Free

€0

Unlimited sites, forever

  • Honeypot sensors
  • Two-factor authentication
  • Single sign-on
  • Firewall and geo blocking
  • Vulnerability scanner
  • Hardening score
  • Audit log, 90 days
  • Security headers
Download free

Pro

€59/yr

1 site

  • Everything in Free
  • Encrypted backups
  • Upload to your own cloud
  • Audit log, 1 year
  • Email support
Join the waiting list
For security teams

Business

€179/yr

5 sites

  • Everything in Pro
  • Microsoft Sentinel streaming
  • CEF and Syslog export
  • Audit log forwarded to SIEM
  • Priority email support
Join the waiting list

Agency

€399/yr

25 sites

  • Everything in Business
  • Move licences between sites
  • Priority email support
Join the waiting list
Pro is built and running today.

It is not on sale yet — we are finishing payment setup. Join the waiting list and you will get a founding discount when it opens, plus the option to try it before then.

Prices exclude VAT, which will be calculated at checkout based on your country.

Founding customers

Join the waiting list.

Tell us what you manage and what matters most. We will email you when paid plans open; volunteers can also opt into the small early-testing cohort.

No captcha, tracking scripts or marketing platform. Your answers stay in this site’s private WordPress admin.

Full comparison

What each tier includes.

Feature Free Pro Business Agency
Detection
Honeypot decoys✓✓✓✓
Attack classification✓✓✓✓
Vulnerability scanner✓✓✓✓
Hardening score✓✓✓✓
Access control
Two-factor authentication✓✓✓✓
SSO — Microsoft, Google, GitHub✓✓✓✓
IP and country blocking✓✓✓✓
Security headers✓✓✓✓
Evidence
Audit log retention90 days1 year1 year1 year
CSV export✓✓✓✓
Microsoft Sentinel——✓✓
CEF / Syslog export——✓✓
Backup
Encrypted local backups—✓✓✓
Upload to Drive, OneDrive, Dropbox—✓✓✓
Scheduled backups—daily+daily+daily+
Licence
Sites includedunlimited1525
Supportforumemailprioritypriority
Why free is this generous

Every install is a sensor.

The more sites running DecoyNest, the sooner a new attack pattern shows up in the data, and the better detection gets — including for the people paying nothing. We would rather run ten thousand sensors and sell to the organisations that need SIEM integration than meter the basics.

Sharing anonymised attack metadata with that network is a separate opt-in, off by default. It never includes your site content, and the plugin works exactly the same if you leave it off.

Questions

The ones that actually matter.

What happens when a licence expires?

Detection keeps running. Honeypots, two-factor, SSO, firewall, scanning, hardening and the audit log are all free features and are unaffected.

Backups and Sentinel streaming stop, and you stop receiving Pro updates. Nothing is deleted — existing backup archives stay where they are, and your logs stay in your database.

What if your licence server goes down?

Paid features keep working for 72 hours after the last successful check, so an outage on our side does not take your backups offline. Validation is cached for 24 hours in normal operation, so the plugin is not calling home on every page load.

The grace period never extends past your actual expiry date.

Can I move a licence to another site?

Yes. Deactivate it on the old site first, which releases the activation slot immediately and removes the stored key from that install. Then activate on the new one. There is no cooldown and no penalty.

Does a staging site use up a slot?

A staging copy of a site you already licensed does not count against your limit. Activation is keyed to the site URL, so a copy on a different hostname is recognised as a separate install — tell us and we will add it at no cost.

Where do encrypted backups actually go?

To your server, and optionally to your own Google Drive, OneDrive or Dropbox account. Never to us — we do not operate backup storage and do not want custody of your database.

Archives are encrypted before they leave the site, with AES-256-GCM or XChaCha20-Poly1305. Cloud upload is refused outright if encryption is not configured, because an unencrypted database dump in cloud storage is a breach waiting to be indexed.

What data do you collect about my site?

For a licence check: the key, your site URL, a random installation identifier, and the plugin version. That is what proves the licence is valid and counts your activations.

For vulnerability scanning: the version numbers of your core, plugins and themes, so we can match them against known issues. Not your content, not your users, not your files.

Attack telemetry is opt-in and separate. Full detail is in the privacy policy.

Do you offer refunds?

Fourteen days, no questions asked. You have that right under EU consumer law regardless of what we write here, so there is no sense pretending otherwise.

Is the plugin open source?

Yes — GPL v2 or later, like WordPress itself. Paid tiers pay for the hosted services behind them: licence validation, the vulnerability database, and support.

Start with free. Upgrade if you need the reporting.

Nothing in the free tier expires, nags, or turns itself off.