Create Accountor Login

Patchstack alternative

A Patchstack Alternative, or the Layer That Sits in Front of It

Patchstack’s Developer plan is $69 a month billed annually, covering 25 sites (October 2026), and it blocks attempts to exploit known plugin vulnerabilities from inside WordPress. Edge Protection works further out, on the bots, floods, and settings that have nothing to do with any one plugin.

With Cascadia you get

  • Noise dropped at the edge
  • Rate limits where it counts
  • Caching and TLS included
  • Checked every morning
  • Nothing installed on the site
  • Your account stays yours

Cascadia vs Patchstack at a Glance

$69/moPatchstack Developer, billed annually (October 2026)
$828/yrPatchstack Developer at 25 sites (October 2026)
48 hoursPatchstack’s stated head start on protection
$49/moCascadia Edge Protection, per domain

Three Questions That Decide It

1

What Worries You Most?

A vulnerable pluginPatchstack
Bots, floods, and driftCascadia
2

How Many Sites Do You Look After?

Many, as an agencyPatchstack
One or a handfulCascadia
3

Who Sets the Edge Rules Today?

Someone on staffPatchstack
Nobody, or no one is sureCascadia

Side by Side

PatchstackCascadia
Where it runs–Inside the site, through a pluginAt the edge, before your server
What it blocksExploits of known plugin vulnerabilitiesBots, floods, and abusive traffic
Price–$69 a month billed annually, 25 sites (October 2026)–$49 a month per domain
Vulnerability alertsIncluded, up to 48 hours early×Not part of this service
Rate limiting and bots×Outside its scopeConfigured for your site
Caching and TLS×Outside its scopeTuned and kept current
Who configures itMitigation rules deploy automaticallyRules written and explained for you

Where It Runs

CascadiaAt the edge, before your server
–
PatchstackInside the site, through a plugin

What It Blocks

CascadiaBots, floods, and abusive traffic
PatchstackExploits of known plugin vulnerabilities

Price

–
Cascadia$49 a month per domain
–
Patchstack$69 a month billed annually, 25 sites (October 2026)

Vulnerability Alerts

×
CascadiaNot part of this service
PatchstackIncluded, up to 48 hours early

Rate Limiting and Bots

CascadiaConfigured for your site
×
PatchstackOutside its scope

Caching and TLS

CascadiaTuned and kept current
×
PatchstackOutside its scope

Who Configures It

CascadiaRules written and explained for you
PatchstackMitigation rules deploy automatically

What Ships in the Standard Plan Here

Patchstack gives you vulnerability alerts and targeted mitigation rules, deployed automatically through a plugin and a central dashboard. The general firewall, bot rules, rate limits, caching, and TLS settings in front of the site sit outside that scope.

  • Firewall rules written for how your site is actually used
  • Rules for wp-login and xmlrpc set at the edge
  • Bot protection and rate limiting configured, not left on defaults
  • Caching tuned so logged-in pages and checkout still work
  • HTTPS enforced and the TLS minimum kept current
  • Nine settings compared every morning against what we set
  • A change you did not make put back by us
  • Nothing installed on your website
  • 90 days of daily history, so you can see what changed and when
  • Your account stays yours, and our access can be withdrawn
See Edge Protection

Where Cascadia Goes Further

A virtual patch covers one known hole. Edge rules cover the steady noise that tries every door, and a daily comparison covers the settings nobody remembers changing.

The Noise Gets Dropped Before WordPress

Brute force runs, vulnerability scanners, and scrapers are turned away at the edge, so your server is not answering them at all.

Rate Limits Where Your Site Gets Hammered

Login pages, search, and forms each get limits that suit their traffic. Anything tight enough to affect real visitors is explained to you before it goes on.

Caching and TLS in the Same Service

Caching tuned so accounts and checkout keep working, browser cache set sensibly, HTTPS enforced, and the TLS minimum kept current.

Settings Checked Every Morning

Nine settings are compared daily with what we set. A change you did not make is put back and reported the next morning with its previous value.

Get Started

Who This Comparison Is For

Patchstack Knows Your Plugins

Its alerts and mitigation rules are built around the software your site runs, with intelligence it says arrives up to 48 hours ahead of competitors. We do not track plugin vulnerabilities, and nothing we do replaces that.

Priced for People with Many Sites

The Developer plan is aimed at professionals and agencies, and Patchstack points individual site owners to hosting partners that include it. A single site may already have it through its host.

Different Jobs, Often Both Worth Doing

A vulnerable plugin and a login flood are separate problems. Plenty of sites are better served by running Patchstack and having the edge configured than by choosing one.

Choose Patchstack if

  • Plugin vulnerabilities are your main worry
  • You manage many WordPress sites
  • You want alerts before issues are public

Choose Cascadia if

  • Bots and login floods are wearing down your server
  • Nobody is looking after the edge settings
  • You want caching and TLS set properly
Get Started

Adding Edge Protection to a Site That Runs Patchstack

Patchstack stays exactly where it is. Edge Protection installs nothing on the site, so the two work in different places.

  1. 1

    We Read Your Current Edge Settings

    We start with what is live and tell you what is wrong with it. Development mode left on and an outdated TLS minimum are both common finds.

  2. 2

    We Set Firewall, Bot, and Rate Limiting Rules

    Written for how your site is used, with exceptions for the tools you rely on and good bots let through. Risky rules are explained before they go on.

  3. 3

    We Tune Caching and TLS

    Caching is set to how the site is built, HTTPS is enforced, and the TLS minimum is brought current.

  4. 4

    Patchstack and the Edge Each Do Their Part

    Patchstack keeps handling plugin vulnerabilities. We compare the edge settings every morning and send a monthly report covering the month just ended.

Get Started

What Clients Say About Working with Cascadia

“I’ve always dreaded website management, but Cascadia has done an incredible job with my WordPress site, making it one less thing for me to worry about.”
Alex R.Cascadia client

Ready to Move from Patchstack?

Talk to us about your setup

Ask us

Patchstack Alternative Questions

Straight answers about switching, pricing, and what moves with you.

See Edge Protection

Still have a question?

What is a Patchstack alternative?

Anything else that keeps attackers away from the software on your site. Plugin firewalls such as Wordfence and All-In-One Security, cloud firewalls such as Sucuri, and managed services like this one, which configure the edge in front of your site. Most of those do a different job from Patchstack rather than the same job differently.

How is Cascadia different from Patchstack?

Patchstack works through a plugin connected to its dashboard, and it deploys targeted rules when a plugin you run has a known vulnerability. We work at the edge, before requests reach your server. We set the firewall, bot protection, rate limiting, caching, and TLS for how your site is used, and compare nine settings every morning against what we set.

How much does Patchstack cost?

The Developer plan is $69 a month billed annually, or $828 a year, at 25 sites, with more sites at $12.50 a month per five (October 2026). Enterprise and host plans are priced on request. Edge Protection is $49 a month per domain.

Does Patchstack do anything you do not?

Yes. It tracks vulnerabilities in the plugins and themes you run, alerts you, and blocks attempts to exploit them without changing the plugin’s code. We do none of that, and we would not suggest dropping it for us.

Can I run both?

Yes, and for many sites that is the better answer. Patchstack works inside the site, and Edge Protection works in your edge account with nothing installed on the site.

Will an edge rule block my own customers?

That is the risk we plan around. Country rules and aggressive rate limits are explained to you before they go on, and exceptions are written for the tools you actually use.

What happens when a setting drifts?

You hear about it the next morning. Anything that moved becomes a ticket naming the setting and the value it had before, and if the change was not yours we put it back.

Do you keep a record of what you change?

Yes. Every setting we change is recorded, and daily snapshots are kept for 90 days, so you can see what something was, when it changed, and whether it was us.

Is this worth it for a single small site?

A small site is where the edge is most often left exactly as it came, and nothing is installed anywhere, so there is no overhead in running it. Whether $49 a month is worth it for your site is a fair question to ask us directly.

Do I need managed hosting to buy this?

No. It runs as a standalone monthly service on whatever hosting you already use. It is also part of Domain Pro, at $59 a month per domain.

How quickly does setup start?

Setup starts within two business days, and the first full picture of your settings arrives within a week.

What if I want to leave?

Withdraw our access. The edge account is yours, every change we made is recorded, and Patchstack carries on as before.

Ready to handle the traffic Patchstack does not see?

Forty-nine dollars a month per domain, with the edge in front of your site configured for how it is used and checked every morning.

Ask Us Anything

We’d love to hear from you!