> Uptime, certificates, attacks and file changes watched all day, with alerts that say why. One PHP file, no SSH. Free on every Growthzi site.

Source: https://growthzi.com/website-monitoring
Updated: 2026-10-01

---

Growthzi Secure · Monitor

# Know when your site breaks, *and why*.

We watch the websites you are responsible for. Uptime, certificates, traffic, attacks and file changes, and we explain every alert in plain words. From the outside with nothing installed, and much deeper with one PHP file that runs on ordinary shared hosting.

Demo Shop Down for 41 s every 30 s from one probe

Uptime, 30 days 99.94%

Response 3.0 s

Attacks blocked today 42

Requests, from the server’s own log Live

- GET /checkout 502 3.0 s
- GET /products/kurta-blue 502 3.0 s
- POST /wp-login.php Blocked 403 9 ms
- GET /cart 200 184 ms
- GET / 200 142 ms
- GET /products?page=2 200 231 ms

Incident opened 10:42:06

## Why it’s marked down

3 of 3 checks got `502 Bad Gateway` after 3.0 s

DNS in 4 ms, certificate valid for 58 days. The network is fine.

The agent is still reporting: CPU 31%, PHP workers 5 of 5 busy.

**Likely:** PHP-FPM ran out of workers after a plugin update. Restart it, then raise `pm.max_children`.

The console, replaying an example incident. Example data.

No card. We set it up on your own sites with you, you see your own data, then you choose a plan.

## No trial and no price list. Your own sites first.

A trial on a sample site tells you very little, and an account nobody set up is worse than none because it looks like cover. So we set it up on the sites you actually run, with you, and you decide what it is worth once you have seen your own data.

1. 1 Book a demo Tell us which sites, where they are hosted and what prompted it. Two minutes, no card.
2. 2 We set it up with you On a call, on your real sites. Checks, the agent where it earns its place, alerts to the right people.
3. 3 You see your own data Uptime, traffic, attacks, file changes and DPDP findings from your sites, not a demo account.
4. 4 Then you choose a plan Sized to what you now know you need. The price is agreed then, and nothing is charged before.

### If your site is built on Growthzi

The outside in checks are already on and they stay free. Uptime, certificates, DNS, headers and blocklists, from the minute you published. A plan is only for going deeper.

### If somebody else built it

Which is most of the sites we watch. WordPress, Laravel, a static build, shared cPanel hosting with no SSH. Start with a demo on your real sites rather than a signup form.

## Everything it watches, including the gaps

All 25 modules, as the console has them. Where something needs the agent on your server, it says so. A feature list with no boundaries on it is a feature list nobody believes.

### Monitoring

What we check from the outside, with no agent.

Uptime and response time Checks as often as every 30 seconds, with DNS, connect, TLS handshake and time to first byte measured separately. Failures collapse into one incident with a start, an end, a timeline and a plain English reason.

TLS certificates Expiry, chain completeness, hostname match and grade. You hear about an expiry weeks ahead, not from a visitor.

DNS monitoring Records as they were, with the date each one moved. The most common site is down that is nobody’s server.

Security headers Each missing or weak header graded, with the exact line for Apache, Nginx or your CDN that fixes it.

Blocklist monitoring Spam and malware lists, Safe Browsing included, so you learn your domain was listed before your email starts bouncing.

Origin exposure Works out which CDN you are behind and whether your origin still answers directly. The misconfiguration that quietly makes a CDN decorative.

### Security

Detection and blocking.

Attack detection Needs agent A request firewall inside the site: SQL injection, XSS, traversal, scanners and brute force, each with the attacker’s own request and an explanation of what was being tried.

IP blocking Needs agent Block an address or range straight from the evidence, and let the firewall refuse attacks rather than only record them. Enforced on your server.

File integrity and malware Needs agent A hash of every file, compared on a schedule. Changed, added and deleted files with excerpts, and malware signatures on anything executable. A web shell in uploads/ shows the matched line.

Privacy readiness for DPDP Trackers before consent, a named grievance officer, retention statements, forms collecting personal data, cookie behaviour. Rechecked weekly, emailed only on change. Findings and fixes, never a verdict.

### Agent insight

What the agent inside the site reports.

Traffic analytics Needs agent Every request from the server’s own log: path, status, response time and the real visitor IP behind a CDN. A live view, people separated from bots, server errors and the slowest pages.

Stack and vulnerabilities Needs agent PHP, web server, database, CMS, plugins and packages, discovered rather than declared, matched against published advisories with the version that fixes each one.

Server posture Needs agent PHP settings that should be off, files that are writable when they should not be, and for WordPress, database hardening checks.

### Code audit

Scanning the code a monitored site is deployed from.

Code audit Connect a Git host and scan the repository behind your site for secrets, vulnerable code and dependencies. Findings show only once the repository is verified as yours.

Scheduled code scans Scan tracked branches daily or weekly without anyone pressing a button.

Scan on push A webhook queues a scan whenever a tracked branch is pushed.

Deep code analysis Adds Semgrep, Gitleaks and npm audit to the built in rules and Composer advisories.

Explain and fix for code An AI explanation and a suggested fix for a code finding.

### Intelligence and reporting

Explanations and scheduled summaries.

AI analysis and the assistant Ask questions about your own data, such as why the shop was slow on Tuesday, and get AI triage that explains a suspicious file and how to fix it. Metered in credits per month.

Reports Uptime, incidents and security for any period, as a page or a download, and scheduled to your inbox weekly or monthly.

### Account and integrations

People, integrations and branding.

API access Bearer token access to the same JSON API the console uses, for your own dashboards and scripts.

Slack, Teams, Telegram and webhooks Signed webhooks, per site and per severity, alongside email and the in app centre.

Team members Owners, managers and viewers. A viewer login is how a client sees their own uptime without being able to change anything.

White label Your colour and logo on the console and reports, so an agency’s clients see the agency.

Assisted support Grant our team time boxed access to look at your data with you. You approve it, it expires, and it is logged.

## Three plans, none of them about money

Every teammate gets a login on every plan, and alerts are never a premium feature. The plans differ in how deep it goes and how much of it you get.

| Limit | Starter Outside in only | Professional Most teams start here | Business Everything |

| --- | --- | --- | --- |

| Monitored sites | 5 | 25 | Unlimited |

| Team members | 3 | 10 | Unlimited |

| Data retention | 30 days | 90 days | 365 days |

| Fastest check interval | 5 min | 1 min | 30 s |

| AI analyses per month | Not included | 500 | 5,000 |

| Code repositories | Not included | 5 | 25 |

| The agent, firewall, file integrity | Not included | Included | Included |

| White label, assisted support | Not included | Not included | Included |

| Price |  |

Unlimited means no limit is set on the plan. Limits can be raised for an account without changing plan, just ask on the call. More than a hundred sites, or an estate that fits none of these? Tell us about it and we will size it.

## In every plan, including the smallest

Not upsells. A monitoring product that puts alerting behind a higher tier is selling a dashboard.

### Alerts that reach a person

Severity routing, quiet hours and repeat collapsing, so thirteen notifications about one outage arrive as one that says thirteen.

### DPDP readiness, weekly

An email only when something actually changed. Findings and fixes, never a compliance verdict.

### Reports you can send on

Uptime, incidents and security for any period, as a page or a download.

### Proper GST invoices

CGST and SGST within the state, IGST across it, zero rated for exports, with a printable copy for your accountant.

## Or, by the question you are asking

### Is it up, and was it up?

The question that gets a monitoring tool bought, and the one most tools answer with a green dot and no evidence.

Timing broken into four parts

DNS, connect, TLS and first byte, separately, because slow has four causes and three different fixes.

Uptime that states its basis

A percentage with the window, the check count and the downtime it came from. A bare 99.9% is unfalsifiable.

### Who is visiting, and who is attacking?

Read from the access log by the agent, so it is your server’s own record rather than a tag a visitor can block.

What was attempted, not just blocked

412 attempts on /wp-login.php from one address is evidence. Brute force detected is a mood.

Real visitor IPs behind any CDN

The proxy headers are unwrapped rather than reported as the visitor.

### Has anything changed that shouldn’t have?

The question you cannot answer after the fact unless something was watching before.

Files, with the diff

A finding is readable, the changed lines, rather than a filename and a hash.

DNS and certificates

Every record change dated, every certificate watched to expiry.

### Would we survive being asked?

India’s DPDP penalties begin on 13 May 2027, and the Board moves from guidance to supervision in November 2026. This part of the product exists because of those dates.

A score with its denominator

Checks that could not run are excluded and counted, and the report says how much a web request can see at all.

Never a compliance verdict

No field in the data model holds one. Findings and fixes. The legal opinion stays with your lawyer.

## What no plan includes

Worth knowing before a call rather than after a month.

### No SMS or phone calls yet

Alerts go to email, Slack, Teams, Telegram and webhooks. If someone must be woken by a ringing phone, we are not the whole answer yet.

### No application tracing

We measure what a request cost and what the server was doing. We do not profile your code.

### No log aggregation

We read your access log for traffic and attacks. It is not a place to ship application logs.

### One probe location

It tells down from slow, not slow in Sydney.

### It is not a CDN or an edge firewall

The firewall runs inside your site, on your server, and refuses the request after it arrives.

### It does not fix things for you

It tells you a file changed, what changed in it and when. Restoring it is your call, or hand it to our team.

## Pick your worst site. Run the free check on it.

If what comes back is not worth a conversation, nothing here will be worth your time either, and you will have lost fifteen seconds. Send us the list and we will come to the call having already looked at them, so it starts with findings rather than a pitch.

[Run a one time audit instead](https://growthzi.com/website-security-audit)

[Both modules, side by side](https://growthzi.com/website-security)

## Questions about monitoring

The demo, the agent, the plans, and what it deliberately does not do.

## Build it here and the watching is free

Every site published on Growthzi gets uptime, certificate, DNS, header and blocklist monitoring from the minute it goes live.

Get Started No credit card Live in 60s
