Overview
Security on StretchWP comes from several layers working together: automatic SSL so traffic is encrypted, TLS health checks so you know the certificate is valid, and the managed Defender plugin providing firewall, hardening, and malware scanning. Most of this runs without your involvement — this article explains what's protecting your site and how to confirm it's working.
SSL and encryption
Every managed site is served over HTTPS. When you attach a custom domain and complete the DNS cutover, StretchWP issues and renews an SSL certificate automatically — there's no certificate to buy, upload, or remember to renew.
To check SSL status:
- Open the site and look at the SSL status pill in the header. Green means the certificate is active/issued.
- Open the Domains tab to see the SSL state per domain (for example issued or not requested).
- Open the Health tab and confirm TLS / HTTPS reads valid on the latest probe.
Reading TLS in Health
StretchWP's health probe checks your public hostname over HTTPS and reports whether the certificate validated. A TLS valid reading on the Health tab is real-world confirmation that visitors reach your site over a trusted, encrypted connection — not just an internal assumption.
Defender: firewall, hardening, and malware scanning
The managed Defender plugin is part of the core suite installed on every site. It provides:
- A firewall and hardening to block common attack patterns and reduce your site's attack surface.
- Malware scanning — the platform can run a scan command against a paired site to check for malicious code, and the Stretch team acts on the results.
Because Defender is part of the managed suite, it's kept current through signed platform updates (see Managed plugin updates and the StretchWP plugin suite), so its protection rules stay up to date automatically.
Steps: confirm your site is protected
- Check the pills. Open the site; confirm the SSL pill is green and the Site pill reads live.
- Verify TLS in Health. Open Health and confirm the latest probe shows TLS valid with an HTTP status of 200.
- Confirm Defender is active. On the Plugins tab, check that the Defender plugin is present and active.
- Review Events for security activity. The Events tab records control-plane activity; scans and other managed actions appear there with timestamps.
Example
Before launching a client's site, an agency runs a pre-launch check. The SSL pill is green, the Health tab shows HTTP 200, TLS valid, and the Plugins tab confirms Defender is active. They ask the Stretch team to run a malware scan for peace of mind; the scan comes back clean, recorded on the Events timeline. The site launches with encryption, a firewall, and a clean bill of health — all documented.
Tips
- Green SSL + TLS valid = encrypted for real. Trust the Health probe's TLS reading; it reflects what visitors actually get.
- Let SSL auto-renew. You never need to renew manually. If the SSL pill ever shows expired, that's a signal to contact the Stretch team, not a task to do yourself.
- Keep Defender in place. As a core managed plugin, Defender's protection is strongest when left active and allowed to update through signed packages.
- Ask for a scan before big moments. Before a launch or after suspicious activity, request a malware scan from the Stretch team.
Troubleshooting
- SSL pill shows not issued or expired. For a new custom domain, SSL is issued after the DNS cutover completes — confirm your A/CNAME records point at StretchWP (see Connecting your custom domain). If it persists after DNS has propagated, contact the Stretch team.
- Health shows a TLS error. Note the exact reading and the time, and escalate to the Stretch team — a certificate that fails to validate is worth immediate attention.
- You suspect malware or a defacement. Don't try to clean it from wp-admin blindly. Contact the Stretch team, request a malware scan, and note anything unusual you've observed; the team can scan, review, and restore from a clean backup if needed.
Was this helpful?
Help us improve this article
Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.

