Supported CMS WordPress

WordPress, wrapped — not rebuilt.

Sitewrap sits in front of your existing WordPress site with edge cache, Hide WordPress, admin gating, WAF defaults, and Forms & Leads. Keep your theme, plugins, and hosting.

No plugin stack requiredOxygen-safe cacheWorks with any host
Hide WordPress Public ↔ origin
/assets /wp-content
/vendor /wp-includes
/api /wp-json
/admin /wp-admin
/login.php gated · /wp-login.php
XML-RPC blocked · author enum blocked · admin unlock required
Built for WordPress Edge-first

Everything WordPress operators ask for — at the edge.

Security plugins and host panels still matter. Sitewrap adds the layer visitors hit first: remaps, gates, cache, and form defense that do not require a rebuild.

Hide WordPress

Erase the fingerprint

Remap /wp-content, /wp-includes, /wp-json, /wp-admin, and /wp-login.php to cleaner public paths. Sitewrap rewrites HTML, CSS, and JS so visitors never see the usual WordPress tells.

  • Path mappings you control
  • Rewrites in cached responses
  • Works with remapped admin gate
Admin gate

Login is not a public endpoint

Gate /wp-admin and /wp-login.php until Sitewrap unlocks them with a passwordless magic link or short code. Scanners never reach the real login screen.

  • Unlock cookie on your domain
  • Respects Hide WordPress paths
  • Operators stay productive
WordPress WAF

Quiet the noisy surfaces

Disable XML-RPC, harden comments and REST user endpoints, block author enumeration, and stop readme/license probes — without stacking another security plugin.

  • XML-RPC off by default option
  • Author & REST user protections
  • Suspicious probe handling
Cache

Fast pages, Oxygen-safe

Edge cache and preload from wp-sitemap.xml (or your sitemap) so visitors hit Sitewrap first. Builder and editor traffic stays on origin so Oxygen and similar tools keep working.

  • Sitemap crawl & warm
  • Stale-while-revalidate options
  • Editor paths stay uncached
Forms & leads

CF7 and WPForms without the spam

Detect Contact Form 7, WPForms, and other HTML forms on proxied pages. Protect submissions at the edge and land clean leads in Sitewrap — field mapping included.

  • Honeypot + time-on-page
  • Per-IP form rate limits
  • Lead groups & visitor context
Onboarding

WordPress detected → defaults ready

When Sitewrap recognizes WordPress during setup, you can apply a recommended security skeleton before cutover — firewall, WAF toggles, and route hygiene included.

  • Detection in the wizard
  • One-click recommended settings
  • Tune later in the dashboard
Setup Minutes, not months

From detection to production cutover.

The dashboard wizard recognizes WordPress and nudges you toward a safe starting config.

01

Add your WordPress site

Enter the public domain and current origin. Sitewrap verifies ownership and checks reachability.

02

Apply WordPress defaults

If WordPress is detected, review Hide WordPress, WAF, admin gate, and cache recommendations — then save.

03

Warm the important pages

Point preload at wp-sitemap.xml (or your sitemap) so key URLs are cached before you switch traffic.

04

Point DNS and go live

Issue TLS, flip the A record, and operate from the dashboard — cache, firewall, forms, analytics, deploy.

Keep the rest of the Sitewrap stack.

Request log, live users, Mixpanel/GA4, A/B tests, deployments, and AI assist work the same on WordPress as on any other origin.

Platform Multi-origin

Built deep for WordPress. Ready for everything else.

Agencies and product teams often run WordPress beside marketing sites, headless fronts, and static exports. Sitewrap wraps each property the same way — with WordPress getting the richest defaults.

  • Any CMS behind the same edge controls
  • Static websites without a CMS at all
  • Custom origins and hybrid stacks
FAQ

WordPress questions, answered.

Do I need to rebuild my WordPress site?

No. Sitewrap sits in front of your existing WordPress origin. Keep your theme, plugins, hosting, and editors — Sitewrap adds the edge layer.

Will Oxygen / page builders still work?

Yes. Builder and editor requests are treated as origin-bound so you can edit safely. Public visitors get the cached, optimized experience.

What does Hide WordPress change?

It remaps common WordPress paths to cleaner URLs and rewrites references in HTML, CSS, and JavaScript served through Sitewrap. Your origin still speaks WordPress paths upstream.

Is Sitewrap only for WordPress?

No. Firewall, cache, analytics, forms, deploy, and admin gating work in front of any CMS or static site. WordPress gets deeper defaults and remaps — this page is that story.

Can agencies standardize this across clients?

Yes. Wrap each client domain, apply the WordPress skeleton, and manage cache, security, leads, and deploys from one Sitewrap account.

Wrap WordPress without rewriting it.

Create a Sitewrap account, apply WordPress defaults, gate admin, and warm your sitemap — then point DNS.