Fundraising Fox

Patchstack

Not explicitly stated · Founded 2021 · 51 employees on LinkedIn · 5 known investors

Patchstack is a security platform that helps make open-source software safer. The company serves developers and organizations using open-source projects.

Also known as Patchstack OÜ

Founders & leadership

Patchstack was founded in 2021 by Oliver Sild.

OSOliver Sild
Oliver Sildin𝕏Founder & CEO
ELEdouard L
Edouard LSecurity engineer
Kürşat Çetin
Kürşat ÇetinVulnerability researcher
IFIvan F
Ivan FEngineer

Investors · 5

Also in the syndicate · 1

Emilia Capitallead

Company profile

researched Aug 2026

Patchstack is a security company focused on vulnerability intelligence and mitigation for websites built on open-source software, primarily WordPress and its plugin and theme ecosystem, with recently announced coverage for Node.js applications used by web hosts. Its core product, RapidMitigate, runs inside the website itself rather than at the server layer and deploys targeted mitigation rules that block exploitation of known vulnerabilities without requiring code changes or immediate updates. The company states this approach prevents up to 74% more vulnerabilities from being exploited than leading web application firewalls, and that it maintains over 12,000 (elsewhere cited as 16,720 in its public database) unique mitigation rules. Capabilities include software composition analysis, contextual prioritization based on known exploited vulnerabilities, remote software management, custom protection rules, an IP blocklist module, WordPress-specific hardening, a threat intelligence API, reporting features and support for PCI-DSS 4.0 requirements.

Patchstack operates a public open-source vulnerability database that lists tens of thousands of vulnerabilities in WordPress plugins and themes as well as npm packages, along with triage status and mitigation availability. The company reports it disclosed more than 4,100 vulnerabilities in 2024, published 76% of all known WordPress-related security vulnerabilities in 2023 and became the largest CVE Naming Authority by volume that year. It runs a Zero-Day Bug Bounty Program, which awarded a $14,400 bounty for a critical LiteSpeed Cache plugin vulnerability, and a managed vulnerability disclosure program (VDP) platform developed with the European Union that is free to plugin and theme developers and is positioned to help projects comply with the European Cyber Resilience Act. Around 900-944 plugins installed on millions of sites list Patchstack as a security point of contact.

The team is fully remote and international, led by co-founder and CEO Oliver Sild, with Dave Jong as CTO, Siobhan McKeown as COO, Darius Sveikauskas leading bounty and data, and staff across security research, engineering, marketing, sales, customer success and finance.

Founding story

Co-founded by Oliver Sild, who serves as CEO, together with CTO Dave Jong, whose bio describes starting a software company via Reddit.

Business model

Patchstack sells subscription security software directly and through channel partners. A Developer plan is priced at $69 per month billed annually ($828/year) covering website licenses and three seats, with additional seats at $24 per seat per month and additional bundles of five sites at $12.50 per month. Enterprise and Web host plans use custom billing and add extended API endpoints, SLAs, data processing agreements and dedicated rollout support. Web hosting partners resell or bundle Patchstack as an add-on, which the company positions to them as a new security revenue stream.

Recurring subscription fees per website/seat for individual developers and agencies, custom enterprise contracts, and infrastructure-wide licensing for hosting providers; personal plans are distributed via partners and resellers.

Traction

Public database totals of 51,314 entries with 16,720 mitigation rules; 12,000+ mitigation rules cited on the site; 4,100+ vulnerabilities disclosed in 2024 (13% highly exploitable); exclusive vulnerability intelligence for 944 WordPress plugins and roughly 900 plugins naming Patchstack as security contact. Partner testimonials cite 631,500+ threats blocked in the first month across WP Umbrella sites, prevention of more than 56,000 vulnerabilities in one managed WordPress environment, and protection against 1.3 million vulnerabilities over six months for another partner's users. Product rating cited as 4.9 stars.

Latest developments

Announced expansion of its protection to Node.js applications for web hosts, added remote software management and extended API endpoints to its plans, and closed a $5M Series A in 2024 intended to accelerate product development and build sales and marketing functions.

Full profile — market position, technology, go-to-market, geography, history

Market position

Patchstack positions itself as the leading handler of open-source vulnerability intelligence, claiming the largest collection of mitigation rules on the market and the ability to mitigate vulnerabilities up to 48 hours ahead of public disclosure and of competitors that rely on its data. Press coverage describes it as a leading WordPress security company, and it was reported as the largest CVE Naming Authority by volume in 2023, publishing 76% of known WordPress-related vulnerabilities that year.

In-application mitigation rules rather than server-level WAF filtering, allowing context-aware blocking without code changes, tooling conflicts or false positives; the largest published set of mitigation rules; and first-hand vulnerability intelligence sourced from its own CVE Naming Authority operations, bug bounty program and managed VDP, enabling mitigation ahead of public disclosure.

Technology

RapidMitigate combines software composition analysis for deep application visibility, threat intelligence and context-aware prioritization based on known exploited vulnerabilities to deploy on-demand mitigation rules. Unlike a traditional web application firewall running at the web server, RapidMitigate executes within the website and can use application context such as user authorization and software versions, which the company says reduces resource usage and false positives. Additional components include an IP blocklist module, WordPress hardening, WP-CLI installation support, CI readiness checks, API integrations, real-time SCA snapshot reports and data retention of up to 24 months.

Go-to-market

Direct sales (contact sales and self-serve pricing with a first-month-free offer and 30-day money-back guarantee) combined with an extensive partner channel: roughly 20 official security partners that offer Patchstack protection as an add-on and around 14 vulnerability monitoring partners that use Patchstack threat intelligence to alert their customers. A free managed VDP platform for plugin and theme developers and a public vulnerability database serve as community and top-of-funnel channels.

Web developers, agencies and professionals maintaining WordPress sites; MSPs and businesses needing advanced security and compliance; and web hosting providers deploying protection across their infrastructure, including eCommerce/WooCommerce sites subject to PCI-DSS 4.0.

Geography

Operates as a full-remote, global team; partnerships with hosting providers and collaboration with the European Union and the European Innovation Council indicate a significant European presence.

History

In 2022 the company received a €2.7M R&D grant from the European Innovation Council. In 2023 it published 76% of all known WordPress-related security vulnerabilities and became the largest CVE Naming Authority by volume. In 2024 it was selected for Google's AI for Cybersecurity accelerator program, its bug bounty program paid a record $14,400 bounty for a LiteSpeed Cache vulnerability, and it raised a $5M Series A led by Karma Ventures, G+D Ventures and Emilia Capital. It has since extended protection to Node.js applications for web hosts.

Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Customer ratingJan 20264.9 stars
Database entries with no official patchJan 202613,330 vulnerabilities
Developer plan priceJan 2026$828
HeadcountAug 202651
Mitigation rules availableJan 202612,000 rules
Mitigation rules in public databaseJan 202616,720 rules
Official security partners listedJan 202620 partners
Plugins listing Patchstack as security point of contactJan 2026900 plugins
Share of WordPress-related vulnerabilities publishedJan 202376%
Vulnerabilities disclosed in 2024Jan 20244,100 vulnerabilities
Vulnerabilities in public databaseJan 202651,314 vulnerabilities
Vulnerability monitoring partners listedJan 202614 partners
WordPress plugins with exclusive vulnerability intelligenceJan 2026944 plugins

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Competitors · 3

by search overlap

Companies competing with Patchstack for the same Google search keywords, organic and paid, via search-intersection analysis.

Timeline · 7

launches, deals, and filings
Jan 2026
Patchstack extends protection to Node.js applications for web hosts

Patchstack announced it is now securing Node.js applications for web hosts.

source ↗

Sep 2024
Patchstack raises $5M Series A

Patchstack raised a $5 million Series A round led by Karma Ventures, G+D Ventures and Emilia Capital, an investment firm backed by Yoast founders Marieke van de Rakt and Joost de Valk. CEO Oliver Sild said the capital would accelerate product development and build a sales and marketing team.

$5M source ↗

Aug 2024
Record $14,400 WordPress bug bounty paid

Patchstack's Zero-Day Bug Bounty Program awarded the highest bounty in WordPress history, $14,400, to John Blackbourn for a critical vulnerability in the LiteSpeed Cache plugin.

$14.4K source ↗

Jan 2024
Selected for Google's AI for Cybersecurity accelerator

Patchstack was selected by Google for its AI for Cybersecurity accelerator program, leveraging its dataset of open-source security vulnerabilities.

source ↗

Jan 2024
Managed VDP platform developed with the European Union

Patchstack's managed vulnerability disclosure program platform, developed in collaboration with the European Union, is free for plugin and theme developers and helps projects comply with the upcoming European Cyber Resilience Act.

source ↗

Jan 2023
Became largest CVE Naming Authority by volume

Patchstack published 76% of all known WordPress-related security vulnerabilities in 2023 and became the largest CVE Naming Authority by volume that year.

source ↗

Jan 2022
€2.7M R&D grant from the European Innovation Council

Patchstack received a €2.7M research and development grant from the European Innovation Council.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

In the news

Research sources · 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Patchstack do?
Patchstack provides vulnerability intelligence and automated mitigation for WordPress and other open-source web software.
Who founded Patchstack?
Patchstack was founded by Oliver Sild in 2021.
Who are Patchstack's investors?
Patchstack's investors include Karma Ventures, Specialist VC, Thorgate Ventures, Trind Ventures.
Where is Patchstack headquartered?
Patchstack is headquartered in Not explicitly stated.