One plan for every site you look after
No per-site fee. Add every Craft site you maintain and put your whole team on it. There are no tiers to compare and nothing to count up, so you pay the same whether you look after five sites or fifty.
The price you see is the price you pay. No setup fee, no per-site charge and nothing added at checkout. Fourteen days free to start, and we do not ask for a card.
- Sites
- Unlimited Production, staging and development. Nothing counts against a quota, so you can add the staging site you actually want checked.
- Team members
- Unlimited Everyone on the rota gets their own login. Nobody shares an account to save a seat.
- Backup storage
- 2 GB included Encrypted database backups, held by us. Buy more in blocks if you need it, or keep your retention short and stay inside the allowance.
- Every capability
- Included Monitoring, security findings, licence tracking, backups and notifications. Nothing is locked behind a bigger plan.
Backup storage is the only thing that scales
Database backups take up real space on somebody's disk, so that is the one part we have to meter.
A typical Craft database compresses to somewhere between a few megabytes and a few hundred, so 2 GB covers a good number of sites on a sensible retention schedule. How much you need is mostly a question of how long you keep old backups rather than how many sites you have, so shortening retention is the first thing to try and it costs nothing. If you would rather keep the history, buy a block.
-
Included
2 GB, held by us
Encrypted on your site before it is uploaded. Nothing to set up.
-
£2 / 10 GB / month
More than 2 GB, held by us
Bought in blocks and added to your subscription. We email you at 80 per cent, and nothing is deleted without telling you first.
All of it, on the one plan
There is no bigger version of Manager to upgrade into. Everything below is what you get for £5 a month.
Monitoring
- Craft version, edition and PHP Plus database engine and version, on every site.
- Every plugin and Composer package With the version actually installed, not the one in the lock file you last read.
- Update availability Including whether a security release sits between what you run and what is current. That is the field that decides urgency.
- Licence state Craft editions and commercial plugin entitlements, worked out on the site. Keys are never transmitted.
- Queue and migrations Depth, failed jobs and pending migrations. Counts only, never the contents of a job.
- Connector heartbeats So a site that stops reporting is itself a signal.
Security
- Configuration findings Dev mode left on in production, HTTPS not enforced, schema changes permitted, the updater enabled.
- Severities that resolve themselves A finding closes when the site is fixed. There is nothing to tick off.
- Acknowledgement with a reason So the next person can tell a decision from a shrug.
- Audit log Every capability grant, revocation and key rotation, recorded.
Backups
- Craft-native database backups Through Craft's own db/backup, not mysqldump guesswork.
- Encrypted before they leave the site Granted separately, per site, behind its own confirmation.
- Retention by period, set per site Thirty days, then one a week for four weeks, then one a month for twelve months. Change any of the three.
- Verified on arrival Checked against the hash taken on your own server, with a notification when a run does not complete.
Notifications
- Email and signed webhooks So a security release on a client site reaches you without anybody opening a dashboard.
- A severity threshold per destination Five events. Set the floor for each destination so a low-severity notice does not wake anyone.
Manager watches; it does not change anything. It installs no updates, alters no configuration, runs no console commands, evaluates no PHP and executes no SQL. The connector has no capability for any of it, and a build script fails if such code ever appears.
Questions worth asking before you commit
Is it really unlimited sites?
Yes. Add every production site, every staging site and every local install if you want to. There is no quota, no per-site charge and no tier to grow into. The only thing that scales with how much you use it is backup storage, and how much of that you need is mostly a question of how long you keep old backups rather than how many sites you have.
How does billing work, and can I cancel?
Card payment, monthly or annually, handled by Stripe, and you can cancel whenever you like. No contract term and no cancellation fee. The price you see is the price you pay. No setup fee, no per-site charge and nothing added at checkout. Cancel and you keep access until the end of the period you have paid for, then the account stops. Your sites carry on exactly as before, because Manager never touched them in the first place.
What happens if I go over 2 GB of backup storage?
New backups are refused until there is room again, and nothing already stored is touched or deleted. Most of the time it settles on its own, because old backups are removed on the retention schedule you set. To make room permanently you have two options: shorten that retention, which costs nothing; or allow extra storage at £2 a month for each additional 10 GB, which an owner switches on from the billing screen so nothing is ever added to your bill without being agreed to first. We email at 80 per cent, which is before you run out rather than after, and again if you do go over.
Is there a free trial?
Fourteen days, and we do not ask for a card to start it. Add every site, put your whole team on, take backups, use all of it. Two reminders go out near the end so it cannot lapse without you noticing, and if you do nothing at the end of it, nothing is charged and nothing is deleted.
What happens if I stop paying?
We stop checking your sites and taking backups, and the console asks you to restart. Nothing is deleted at that point: every backup you have taken stays exactly where it is, still encrypted, and paying again brings all of it straight back. If an account stays lapsed for 30 days we destroy the stored backups, because holding somebody's database indefinitely after they have stopped being a customer is not caretaking. We tell you before that happens, and your sites themselves are untouched throughout, because Manager never had access to change them.
Who owns the data, and what do you actually hold?
Your data is yours, and Manager holds less of it than you would expect. It never receives an administrator password, an SSH credential or a site database password. There is nowhere in the schema to put one, and a test walks the live schema on every run to keep that true. What it stores is operational metadata: versions, packages, licence states, findings, queue counts. Never entries, assets, users, password hashes, logs, environment values or keys.
Are backups encrypted end to end?
Not yet, and we will not claim it before it is true. Backups are encrypted on your site before they are uploaded, and the site's own database password never leaves it. What we cannot honestly say today is that we are unable to decrypt them, so we do not say it. When that changes we will describe exactly who holds the keys.
What support is included?
Email support from the people who build Manager. There is no separate support tier and no priority queue to buy, because there is only one plan.
How do I report a security problem?
Email [email protected] and please do not open a public issue. We aim to acknowledge within two working days and to keep you posted while a fix is prepared. An advisory goes out once a fix is available, or after 90 days, whichever comes first. In scope: the platform, the connector and the shared protocol package.
Would rather run it yourself?
Manager Self-Hosted is free, open source (AGPL-3.0) and complete, with no per-site fee. You provide a server, Postgres, Redis and somebody to keep them patched. Most people would rather not, which is what the £5 is for.
Either way, the connector is the same
Cloud and self-hosted run the same core and speak the same protocol, so moving between them means re-pairing your sites rather than rebuilding anything. Start wherever you like; changing your mind later costs an afternoon, not a migration project.
Built for Craft CMS 4.4 and later. Read-only monitoring by default. Open source.