Most websites are assembled from open-source parts, and in 2021, 99.42% of reported WordPress vulnerabilities were in plugins and themes rather than the core, according to Patchstack. Patchstack, an Estonian company called WebARX until 2021, works with independent security researchers to find those flaws, then issues "virtual patches" that block attacks on a vulnerable plugin before its developer, or the site owner, has fixed it.
The European Innovation Council granted €1,904,000 towards a €2.72 million project to build that platform. By its end in November 2024 Patchstack reported more than 9,500 virtual patches and a leading role in naming WordPress vulnerabilities. Since then it has signed hosting companies including GoDaddy. It raised a $5 million Series A in 2024; its revenue is not public.
Company file
- Legal entity
- Patchstack OÜ (formerly WebARX), Pärnu, Estonia
- Founded
- 2013, by Oliver Sild, now CEO
- Leadership
- Oliver Sild (CEO), Dave Jong (CTO), Siobhan McKeown (COO)
- Team
- Fully remote, across more than a dozen countries
- Products
- Virtual patching, vulnerability database, disclosure programmes, CRA reporting
- Partners
- GoDaddy, Hostinger, ManageWP, Elementor, other hosts
- EIC project
- PROWEB, 1 Jun 2022 to 30 Nov 2024, closed
- EIC funding
- Grant first
Where Patchstack Stands Today
Patchstack's press page lists partnerships with GoDaddy for managed WordPress hosting in June 2026 and with Hostinger for Node.js vulnerability scanning in July 2026, and media coverage of WordPress flaws its researchers disclosed. Its news page adds ManageWP, Elementor's site management tool and several smaller hosts in 2026. In September 2026 it launched free reporting under Article 14 of the EU Cyber Resilience Act for open-source maintainers, saying more than 1,000 open-source products already use its disclosure platform, and extended its protection to apps built with AI tools such as Lovable, Replit and Claude Code.
The Technology: Patches Before the Patch
When a flaw in a popular plugin is found, sites stay exposed until the developer releases a fix and each owner installs it. Patchstack writes a rule for each specific vulnerability that blocks attempts to exploit it, and deploys it to protected sites. Its website claims more than 12,000 such rules and mitigation "up to 48 hours" before disclosure. The flaws researchers find also feed its vulnerability database, expanded when Patchstack bought ThreatPress and its WordPress vulnerability database, announced with the 2021 rebrand.
"The largest collection of vulnerability specific protection rules in the world."
Patchstack, final PROWEB report on CORDISWhat the EIC Project Promised, and What CORDIS Shows
PROWEB set out to combine independent researchers with automated virtual patching to give "effective protection against open-source code vulnerabilities". The CORDIS results report a software platform covering WordPress, WooCommerce, Drupal and Joomla, 4,566 new unique vulnerabilities processed in 2024, 9,566 virtual patches, recognition as an official CVE naming authority, the largest by volume in 2023 and 2024 by the company's account, more than 600 open-source developers running disclosure programmes on the platform, and selection for Google's cybersecurity and AI start-up programme in July 2024. It says GoDaddy, WP Engine and DigitalOcean had "expressed interest" in partnerships.
- A virtual patching platformDelivered9,566 patches; four CMS platforms.
- Early detection of flawsDeliveredCVE naming authority; 4,566 in 2024.
- Large distribution partnersDeliveredGoDaddy partnership in 2026.
- A profitable businessNot shownNo revenue or funding published.
What Has Happened Since the Award
The Money
The award was "grant first", and we found no EIC Fund investment. In September 2024 Patchstack raised a $5 million Series A led by Karma Ventures, with G+D Ventures and Emilia Capital, the investment firm of the Yoast founders, to build its product and a sales and marketing team. At the time it said its recurring revenue had grown two to three times a year since the EIC grant, that it scanned "over five million websites", and that it had published 76% of all known WordPress-related vulnerabilities in 2023. Estonian register data, which would show revenue and staff numbers, could not be accessed for this article.
What cannot be checked
Patchstack's revenue, how many websites its virtual patches protect, and how many of its figures an independent party has verified are not public. The results above come from the company's own reporting to the EU.
Why Europe Should Care
The EU's Cyber Resilience Act makes manufacturers of software products report actively exploited vulnerabilities, and open-source maintainers need somewhere to handle that. An EU-funded Estonian company offering that service for free, with a researcher network behind it, is a direct match between EU research money and EU regulation.
What the project promised
Researchers plus automated virtual patching to protect sites built on open-source code.
What the record shows
9,566 virtual patches, CVE naming authority status and hosting partners including GoDaddy and Hostinger.
The Verdict
A clear deliverable, a hidden balance sheet
PROWEB produced exactly what it proposed, and Patchstack has since built distribution through some of the largest web hosts. What remains hidden is whether that makes a sustainable business, since the company publishes neither revenue nor funding.
Patchstack has not been asked for comment for this article. It is based entirely on company statements and EU project data, linked throughout.
