Patchstack alternative
A Patchstack Alternative, or the Layer That Sits in Front of It
Patchstack’s Developer plan is $69 a month billed annually, covering 25 sites (October 2026), and it blocks attempts to exploit known plugin vulnerabilities from inside WordPress. Edge Protection works further out, on the bots, floods, and settings that have nothing to do with any one plugin.
With Cascadia you get
- Noise dropped at the edge
- Rate limits where it counts
- Caching and TLS included
- Checked every morning
- Nothing installed on the site
- Your account stays yours
Cascadia vs Patchstack at a Glance
Three Questions That Decide It
What Worries You Most?
How Many Sites Do You Look After?
Who Sets the Edge Rules Today?
Side by Side
| Patchstack | Cascadia | |
|---|---|---|
| Where it runs | –Inside the site, through a plugin | At the edge, before your server |
| What it blocks | Exploits of known plugin vulnerabilities | Bots, floods, and abusive traffic |
| Price | –$69 a month billed annually, 25 sites (October 2026) | –$49 a month per domain |
| Vulnerability alerts | Included, up to 48 hours early | ×Not part of this service |
| Rate limiting and bots | ×Outside its scope | Configured for your site |
| Caching and TLS | ×Outside its scope | Tuned and kept current |
| Who configures it | Mitigation rules deploy automatically | Rules written and explained for you |
Where It Runs
What It Blocks
Price
Vulnerability Alerts
Rate Limiting and Bots
Caching and TLS
Who Configures It
What Ships in the Standard Plan Here
Patchstack gives you vulnerability alerts and targeted mitigation rules, deployed automatically through a plugin and a central dashboard. The general firewall, bot rules, rate limits, caching, and TLS settings in front of the site sit outside that scope.
- Firewall rules written for how your site is actually used
- Rules for wp-login and xmlrpc set at the edge
- Bot protection and rate limiting configured, not left on defaults
- Caching tuned so logged-in pages and checkout still work
- HTTPS enforced and the TLS minimum kept current
- Nine settings compared every morning against what we set
- A change you did not make put back by us
- Nothing installed on your website
- 90 days of daily history, so you can see what changed and when
- Your account stays yours, and our access can be withdrawn
Where Cascadia Goes Further
A virtual patch covers one known hole. Edge rules cover the steady noise that tries every door, and a daily comparison covers the settings nobody remembers changing.
The Noise Gets Dropped Before WordPress
Brute force runs, vulnerability scanners, and scrapers are turned away at the edge, so your server is not answering them at all.
Rate Limits Where Your Site Gets Hammered
Login pages, search, and forms each get limits that suit their traffic. Anything tight enough to affect real visitors is explained to you before it goes on.
Caching and TLS in the Same Service
Caching tuned so accounts and checkout keep working, browser cache set sensibly, HTTPS enforced, and the TLS minimum kept current.
Settings Checked Every Morning
Nine settings are compared daily with what we set. A change you did not make is put back and reported the next morning with its previous value.
Who This Comparison Is For
Patchstack Knows Your Plugins
Its alerts and mitigation rules are built around the software your site runs, with intelligence it says arrives up to 48 hours ahead of competitors. We do not track plugin vulnerabilities, and nothing we do replaces that.
Priced for People with Many Sites
The Developer plan is aimed at professionals and agencies, and Patchstack points individual site owners to hosting partners that include it. A single site may already have it through its host.
Different Jobs, Often Both Worth Doing
A vulnerable plugin and a login flood are separate problems. Plenty of sites are better served by running Patchstack and having the edge configured than by choosing one.
Choose Patchstack if
- Plugin vulnerabilities are your main worry
- You manage many WordPress sites
- You want alerts before issues are public
Choose Cascadia if
- Bots and login floods are wearing down your server
- Nobody is looking after the edge settings
- You want caching and TLS set properly
Adding Edge Protection to a Site That Runs Patchstack
Patchstack stays exactly where it is. Edge Protection installs nothing on the site, so the two work in different places.
- 1
We Read Your Current Edge Settings
We start with what is live and tell you what is wrong with it. Development mode left on and an outdated TLS minimum are both common finds.
- 2
We Set Firewall, Bot, and Rate Limiting Rules
Written for how your site is used, with exceptions for the tools you rely on and good bots let through. Risky rules are explained before they go on.
- 3
We Tune Caching and TLS
Caching is set to how the site is built, HTTPS is enforced, and the TLS minimum is brought current.
- 4
Patchstack and the Edge Each Do Their Part
Patchstack keeps handling plugin vulnerabilities. We compare the edge settings every morning and send a monthly report covering the month just ended.
What Clients Say About Working with Cascadia
“I’ve always dreaded website management, but Cascadia has done an incredible job with my WordPress site, making it one less thing for me to worry about.”
“I’ve worked with Cascadia for several years now. They are always ready to help in any way I ask and can implement my ideas with ease. A company that values their clients!”
“Cascadia has been great to work with! We recently needed some updates, and Cascadia was quick to get them completed! We highly recommend Cascadia Web Services.”
“Cascadia is very responsive and we’re happy with them as our primary IT vendor.”
“They do great work, been using for years. Prompt responses to requests.”
Ready to Move from Patchstack?
Talk to us about your setupAsk us
Patchstack Alternative Questions
Straight answers about switching, pricing, and what moves with you.
See Edge ProtectionStill have a question?
What is a Patchstack alternative?
Anything else that keeps attackers away from the software on your site. Plugin firewalls such as Wordfence and All-In-One Security, cloud firewalls such as Sucuri, and managed services like this one, which configure the edge in front of your site. Most of those do a different job from Patchstack rather than the same job differently.
How is Cascadia different from Patchstack?
Patchstack works through a plugin connected to its dashboard, and it deploys targeted rules when a plugin you run has a known vulnerability. We work at the edge, before requests reach your server. We set the firewall, bot protection, rate limiting, caching, and TLS for how your site is used, and compare nine settings every morning against what we set.
How much does Patchstack cost?
The Developer plan is $69 a month billed annually, or $828 a year, at 25 sites, with more sites at $12.50 a month per five (October 2026). Enterprise and host plans are priced on request. Edge Protection is $49 a month per domain.
Does Patchstack do anything you do not?
Yes. It tracks vulnerabilities in the plugins and themes you run, alerts you, and blocks attempts to exploit them without changing the plugin’s code. We do none of that, and we would not suggest dropping it for us.
Can I run both?
Yes, and for many sites that is the better answer. Patchstack works inside the site, and Edge Protection works in your edge account with nothing installed on the site.
Will an edge rule block my own customers?
That is the risk we plan around. Country rules and aggressive rate limits are explained to you before they go on, and exceptions are written for the tools you actually use.
What happens when a setting drifts?
You hear about it the next morning. Anything that moved becomes a ticket naming the setting and the value it had before, and if the change was not yours we put it back.
Do you keep a record of what you change?
Yes. Every setting we change is recorded, and daily snapshots are kept for 90 days, so you can see what something was, when it changed, and whether it was us.
Is this worth it for a single small site?
A small site is where the edge is most often left exactly as it came, and nothing is installed anywhere, so there is no overhead in running it. Whether $49 a month is worth it for your site is a fair question to ask us directly.
Do I need managed hosting to buy this?
No. It runs as a standalone monthly service on whatever hosting you already use. It is also part of Domain Pro, at $59 a month per domain.
How quickly does setup start?
Setup starts within two business days, and the first full picture of your settings arrives within a week.
What if I want to leave?
Withdraw our access. The edge account is yours, every change we made is recorded, and Patchstack carries on as before.
Ready to handle the traffic Patchstack does not see?
Forty-nine dollars a month per domain, with the edge in front of your site configured for how it is used and checked every morning.
