managed WordPress hosts a dedicated control layer for hosting-critical WordPress infrastructure—so clients can manage their sites without automatically receiving authority over everything that keeps those sites running.

Coming soon. Join the launch list for availability and release updates.

Plugin Resources

Everything for Infrastructure Steward.

Downloads, documentation, support, and official plugin destinations—when available.

Availability Notify me at launch Get launch and availability updates.
Documentation Knowledgebase Setup, configuration, troubleshooting, and reference.
Need Help? Support Get help specifically for this plugin.

Administrator shouldn’t have to mean infrastructure owner.

Client administrators need meaningful control of their WordPress sites. Hosting providers and agencies need to protect the infrastructure they are responsible for operating. Those two requirements should not have to conflict.

Infrastructure Steward is designed to separate ordinary site administration from infrastructure-management authority, giving providers a purpose-built way to define and enforce that boundary inside WordPress.

Built for infrastructure governance inside WordPress.

Separate infrastructure authority

Designate Infrastructure Administrators independently of ordinary WordPress Administrator access, creating a distinct authority boundary for protected infrastructure.

Protect critical components

Apply independent policies to managed plugins and supported administrative/configuration surfaces while preserving the runtime behavior those components provide to the site.

More than menu hiding

Infrastructure Steward is designed to enforce known protected management routes and lifecycle actions where technically feasible. Interface hiding is presentation—not the security boundary.

Harden the protection layer

A dedicated MU Protection Anchor is designed to strengthen enforcement and self-protection. Professional hosts can go further with Host Hardening, where effective filesystem permissions keep PHP from modifying the protection component.

Know your posture

An objective three-level Security Posture model is designed to report whether protection is Standard, Hardened, or Host Hardened based on verification rather than a user-selected claim.

h

Audit important activity

Infrastructure-related authority changes, policy changes, protected actions, posture changes, recovery activity, and other material events are designed to feed a bounded audit/event system.

Designed for the people responsible for keeping WordPress infrastructure running.

Managed WordPress hosts

Maintain an administrative boundary between your hosting infrastructure and the customer’s website-management authority.

Agencies

Give clients practical WordPress access while retaining control over the plugins and configuration surfaces your service depends on.

Professional site operators

Delegate day-to-day administration without treating every WordPress Administrator as an infrastructure administrator.

A control boundary—not another security-suite checklist.

Infrastructure Steward is focused on WordPress infrastructure governance. It is not trying to replace your WAF, malware scanner, backup platform, login security, or server controls. Its job is narrower: establish who is allowed to manage protected WordPress infrastructure and enforce that distinction where WordPress can reliably do so.

Host Hardening boundary

For professional hosting environments, optional Host Hardening moves modification authority for the protection anchor outside the PHP runtime. Infrastructure Steward does not claim to contain root, filesystem, arbitrary PHP, or equivalent server-level authority.

WP Infrastructure Steward FAQ

What is WP Infrastructure Steward?

WP Infrastructure Steward is a commercial WordPress infrastructure-governance plugin designed to separate ordinary site administration from authority over protected hosting-critical infrastructure.

Who is it for?

It is designed for managed WordPress hosts, agencies, and professional operators who give clients administrative access while remaining responsible for infrastructure components on those sites.

Does it replace a WordPress security plugin?

No. Infrastructure Steward is not a WAF, malware or vulnerability scanner, login-security product, backup platform, or general server-security suite. It focuses on infrastructure-management authority and enforcement inside WordPress.

Will protected plugins still run?

Yes. Infrastructure Steward restricts management authority without disabling the protected component’s normal runtime or front-end behavior.

What is an Infrastructure Administrator?

An Infrastructure Administrator, or IA, is the privileged authority used by Infrastructure Steward. IA membership is separate from ordinary WordPress Administrator status.

What is Host Hardening?

Host Hardening combines a verified active protection anchor with host-level filesystem controls that prevent the PHP runtime from modifying, replacing, renaming, or deleting that protection component while retaining required read access.

How is Infrastructure Steward licensed?

Infrastructure Steward is a commercial product. Pricing is based primarily on deployment scale rather than weakening local protection for lower tiers.

What environments are supported?

Product requirements are WordPress 7.1+, PHP 8.2+, and Linux hosting. WordPress Multisite and Windows-hosted WordPress are not supported.

Get notified at launch.

Release notification only—no need to keep checking back.

WHAT YOU’LL GET

One useful email when it matters.

  • Launch availability and download details
  • Important compatibility and licensing notes
  • Low-noise updates only—you can unsubscribe anytime
Fuel the Dragon