Skip to content
Manager for Craft

Everything it
watches

Manager reads what each Craft site is actually running and tells you what needs doing. It never changes anything, which is why it can be trusted with all of them at once.

What Manager watches

  • Updates Outstanding Craft and plugin updates across every site.
  • Security Advisories matched to the versions you actually run.
  • Licences Craft editions and commercial plugin entitlements.
  • Backups Scheduled database backups, verified and retained.
  • SSL Certificate expiry, issuer and chain checks.
  • Connections Connector heartbeats, PHP and platform versions.

Craft is not just another integration

Manager understands the operational information Craft developers already work with. It does not reduce every website to a generic uptime result.

  • Craft CMS 5+

    built against current Craft

  • Editions and licences

    solo · pro · enterprise

  • Plugin handles and versions

    vendor/package · 5.2.0

  • Composer constraints

    ^5.0 conflicts surfaced

  • Project Config state

    pending changes flagged

  • Pending migrations

    craft up outstanding

  • Queue health

    failed jobs · backlog age

  • PHP and database compatibility

    php 8.3 · mysql 8.0

  • Production and development environments

    grouped per project

  • Craft-native database backups

    db/backup, not mysqldump guesswork

Start with the sites that need attention

Manager groups sites by their current state, so you can see what is healthy, what needs attention and what has stopped reporting before you open a single control panel.

Sites · needs attention Client: Bracken & Field

Northgate Trust

northgatetrust.org Production Backup failed
Craft
5.6.4
PHP
8.3.14
Updates
6 pending
Backup
Failed 02:15
Heartbeat
1m ago

Harbour Lodgings

harbourlodgings.net Production Updates due
Craft
5.4.9
PHP
8.2.30
Updates
11 pending
Backup
4d ago
Heartbeat
4m ago

Redland Studio

redlandstudio.example Production Not reporting
Craft
5.3.1
PHP
8.2.24
Updates
Unknown
Backup
No schedule
Heartbeat
3d ago
  • Production and development environments Grouped by project, so staging noise stays out of the way.
  • Last connector heartbeat Know when a site stopped reporting, not just when it broke.
  • Craft and PHP versions Spot the site holding back a platform upgrade.
  • Open findings and update counts Severity-weighted, so twelve minor updates never outrank one advisory.
  • Backup state Last successful run, schedule and retention at a glance.
  • Client and site grouping Filter to one client before a maintenance call.
  • Search and filtering Search across sites, plugin handles and findings.

Updates and licences across the whole fleet

Stop opening every control panel just to find out what has changed. Manager reads installed and available versions, Composer constraints, Craft edition and commercial plugin licence states.

  • Craft core updates
  • Plugin updates
  • Installed and available versions
  • Composer compatibility problems
  • Security-related releases
  • Craft edition
  • Licence and entitlement states
  • Domain or licence mismatches
northgatetrust.org · outstanding updates Craft Pro · 24 plugins
Outstanding Craft and plugin updates for northgatetrust.org
Package Installed Available Note
Craft CMS craftcms/cms 5.6.4 5.7.1 Security release
SEOmatic nystudio107/craft-seomatic 5.1.8 5.2.0 Minor
Formie verbb/formie 3.0.12 3.1.4 Licence expired
Imager X spacecatninja/imager-x 5.0.3 5.1.1 Minor
Blitz putyourlightson/craft-blitz 5.4.0 5.6.2 Needs PHP 8.3
Guzzle PSR-7 guzzlehttp/psr7 2.6.1 2.7.0 Advisory

Manager reports available updates. It does not deploy them for you.

Find vulnerable dependencies before they are forgotten

Craft security releases, plugin advisories and Composer package advisories are matched against the versions actually installed on each site, with severity, evidence, fixed versions and remediation guidance.

Findings carry first and last detected dates, and can be acknowledged or recorded as accepted risk with a reason, so nothing quietly disappears from the list.

High Vulnerable Composer dependency First detected 14 Jul · last seen today

guzzlehttp/psr7 2.6.1

Affected by a published request-smuggling advisory. Upgrade to 2.7.0 or later.

Installed
2.6.1
Fixed in
2.7.0
Affected sites
3

Database backups, without sharing database credentials

  1. 01 Manager schedules an authorised backup.
  2. 02 The connector asks Craft to create it.
  3. 03 The backup is encrypted and uploaded.
  4. 04 Manager verifies the artifact and applies retention.
  • Optional per site
  • Configurable schedules
  • Configurable retention
  • Encrypted storage
  • S3-compatible destinations
  • Backup history
  • Failure notifications
  • Checksums and verification
Backup history · northgatetrust.org Daily 02:15 · keep 14
Recent backup runs for northgatetrust.org
Run Result Size Checksum
Today 02:15 Failed n/a timeout after 240s
Yesterday 02:15 Verified 412 MB sha256 9f3c…41ab
28 Jul 02:15 Verified 409 MB sha256 71de…c802
27 Jul 02:15 Verified 407 MB sha256 2ab8…5f19
26 Jul 11:40 Manual 406 MB sha256 c410…88d7

Artifacts are encrypted before upload to your S3-compatible destination. Production database passwords stay on the site.

Hear about the issues that matter

Email, browser push, signed webhooks and in-app notifications. Choose immediate alerts or a daily or weekly digest.

  • Immediate alerts
  • Daily or weekly digests
  • Severity rules
  • Site and tag filters
  • Quiet hours
  • Maintenance windows
  • Recovery notifications
  • Alert deduplication
  • Warning SSL certificate expires in 12 days woldheritage.org.uk · email, webhook
  • Warning Connector has not checked in since yesterday redlandstudio.example · email
  • High A high-severity package vulnerability affects three sites guzzlehttp/psr7 · email, push, webhook
  • Critical Scheduled database backup failed northgatetrust.org · 02:15 · email, push
  • Notice Plugin update entitlement has expired verbb/formie · weekly digest

See what changed and who handled it

Manager keeps an activity history across the organisation: findings opened and acknowledged, backups completed, connectors paired, capabilities enabled and credentials rotated.

Findings can be assigned so it is clear who is looking at what, without turning Manager into a project tracker.

  1. 09:12 Finding opened · guzzlehttp/psr7 advisory matched on 3 sites System
  2. 09:40 Finding acknowledged · scheduled for Thursday release A. Mercer
  3. 10:02 Backup capability enabled · northgatetrust.org A. Mercer
  4. 10:03 Connector credentials rotated · northgatetrust.org A. Mercer
  5. 11:20 Connector paired · brackenfield.co.uk (staging) J. Okafor
  6. 13:45 Backup completed and verified · 412 MB System
  7. 16:08 Issue resolved · SSL certificate renewed J. Okafor

Connect a site in a few minutes

  1. 01 Add the site in Manager.
  2. 02 Install the connector through Composer.
  3. 03 Enter the one-time pairing code.
  4. 04 Review the requested capabilities.
  5. 05 Receive the first heartbeat.

Pairing codes are single-use. Connector credentials can be rotated or revoked at any time.

Terminal · northgatetrust.org
$ composer require manager/craft-connector
  Using version ^1.2 for manager/craft-connector
  Package operations: 2 installs, 0 updates

$ php craft manager/connect
  Pairing code: 7QF2-K91D
  Requested capabilities:
    · read craft & plugin versions
    · read licence state
    · read ssl & queue health
    · backups (not enabled)
  Paired. First heartbeat received.

Keep every Craft site in view

Add your sites, connect the plugin and see what needs attention.

Built for Craft CMS 5 and later. Read-only monitoring by default.