Skip to content
ServerPulse
Live monitoring · one console

Every request, every file change, every attack — as it happens.

ServerPulse watches the websites and servers you are responsible for, wherever they are hosted — shared hosting, a VPS, or behind a CDN — and tells you what changed, when, and what it means. It works from the outside with nothing installed, and goes considerably deeper when you upload one PHP file.

Five sites to start with. Ask for more when you need them.

serverpulse.dxcslabs.com/app Live
Sites up 18 2 down
Open incidents 3 1 critical
Requests 24h 1.42M 9.1k visitors
Attacks blocked 2,318 SQLi, scanners

Fleet requests · 24 hours

Requests and errors per hour

Requests Errors

Live activity

09:41:02 Critical SQL injection blocked · 203.0.113.9
09:40:55 Low Scanner blocked · /wp-login.php
09:40:31 High shop.example.com down · connect refused
09:39:12 Medium Certificate 12 days remaining
09:38:44 High File changed wp-config.php
The console, with example figures.

What it actually checks

Six things, continuously, for every site you add. Each one has a page of its own in the console with the raw evidence behind the summary — no score without the reason for it.

Availability

Checks as often as every 30 seconds, with DNS, connect, TLS handshake and time-to-first-byte measured separately — so "the site got slow" becomes "DNS went from 4 ms to 900 ms".

Certificates & DNS

Expiry, chain, hostname match and grade for every certificate, plus a record-by-record DNS change log. You hear about an expiry with weeks to spare, not from a visitor.

Traffic

Every request with its real client IP, even behind Cloudflare. Paths, countries, referrers, browsers, bots versus people, and which pages are slowest.

Attacks

A request firewall on the site itself: injection, traversal, scanners, brute force. Blocked or logged, each with the payload excerpt and an explanation of what was being attempted.

File integrity

A hash of every file, compared on a schedule. Changed, added and deleted files with excerpts, and malware signatures on what looks executable.

Origin exposure

Works out which CDN you are behind and whether your origin server still answers directly — the misconfiguration that quietly makes a CDN decorative.

Three tiers, and none of them is about money

How much ServerPulse can tell you depends on how much of it you install. You can stay on the first tier forever; plenty of sites do. Moving up takes about two minutes and never needs SSH.

Agentless

Nothing to install

Point ServerPulse at a URL. Everything here is measured from the outside, the way your visitors see it.

  • Uptime checks as often as every 30 seconds, with DNS, connect, TLS and time-to-first-byte broken out
  • TLS certificate expiry, chain and hostname validation
  • DNS record monitoring, with a change log
  • Security header grading and a plain-English explanation of each gap
  • Blacklist and reputation checks
  • Origin analysis: which CDN you are behind, and whether your origin server is still reachable directly

No CPU, memory, disk, traffic or attack data — none of that is visible from outside.

PHP agent

One file in your web root

Most useful

Upload a single PHP file. It works on shared hosting, needs no SSH, no root, and no extensions — PHP 7.2 and up.

  • Everything in Agentless
  • CPU, load, memory, swap, disk and inode usage, minute by minute
  • Every request: path, status, response time, real visitor IP behind any proxy
  • Live visitor count with a country breakdown
  • Request firewall: SQL injection, XSS, traversal, scanners and brute-force attempts, blocked or logged
  • File integrity scanning with diff excerpts, and malware signatures
  • Environment inventory: PHP version and extensions, web server, database, open ports

WordPress plugin and theme inventory needs the WordPress connector.

WordPress connector

A plugin, installed the usual way

The same agent, packaged as a WordPress plugin, plus everything that only makes sense inside WordPress.

  • Everything in the PHP agent
  • Core, plugin and theme inventory with versions
  • Update-available and known-vulnerability flags per component
  • Core file integrity against the official checksums
  • Login protection: failed attempts, user enumeration, brute-force lockouts

Getting started

  1. 1

    Add an address

    Paste a URL or an IP. Before anything is saved, ServerPulse resolves it and tells you what it found: whether it answers, where it redirects, whether the certificate is valid, and whether a CDN is in front of it.

  2. 2

    Watch the first check

    The first availability check runs immediately, not on the next scheduler tick. Uptime, TLS, DNS, headers and reputation start filling in within a minute.

  3. 3

    Install the agent, or don’t

    If you want CPU, traffic and attack data, download one pre-configured PHP file and upload it to your web root. The console flips to “connected” the moment it reports.

What it does not do

Worth knowing before you sign up, rather than after.

  • It does not fix anything for you. It tells you a file changed, what changed in it, and when — restoring it is your call.
  • It is not a CDN or a WAF in front of your site. The firewall runs inside your site, on your server, and blocks the request after it arrives.
  • It does not check from multiple continents. Checks run from one probe location, so it distinguishes “your site is down” from “your site is slow”, not “your site is slow in Sydney”.
  • It does not store visitor data forever. Traffic and security records are pruned on your company’s retention setting, 30 days by default.

Add your first site in about a minute

No agent required to start. Add an address, watch the first check run, and decide later whether you want the server-side half.