Patchstack
Estonia-based application security vendor that runs a WordPress vulnerability database, coordinated disclosure program, and virtual patching to close the gap between disclosure and official fixes.
Visit Website ↗ + Add to CompareOverview
Patchstack focuses on a narrow but consequential slice of application security: vulnerabilities in WordPress core, plugins, and themes, which together power a large share of the public web. Its platform combines a vulnerability intelligence database, a managed bug-bounty and coordinated-disclosure program for WordPress plugin developers, and virtual patching that blocks exploitation of known vulnerabilities at the site level before an official plugin update is even released — closing the gap between vulnerability disclosure and a site owner actually applying a fix.
The company was founded by Estonian entrepreneur Oliver Sild and Dutch developer Dave Jong, who met through PHP security research communities before launching what was originally branded WebARX and later rebranded to Patchstack. Headquartered in Parnu, Estonia, the company raised a $5 million Series A led by Karma Ventures, G+D Ventures, and Emilia Capital — whose backers include Yoast SEO co-founders Joost de Valk and Marieke van de Rakt — and separately received a €2.7 million R&D grant from the European Innovation Council.
Patchstack’s most concrete evidence of scale is structural rather than promotional: it became a CVE Numbering Authority and, by its own 2023 accounting, was responsible for publishing 76% of all known WordPress-related CVEs that year, meaning a large share of the vulnerability data the entire WordPress ecosystem relies on for patching decisions flows through Patchstack’s own disclosure pipeline.
Innovation Matrix Assessment
Became a CVE Numbering Authority and scaled its vulnerability-disclosure pipeline to account for the large majority of published WordPress CVEs within a few years of its Series A, and was selected for Google's AI for Cybersecurity accelerator, indicating active platform development.
Combines vulnerability intelligence, a coordinated bug-bounty/disclosure program for plugin developers, and virtual patching in one pipeline, giving it end-to-end coverage of the WordPress vulnerability lifecycle rather than just a database or just a firewall.
Raised a $5M Series A backed by notable WordPress-ecosystem angels (Yoast co-founders) plus a separate €2.7M EU Innovation Council grant, solid but not large-scale funding for a company operating a wide-reach vulnerability database.
Virtual patching that blocks exploitation of a known WordPress vulnerability before the affected plugin developer ships an official fix meaningfully shortens a real, well-documented exposure window that affects a huge share of the public web.
Becoming the CVE Numbering Authority responsible for a reported 76% of published WordPress vulnerabilities in 2023 is a structurally verifiable claim (CNA status is publicly listed by MITRE), giving unusually strong independent evidence of the scale of its vulnerability-intelligence pipeline compared to marketing-only claims.
WordPress powers a large share of the internet's websites, and plugin/theme vulnerabilities remain one of the most common initial-access vectors for web compromise, keeping WordPress-specific vulnerability management a persistently relevant niche.
Why CISOs Should Care
For organizations running WordPress at any scale, Patchstack closes the practical gap between a vulnerability being disclosed and a fix actually being deployed, via virtual patching rather than relying on every plugin author and site owner to update in time.
What Makes It Different
Its CVE Numbering Authority status and outsized share of WordPress vulnerability disclosures give it a data-pipeline advantage most application-security vendors serving this niche don't have — it isn't just consuming public vulnerability feeds, it's a primary source for them.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
A focused, structurally credible vulnerability-management vendor for the WordPress ecosystem, with CNA status providing genuine independent evidence of scale rather than relying solely on vendor-reported numbers.
Editorial Note: Claims vs. Verified Findings
CVE Numbering Authority status and the specific 76%-of-WordPress-CVEs figure for 2023 are checkable against MITRE's public CNA list and were reported by multiple independent outlets, giving this claim more independent grounding than typical vendor statistics. Funding amounts and founder history are corroborated by multiple press sources. The company's own G2/customer-satisfaction claims were not independently verified.
Sources
Alternatives to Patchstack
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…