Overview
StretchWP ships and maintains its own suite of WordPress plugins, and it updates them for you through signed packages delivered by the platform — not the public plugin directory. This means the plugins that handle your site's security, SEO, analytics, images, backups, and performance are kept current and verified without you touching a single Update button.
This article explains the core suite and how managed updates work.
The core plugin suite
Every managed StretchWP site is provisioned with a core set of plugins, installed and activated for you:
- Dashboard (SSO) — the connection to your workspace. It powers pairing, live telemetry, one-click login, and managed updates. This one is mandatory and shouldn't be removed.
- Defender — security: firewall, hardening, and malware scanning. (See Site security and SSL.)
- SEO — search-engine optimization tooling for titles, meta, sitemaps, and on-page checks.
- Analytics — visitor and traffic analytics for the site.
- Scrunch — automatic image optimization, so media stays sharp but lightweight.
- Snapshot — backups: scheduled snapshots and restore points. (See Backups and restore.)
- Optimizer — caching and performance tuning. (See Site performance and optimization.)
Beyond the core set, additional plugins can be enabled on demand when a site needs them — for example email, forms, commerce, translation, consent/cookie management, reviews, comments, or media folders. These aren't preloaded; the Stretch team enables them per site as required.
How managed updates work
- The platform publishes a new version. When StretchWP releases an updated plugin, it's packaged and cryptographically signed by the platform.
- Your paired site is entitled to it. The site's connection (via the dashboard plugin) knows which managed plugins it's entitled to and what versions are available.
- The update is delivered securely. When an update runs, the site fetches the package through a short-lived, single-use download link and verifies the signature before installing. A package without a valid platform signature is never applied.
- You see the result in the workspace. The Plugins tab reflects the new version, and the Plugin updates tile on Overview counts anything still pending.
The security benefit is significant: managed updates can't be spoofed or tampered with in transit, and your site won't install a package that doesn't carry a valid signature.
What you do (and don't do)
- You don't manually update the managed suite — the platform handles it.
- You do keep an eye on the Plugins tab and the Plugin updates tile, and flag anything that stays pending for a long time.
- You do request on-demand plugins from the Stretch team when a site needs a capability the core set doesn't cover.
Example
StretchWP releases a security update for Defender. Because the site is paired and entitled, the update is delivered as a signed package, verified on the site, and installed. Next time you open the site, the Plugins tab shows Defender at the new version and the Plugin updates tile is back to zero — all without you clicking anything. Later you decide you want a contact form on the site, so you ask the Stretch team to enable the forms plugin, which they add to that site's on-demand set.
Tips
- The Plugin updates tile is your at-a-glance signal. When it's highlighted, open the Plugins tab to see what's pending.
- Managed plugins are best left managed. Avoid replacing a StretchWP suite plugin with a public-directory equivalent — you'd lose signed-update protection and could create conflicts.
- Ask for on-demand plugins by capability. Tell the Stretch team what you need ("a contact form," "multilingual"), and they'll enable the right plugin for that site.
Troubleshooting
- An update has been pending for a long time. Confirm it on the Plugins tab and flag the plugin name and site to the Stretch team. Because updates are signed and platform-delivered, a stuck update is something the team should look at rather than something you force.
- A plugin I expect isn't listed. Core plugins should appear once inventory reports; give a new site a few minutes and refresh. On-demand plugins only appear after the Stretch team enables them for that site.
- I want to remove a managed plugin. Removing core plugins — especially the Dashboard/SSO plugin — breaks managed features. Talk to the Stretch team about the outcome you want instead of deactivating it yourself.
Was this helpful?
Help us improve this article
Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.

