SteadWeave Free includes complete monitoring for one website, free forever. There is no trial period and no expiration.
SteadWeave Companion is the complete WordPress plugin, not a separate “Lite” or feature-locked edition. Paid plans are available when you need to monitor more websites.
SteadWeave Companion is the lightweight WordPress-side connector for the SteadWeave external monitoring service.
The Companion does not perform the central monitoring workload locally. After a WordPress administrator explicitly starts setup and confirms the external-service disclosure, the plugin connects the site to SteadWeave. After pairing, authenticated technical heartbeats let the service evaluate WordPress health, software versions, update availability and other website-assurance signals.
The PHP, JavaScript, CSS, translations, documentation and bundled image assets distributed in this WordPress.org plugin package are licensed under GPLv2 or later. The SteadWeave name and source-identifying marks may also be protected by applicable trademark law; those trademark rights are separate from, and do not restrict, the GPL license granted for the copies of the bundled assets distributed with this plugin. See ASSET-LICENSE.txt and LICENSE.txt.
SteadWeave is a separate SaaS service. Service plans may differ by the number of websites that can be managed. The Companion does not hide premium PHP code or unlock local plugin functionality with a license key.
The plugin does not add analytics, advertising trackers, marketing pixels or public-site credits.
The Companion does not download or execute arbitrary PHP or JavaScript from SteadWeave, does not install plugins or themes remotely, and does not expose a general-purpose remote code execution mechanism.
SteadWeave Companion relies on the external SteadWeave service. The official production endpoint is:
https://app.steadweave.com/
No enrollment data or SteadWeave telemetry is sent merely by activating the plugin. The administrator must open the SteadWeave screen, review the disclosure and explicitly confirm the connection before the first enrollment request. The manual recovery path requires the same acknowledgement.
During enrollment the plugin sends:
After pairing, authenticated heartbeats send technical website telemetry including:
Regular heartbeat telemetry does not include page or post content.
The administrator-only manual recovery path sends one authenticated technical snapshot to verify candidate credentials before those credentials are stored locally.
The SteadWeave server also receives normal network metadata, such as the source IP address, as part of operating the HTTPS service.
When an authorized SteadWeave account user explicitly requests Assisted Remediation, the paired service may include a bounded Smart Fix command in an authenticated heartbeat response. The command identifies the requested fixer, target page, expected current state, proposed value and command identifier. Commands are subject to local validation, expiry and anti-replay controls before a write can occur.
Depending on the selected fixer and local capabilities, Smart Fix can:
http:// hyperlink references with their corresponding https:// references in published WordPress post_content.SEO-specific fixers are available only when one supported SEO provider is detected unambiguously. The HTTP-reference fixer does not require an SEO provider.
After a Smart Fix attempt, the Companion posts a structured result to the authenticated SteadWeave remediation-result endpoint. Depending on the fixer, that result can include the target page URL, command UUID, provider, whether data changed, previous value, new value, preflight evidence, rollback state and validation details used to verify the requested action.
To prevent replay of Smart Fix commands, the Companion keeps a bounded local command ledger containing sanitized remediation results for up to seven days. Disconnecting or uninstalling the Companion removes this local ledger.
No public Companion REST endpoint provides a general remote content-write API. Smart Fix commands are accepted only through authenticated responses from the paired SteadWeave service and are limited to the fixers implemented in this plugin.
Service information:
On normal production installations, the Companion is pinned to the official SteadWeave application endpoint. Custom central URLs are available only for local/development/staging environments or when the site owner deliberately enables the development override with STEADWEAVE_COMPANION_ALLOW_CUSTOM_CENTRAL.
SteadWeave Companion adds suggested privacy-policy text to Settings > Privacy in WordPress.
The suggested text describes enrollment data, regular technical heartbeat telemetry, Assisted Remediation commands, supported WordPress changes, the structured remediation results returned to SteadWeave and the bounded local Smart Fix anti-replay ledger retained for up to seven days.
The plugin also registers with the WordPress personal-data exporter and eraser for the enrollment email stored locally by the Companion. Service-side monitoring and remediation data is controlled by the SteadWeave service and is described in the SteadWeave Privacy Notice.
For service privacy information see https://steadweave.com/privacy/.
manage_options plus WordPress nonces.