cPFence command-line quick reference
Use the public cpfence command on the server you intend to manage. Operational changes normally require root and a valid license; read the task’s role and recovery instructions before running them.
Find the current command help
Section titled “Find the current command help”cpfence --helpBare cpfence shows the same help. To find a group, pipe it to a text filter:
cpfence --help | grep WAFYour installed version’s help lists the available flags and arguments.
Status, notifications, and maintenance
Section titled “Status, notifications, and maintenance”| Task | Command or guide |
|---|---|
| Command dashboard | cpfence --ui |
| License and protection status | cpfence --status |
| Protection statistics | cpfence --show-stats |
| Installed version | cpfence --version; version checks |
| Software and signature updates | cpfence --update, cpfence --update-signatures; updates and job status |
| Notification address | cpfence --set-email [email protected]; replace the example address |
| SMTP and Slack | Notification settings |
| Settings archives | cpfence --backup-cpf-settings; backup and restore modes |
| Apply the saved protection profile | cpfence --restart; configured On protections restart and configured Off protections shut down |
| Pause or remove protection | Pause selected features or uninstall |
Protection and scans
Section titled “Protection and scans”| Task | Commands and detailed instructions |
|---|---|
| Malware scans | cpfence --full-scan, cpfence --smart-scan, cpfence --custom-scan /absolute/path, cpfence --quick-scan /absolute/path; scans and results |
| Stop scan jobs | cpfence --stop-scan; check the current job’s result afterward |
| Website real-time protection | cpfence --enable-MRTP / cpfence --disable-MRTP; website and mail scanning |
| Website auto-quarantine | cpfence --enable-quarantine / cpfence --disable-quarantine; exclusions and quarantine |
| WAF | cpfence --enable-cpf-waf / cpfence --disable-cpf-waf; rules, domains, bots, and CAPTCHA |
| IPDB | cpfence --enable-ipdb / cpfence --disable-ipdb; IP, country, ASN, and temporary policies |
| Under attack mode | cpfence --under-attack-on / cpfence --under-attack-off; turn the emergency mode off after the attack |
| WordPress daily protection | cpfence --wp-autoshield-on / cpfence --wp-autoshield-off; AutoShield and integrity |
| Integrity checks | cpfence --enable-integrity-check; cpfence --set-check-frequency hourly or daily; review automatic file action separately |
| WordPress maintenance | Selected-site bulk tools and WordPress backups |
| Spam filtering | Spam AutoShield policies, lists, and training |
| Rootkit and server reputation | Scheduled checks and advisory results |
Quick scan bypasses configured malware exclusions and does not quarantine or record normal scan history. Restore files through the quarantine controls rather than moving an old quarantine path into a site blindly.
Common feature controls
Section titled “Common feature controls”Each entry is a separate command. Run the command for your intended choice and read its task guide before changing protection or a bulk selection.
| Task | Commands | Task guide |
|---|---|---|
| Notification SMTP | cpfence --enable-cpfence-smtp, cpfence --disable-cpfence-smtp |
Email and SMTP |
| Slack alerts | cpfence --set-slack-webhook, cpfence --slack-notifications-on, cpfence --slack-notifications-off |
Notification settings |
| IP reputation | cpfence --ip-reputation-on, cpfence --ip-reputation-off |
Scheduled reputation checks |
| DDoS module | cpfence --enable-DDos, cpfence --disable-DDos, cpfence --restart-ipdb |
IPDB DDoS protection |
| Proactive scanning | cpfence --enable-proactive, cpfence --disable-proactive |
Proactive scans |
| Email quarantine | cpfence --enable-email-quarantine, cpfence --disable-email-quarantine |
Email quarantine |
| Mail spam protection | cpfence --enable-spam-protection, cpfence --disable-spam-protection |
Email spam protection |
| Rootkit schedule | cpfence --rootkit-on, cpfence --rootkit-off |
Advisory rootkit checks |
| Exact malware path | cpfence --exclude-exact-path PATH, cpfence --del-exclude-exact-path PATH |
Path and signature policy |
| Malware expression or signature | cpfence --exclude-path REGEX, cpfence --del-exclude-path REGEX, cpfence --exclude-sig ID, cpfence --del-exclude-sig ID |
Exclusion scopes |
| WordPress vulnerability reports | cpfence --vuln-scan, cpfence --vuln-export |
Vulnerability Manager |
WAF and IP policies
Section titled “WAF and IP policies”Replace uppercase placeholders with your intended values. Domain rules and server-wide rules have different effects; start with the narrower rule needed.
| Task | Commands | Task guide |
|---|---|---|
| WAF rule IDs | cpfence --disable-waf-rule RULE_ID, cpfence --enable-waf-rule RULE_ID, cpfence --disable-waf-domain-byid, cpfence --enable-waf-domain-byid |
Rule exceptions |
| Domain WAF | cpfence --disable-waf-domain DOMAIN, cpfence --enable-waf-domain DOMAIN, cpfence --debug-domain-waf |
Domain protection and investigation |
| Layer 7 domain/global | cpfence --enable-layer7-waf-domain DOMAIN, cpfence --disable-layer7-waf-domain DOMAIN, cpfence --enable-layer7-waf-global, cpfence --disable-layer7-waf-global |
Domain / global |
| Bot domain/global | cpfence --enable-bot-protection-domain DOMAIN, cpfence --disable-bot-protection-domain DOMAIN, cpfence --enable-bot-protection-global, cpfence --disable-bot-protection-global |
Domain / global |
| CAPTCHA domain/global | cpfence --enable-captcha-waf-domain DOMAIN, cpfence --disable-captcha-waf-domain DOMAIN, cpfence --enable-captcha-waf-global, cpfence --disable-captcha-waf-global |
CAPTCHA controls |
| Inspect IP policy | cpfence --check-ip IP, cpfence --bulk-check-ip URL_OR_FILE |
Check IP status |
| Allow an IP | cpfence --add-whitelist-ip IP, cpfence --del-whitelist-ip IP, cpfence --temp-whitelist-ip IP TTL |
IPDB policy |
| Block an IP | cpfence --add-blacklist-ip IP, cpfence --del-blacklist-ip IP, cpfence --temp-blacklist-ip IP TTL |
IPDB policy |
| Bulk IP lists | cpfence --bulk-whitelist-ip URL_OR_FILE, cpfence --bulk-blacklist-ip URL_OR_FILE, cpfence --bulk-del-wl-ip URL_OR_FILE, cpfence --bulk-del-bl-ip URL_OR_FILE |
List input and troubleshooting |
| ASN ranges | cpfence --blacklist-asn, cpfence --remove-asn |
ASN blocking |
| Dynamic DNS addresses | cpfence --add-whitelist-ddns HOSTNAME, cpfence --del-whitelist-ddns HOSTNAME |
DDNS scope and WebUI access |
| Country policy | cpfence --whitelist-country CODE, cpfence --del-whitelist-country CODE, cpfence --blacklist-country CODE, cpfence --del-blacklist-country CODE |
Country access |
For custom WAF rules, follow managed WAF rules and supported exceptions. Avoid copying a broad rule-engine bypass into a narrow exception.
WordPress command groups
Section titled “WordPress command groups”Run the intended command only. Uppercase values are placeholders. WordPress CLI
bulk actions use the hosting server’s reviewed sites list; they do not inherit
checked WebUI rows. Interactive user commands take no positional fields and ask
for them. Commands ending in -auto, and update-policy commands with an explicit
component, can apply without confirmation. Keep backups before mutations.
PLUGIN_SOURCE/THEME_SOURCE means the intended repository slug, supported local
ZIP path or HTTPS ZIP URL; use a slug for activation, removal or update policy.
Keep user passwords out of shared command history and logs. Read the focused
task for target scope, consequences and recovery.
Protection and exclusions
Section titled “Protection and exclusions”| Command | Purpose |
|---|---|
cpfence --del-exclude-integrity-file FILE_BASENAME |
Remove a file from the integrity exclusion list. |
cpfence --del-exclude-integrity-site SITE_PATH |
Remove a website from the integrity exclusion list. |
cpfence --del-exclude-wp-site SITE_PATH |
Remove a site from the WP-AutoShield exclusion list. |
cpfence --disable-auto-file-action |
Turn off automatic file quarantine for the integrity check. |
cpfence --disable-integrity-check |
Disable WordPress Integrity Check. |
cpfence --enable-all |
Start applicable protections configured On; preserve the saved profile. |
cpfence --exclude-integrity-file FILE_BASENAME |
Exclude a specific file from integrity checks. |
cpfence --exclude-integrity-site SITE_PATH |
Exclude a website (full site path) from integrity checks. |
cpfence --exclude-wp-site SITE_PATH |
Exclude a WordPress site from the WP-AutoShield daily cron tasks. |
Updates, plugins and themes
Section titled “Updates, plugins and themes”| Command | Purpose |
|---|---|
cpfence --bulk-activate-wp-theme THEME_SLUG |
Bulk Activate any WordPress theme server-wide using the theme slug. |
cpfence --bulk-activate-wp-theme-auto THEME_SLUG |
Bulk Activate a WordPress theme server-wide by providing its slug (non-interactive; good for automation). |
cpfence --bulk-auto-update-all-sites plugins |
Bulk update all WordPress sites without confirmation. Allowed values: all, core, plugins, themes or translations |
cpfence --bulk-delete-wp-theme THEME_SLUG |
Bulk Delete any WordPress theme server-wide using the theme slug. |
cpfence --bulk-delete-wp-theme-auto THEME_SLUG |
Bulk Delete a WordPress theme server-wide by providing its slug (non-interactive; good for automation). |
cpfence --bulk-disable-wp-plugin PLUGIN_SLUG |
Disable any WordPress plugin server-wide using the plugin slug. |
cpfence --bulk-disable-wp-plugin-auto PLUGIN_SLUG |
Disable a WordPress plugin server-wide by providing its slug (non-interactive; good for automation). |
cpfence --bulk-enable-wp-plugin PLUGIN_SLUG |
Enable any WordPress plugin server-wide using the plugin slug. |
cpfence --bulk-enable-wp-plugin-auto PLUGIN_SLUG |
Enable a WordPress plugin server-wide by providing its slug (non-interactive; good for automation). |
cpfence --bulk-install-plugin-auto PLUGIN_SOURCE |
Install or overwrite a WordPress plugin by slug, path, or URL without confirmation (server-wide; good for automation). |
cpfence --bulk-install-wp-plugin PLUGIN_SOURCE |
Search and install or overwrite any WordPress plugin using name, path, or ZIP URL server-wide. |
cpfence --bulk-install-wp-theme THEME_SOURCE |
Search and install or overwrite any WordPress theme using name, path, or ZIP URL server-wide. |
cpfence --bulk-install-wp-theme-auto THEME_SOURCE |
Install or overwrite a WordPress theme by slug, path, or URL without confirmation (server-wide; good for automation). |
cpfence --bulk-uninstall-plugin-auto PLUGIN_SLUG |
Uninstall a WordPress plugin server-wide by providing its slug (non-interactive; good for automation). |
cpfence --bulk-uninstall-wp-plugin PLUGIN_SLUG |
Deactivate and Uninstall any WordPress plugin server-wide using the plugin slug. |
cpfence --bulk-update-wordpress |
Perform a bulk update of WordPress core, plugins, themes, and translations on all listed sites. |
cpfence --bulk-update-wp-plugin PLUGIN_SOURCE |
Update an installed WordPress plugin using its name, slug, ZIP path, or URL server-wide. |
cpfence --bulk-update-wp-plugin-auto PLUGIN_SOURCE |
Update an installed WordPress plugin by slug, ZIP path, or URL without confirmation (server-wide; good for automation). |
cpfence --bulk-update-wp-theme THEME_SOURCE |
Update an installed WordPress theme using its name, slug, ZIP path, or URL server-wide. |
cpfence --bulk-update-wp-theme-auto THEME_SOURCE |
Update an installed WordPress theme by slug, ZIP path, or URL without confirmation (server-wide; good for automation). |
cpfence --disable-auto-updates-plugin PLUGIN_SLUG |
Disable automatic updates for a specific WordPress plugin across all listed WordPress sites. |
cpfence --disable-auto-updates-theme THEME_SLUG |
Disable automatic updates for a specific WordPress theme across all listed WordPress sites. |
cpfence --disable-wp-auto-updates plugins |
Disable auto-updates for selected WordPress components. Allowed values: all, core, plugins, themes or translations |
cpfence --enable-auto-updates-plugin PLUGIN_SLUG |
Enable automatic updates for a specific WordPress plugin across all listed WordPress sites. |
cpfence --enable-auto-updates-theme THEME_SLUG |
Enable automatic updates for a specific WordPress theme across all listed WordPress sites. |
cpfence --enable-wp-auto-updates plugins |
Enable auto-updates for selected WordPress components. Allowed values: all, core, plugins, themes or translations |
WordPress users
Section titled “WordPress users”| Command | Purpose |
|---|---|
cpfence --bulk-create-wp-user |
Create a WordPress user server-wide. You will be prompted for username, email, password, and role. |
cpfence --bulk-create-wp-user-auto "USERNAME,EMAIL,PASSWORD,ROLE" |
Create a user by ‘username,email,password,role’ (non-interactive; good for automation). |
cpfence --bulk-delete-wp-user |
Delete a user and all of their content server-wide (no reassign). |
cpfence --bulk-delete-wp-user-auto USER_IDENTIFIER |
Delete user (no reassign): IDENTIFIER (non-interactive; good for automation). |
cpfence --bulk-delete-wp-user-reassign |
Delete a user and reassign content to the first administrator server-wide. |
cpfence --bulk-delete-wp-user-reassign-auto USER_IDENTIFIER |
Delete user (reassign): IDENTIFIER (non-interactive; good for automation). |
cpfence --bulk-list-wp-users |
List WordPress users (all or by role) server-wide and save results as CSV. |
cpfence --bulk-list-wp-users-auto administrator |
List users by role: ROLE/all (non-interactive; good for automation). |
cpfence --bulk-wp-reset-all-passwords |
Reset passwords for all users or users of a specific role server-wide (shows new passwords). |
cpfence --bulk-wp-reset-all-passwords-auto administrator |
Reset passwords by role: ROLE/all (non-interactive; good for automation). |
cpfence --bulk-wp-reset-user-password |
Reset password for a specific user (login, email, or ID) server-wide (shows new passwords). |
cpfence --bulk-wp-reset-user-password-auto USER_IDENTIFIER |
Reset one user: IDENTIFIER[,PASSWORD] (non-interactive; good for automation). |
Maintenance, cache and backups
Section titled “Maintenance, cache and backups”| Command | Purpose |
|---|---|
cpfence --bulk-backup-wp-sites |
Bulk create backups of all your WordPress sites (files and databases) and store them in /cpf_wp_backups/. |
cpfence --bulk-clear-litespeed-cache |
Clear the LiteSpeed cache on listed WordPress sites. |
cpfence --bulk-configure-ls-plugin |
Configure the LiteSpeed plugin with advanced presets and Redis enabled server-wide. |
cpfence --bulk-disable-ls-cache-login-page |
Disable login page caching in LiteSpeed Cache server-wide (needed for cPFence WAF Captcha). |
cpfence --bulk-disable-maintenance-mode |
Disable maintenance mode for listed WordPress sites. |
cpfence --bulk-disable-search-engine-index |
Disable search engine indexing for listed WordPress sites. |
cpfence --bulk-disable-sec-headers |
Disable recommended security headers for listed WordPress sites. |
cpfence --bulk-disable-wp-captcha |
Disable text math CAPTCHA on login, registration, and lost password forms for all listed WordPress sites. |
cpfence --bulk-disable-wp-cron |
Disable Default WordPress Cron for all listed sites to improve performance. |
cpfence --bulk-disable-wp-file-edit |
Disable file editing in WordPress Admin panel for all listed sites. |
cpfence --bulk-disable-wp-hardening |
Disable WordPress hardening for all listed sites. |
cpfence --bulk-disable-wp-idle-logout |
Disable automatic logout protection after 60 minutes for idle users on all listed sites. |
cpfence --bulk-disable-wp-limit-login |
Disable wp-login protection by removing Limit Login Attempts for all listed sites. |
cpfence --bulk-disable-wp-pingback |
Disable default pingbacks in WordPress for all listed sites. |
cpfence --bulk-disable-wp-xmlrpc |
Fully Disable XML-RPC for all listed WordPress sites with a 403 denied error. |
cpfence --bulk-disable-xss-in-wp-posts |
Disable XSS & risky code such as iframes, embeds, or scripts in WordPress posts for all listed sites. |
cpfence --bulk-enable-ls-cache-login-page |
Re-enable login page caching in LiteSpeed Cache server-wide (when not using cPFence WAF Captcha). |
cpfence --bulk-enable-ls-heartbeat |
Bulk enable and configure heartbeat options in the LiteSpeed Cache plugin (disabled on frontend and minimal on backend). |
cpfence --bulk-enable-ls-redis |
Enable Redis caching within the LiteSpeed plugin server-wide. |
cpfence --bulk-enable-maintenance-mode |
Enable maintenance mode for listed WordPress sites. |
cpfence --bulk-enable-search-engine-index |
Enable search engine indexing for listed WordPress sites. |
cpfence --bulk-enable-sec-headers |
Enable recommended security headers for listed WordPress sites. |
cpfence --bulk-enable-wp-captcha |
Enable text math CAPTCHA on login, registration, and lost password forms for all listed WordPress sites. |
cpfence --bulk-enable-wp-cron |
Enable Default WordPress Cron for all listed sites. |
cpfence --bulk-enable-wp-file-edit |
Enable file editing in WordPress Admin panel for all listed sites. |
cpfence --bulk-enable-wp-hardening |
Enable WordPress hardening by securing wp-includes, uploads dirs, and wp-config file. |
cpfence --bulk-enable-wp-idle-logout |
Enable automatic logout protection after 60 minutes for idle users on all listed sites. |
cpfence --bulk-enable-wp-limit-login |
Enable wp-login protection by implementing Limit Login Attempts for all listed sites. |
cpfence --bulk-enable-wp-pingback |
Enable default pingbacks in WordPress for all listed sites. |
cpfence --bulk-enable-wp-xmlrpc |
Enable XML-RPC for all listed WordPress sites. |
cpfence --bulk-enable-xss-in-wp-posts |
Enable XSS & risky code such as iframes, embeds, or scripts in WordPress posts for all listed sites. |
cpfence --bulk-force-wp-core-files |
Force restore WordPress core files to default server-wide (For experienced system admins only). |
cpfence --bulk-install-custom-mu-plugin |
Bulk install your custom MU plugin. Add your one file MU plugin to /var/log/cpfenceav/mu-plugin before running. |
cpfence --bulk-install-ls-plugin |
Install the LiteSpeed plugin on listed WordPress sites. |
cpfence --bulk-install-plugin-bundle |
Bulk install the plugin bundle listed in /var/log/cpfenceav/wp-plugin-bundle.txt |
cpfence --bulk-optimize-wp-databases |
Optimize all WordPress databases to improve performance and reduce overhead. |
cpfence --bulk-rename-wp-admin |
Rename the default ‘admin’ username to a unique, secure name across all listed WordPress sites. |
cpfence --bulk-reset-ls-plugin |
Reset all options in the LiteSpeed Cache plugin to factory defaults server-wide. |
cpfence --bulk-restore-wp-sites BACKUP_DATE |
Restore one or all WordPress sites from a backup. Ex: cpfence –bulk-restore-wp-sites YYYY-MM-DD or YYYY-MM-DD_HH-MM-SS |
cpfence --bulk-run-due-wp-cron |
Run all WordPress cron events due right now server-wide. |
cpfence --bulk-scan-wp-databases |
Scan all WordPress databases for malware, injections, and other threats. |
cpfence --bulk-set-wp-permissions |
Fix and Apply secure permissions to critical files and directories. |
cpfence --bulk-set-wp-secure-keys |
Initialize missing secure keys; do not assume existing nonempty keys are rotated. |
cpfence --bulk-switch-wp-language en_US |
Change the WordPress language for all or selected sites. |
cpfence --bulk-uninstall-bl-plugins |
Bulk uninstall blacklisted plugins listed in /var/log/cpfenceav/blacklisted-wp-plugins.txt |
cpfence --bulk-uninstall-cache-plugins |
Bulk uninstall all major and widely used cache and Redis plugins from all WordPress sites, except LiteSpeed. |
cpfence --bulk-uninstall-custom-mu-plugin |
Bulk uninstall your custom MU plugin stored in /var/log/cpfenceav/mu-plugin. |
cpfence --cpf-backup-cron-off |
Disable the cPFence Backup module and stop scheduled backups. |
cpfence --cpf-backup-cron-on |
Enable the cPFence Backup module and activate scheduled backups. |
cpfence --cpf-remote-backup-off |
Disable remote backups and use local storage instead. |
cpfence --cpf-remote-backup-on |
Enable remote backups. You will be prompted to enter the remote server (Ex: root@IP). |
cpfence --generate-wp-sites-list |
Generate a list of WordPress sites and their owners on the server. |
For an explicit integrity check, cpfence --wp-integrity-scan SITE_PATH checks
the named installation; automatic file action still depends on its policy.
Integrity filename exceptions apply by basename across sites. Use full paths
for site exceptions. Keep daily AutoShield policy consistent with manual changes.
Remote WordPress backups and MultiRun require passwordless SSH. Ordinary v4+ WebUI/cluster features and local WordPress backups do not. For cron-ready options, use scheduled WordPress tools.
Use the reviewed WordPress site list before manual bulk commands. Its daily regeneration can replace edits. The focused guides explain current WebUI selection, outcomes, and recovery. Use your installed cpfence --help for CLI arguments:
- AutoShield exceptions, integrity and automatic file action, cron, and editor/risky HTML compatibility.
- Core and component updates, one plugin, one theme, and plugin/theme automatic-update policies.
- Install a plugin, uninstall a plugin, enable or disable a plugin, and install, activate, or delete a theme.
- Plugin bundles, blacklisted plugins, custom MU plugins, and cPFence MU removal.
- LiteSpeed Cache setup, Redis, heartbeat, login-page caching, cache purge, reset, and cache-plugin removal.
- Create users, list users, reset passwords, delete users, language, maintenance/indexing, database scanning, database exceptions, and database optimization.
- Local and remote WordPress backups and restore.
Owl, MonitorPro, Spam AutoShield, and LogSpot
Section titled “Owl, MonitorPro, Spam AutoShield, and LogSpot”| Task | Commands | Task guide |
|---|---|---|
| Owl lifecycle and history | cpfence --enable-owl, cpfence --disable-owl, cpfence --restart-owl, cpfence --enable-owl-history, cpfence --disable-owl-history, cpfence --owl-stats 30m |
Owl and LogSpot |
| Query control | cpfence --owl-automysql-on, cpfence --owl-automysql-off, cpfence --monitor-killed-queries |
AutoMySQL effects and history |
| Website and TLS checks | cpfence --monitorpro-on, cpfence --monitorpro-off, cpfence --monitorpro-scan-status, cpfence --export-cluster-domains, cpfence --enable-ssl-monitor DAYS, cpfence --disable-ssl-monitor |
MonitorPro sites, CSV, and alerts |
| Spam AutoShield lifecycle | cpfence --activate-spam-autoshield, cpfence --deactivate-spam-autoshield, cpfence --configure-spam-autoshield, cpfence --rspamd-training-tool, cpfence --reset-rspamd-training-data |
Spam AutoShield and training |
| Sender and outbound policies | Add/remove IP, email, domain, subject, TLD, ASN, trusted-sender, or outbound-user entries | Mail policy controls |
| LogSpot lifecycle | cpfence --enable-logspot, cpfence --disable-logspot, cpfence --restart-logspot |
LogSpot access |
| LogSpot access and data | cpfence --enable-logspot-autologin, cpfence --disable-logspot-autologin, cpfence --set-logspot-logsize MB, cpfence --logspot-logs-viewer, cpfence --remove-logspot-data |
Per-site passwords, report paths, WHMCS, and data removal |
LogSpot data removal is server-wide and permanent. Keep access passwords private. MonitorPro’s external-domain and required/unwanted-content rules belong in its five-field CSV; see its guide before editing.
Spam AutoShield policy commands
Section titled “Spam AutoShield policy commands”Run these as root on the intended mail server. Replace uppercase placeholders with the reviewed address, domain, ASN or quoted subject. Add/remove are separate choices; removing a block does not create a trust exception. A trust exception belongs to mail policy, not a firewall whitelist.
| Type | Add | Remove |
|---|---|---|
| Sender IP | cpfence --add-spam-autoshield-ip IP_ADDRESS |
cpfence --del-spam-autoshield-ip IP_ADDRESS |
| Incoming sender | cpfence --add-spam-autoshield-email EMAIL_ADDRESS |
cpfence --del-spam-autoshield-email EMAIL_ADDRESS |
| Outgoing user | cpfence --add-spam-autoshield-out-email EMAIL_ADDRESS |
cpfence --del-spam-autoshield-out-email EMAIL_ADDRESS |
| Sender domain | cpfence --add-spam-autoshield-domain DOMAIN |
cpfence --del-spam-autoshield-domain DOMAIN |
| Sender ASN | cpfence --add-spam-autoshield-asn ASN |
cpfence --del-spam-autoshield-asn ASN |
| Subject | cpfence --add-spam-autoshield-subject "SUBJECT" |
cpfence --del-spam-autoshield-subject "SUBJECT" |
| TLD | cpfence --add-spam-autoshield-tld TLD |
cpfence --del-spam-autoshield-tld TLD |
| Trusted email | cpfence --add-spam-autoshield-wl-email EMAIL_ADDRESS |
cpfence --del-spam-autoshield-wl-email EMAIL_ADDRESS |
| Trusted domain | cpfence --add-spam-autoshield-wl-domain DOMAIN |
cpfence --del-spam-autoshield-wl-domain DOMAIN |
| Trusted ASN | cpfence --add-spam-autoshield-wl-asn ASN |
cpfence --del-spam-autoshield-wl-asn ASN |
Quote subjects and choose values carefully; broad domain/ASN/TLD policies can affect legitimate mail. See the focused mail tasks before changing them.
Cluster tools, monitoring, and access
Section titled “Cluster tools, monitoring, and access”| Task | Commands and guides |
|---|---|
| Open the central WebUI | cpfence --enable-webui; main control panel server setup |
| Lost administrator access | cpfence --reset-webui-pass; password, MFA, and country recovery |
| ApiMachine API key | cpfence --set-enhance-api-key; token setup |
| ApiMachine site list | cpfence --generate-cluster-sites-list; review the editable CLI selection |
| Website API actions | Caching, SSL, DNS, PHP, and Enhance backups |
| Per-website license IPs | cpfence --sync-ips on the main control panel server; license IP synchronization |
| Owl and query control | cpfence --owl-automysql-on; Owl monitoring and LogSpot |
| Website availability/content | cpfence --monitorpro-on; MonitorPro domains and checks |
| Live protection logs | cpfence --monitor-ipdb-blocks, cpfence --monitor-waf-logs, cpfence --monitor-owl-logs; run the intended stream and use Ctrl-C to close it |
| Server utilities | Permissions, homelinks, inventory, and temporary support access |
Before a bulk command, review its site/server list. Regenerating a CLI selection can replace your exclusions. Read every target’s output and actual resulting state; a background dispatch is not completed work.
For editable paths and validation, use Configuration files. Do not use old /opt/cpfence scripts or configuration paths for v4+ tasks.
ApiMachine CLI groups
Section titled “ApiMachine CLI groups”Run these from root on the Enhance main control panel server with a valid license and saved API key. Review the CLI selection file before website actions. Run one command for the intended choice; read its prompts and results.
| Group | Commands |
|---|---|
| New websites/WordPress | cpfence --bulk-create-websites, cpfence --bulk-create-websites --wp, cpfence --bulk-create-wordpress-cluster |
| Redis/OPcache | cpfence --bulk-enable-redis-cluster, cpfence --bulk-disable-redis-cluster, cpfence --bulk-enable-opcache-cluster, cpfence --bulk-disable-opcache-cluster |
| PHP | cpfence --bulk-update-php-version php83, cpfence --bulk-restart-php-container, cpfence --bulk-enable-php-extensions LIST, cpfence --bulk-disable-php-extensions LIST |
| Cloudflare | cpfence --bulk-set-cloudflare-key-org, cpfence --bulk-remove-cloudflare-key-org, cpfence --bulk-set-cloudflare-key-dom, cpfence --bulk-remove-cloudflare-key-dom |
| Certificates/HTTPS | cpfence --bulk-generate-ssl-cluster, cpfence --bulk-generate-mail-ssl-cluster, cpfence --bulk-enable-force-ssl-cluster, cpfence --bulk-disable-force-ssl-cluster |
| DNS/mail signing | cpfence --bulk-enable-dnssec-cluster, cpfence --bulk-disable-dnssec-cluster, cpfence --bulk-enable-dkim-cluster, cpfence --bulk-disable-dkim-cluster |
| Nginx | cpfence --bulk-enable-nginx-cache, cpfence --bulk-disable-nginx-cache, cpfence --bulk-clear-nginx-cache, cpfence --bulk-add-nginx-cache-exclude PATH, cpfence --bulk-remove-nginx-cache-exclude PATH |
| Enhance backups | cpfence --bulk-create-website-backups, cpfence --bulk-report-website-backups, cpfence --bulk-delete-website-backups |
New website creation uses its separate reviewed /var/log/cpfenceav/bulk-create-websites.txt input. Keep provisioning credentials and Cloudflare tokens private; organization-level changes can affect other domains. Certificate requests require eligible DNS/hostnames, DNSSEC removal requires upstream DS removal first, and backup deletion is permanent. Follow the focused ApiMachine tasks for the complete action steps and background-job outcomes.
Server administration commands
Section titled “Server administration commands”| Task | Commands | Scope or effect |
|---|---|---|
| Browser service/access | cpfence --disable-webui, cpfence --restart-webui, cpfence --add-webui-ip IP, cpfence --del-webui-ip IP |
Main control panel server; browser access |
| SSH helper | cpfence --deploy-ssh-key |
Main control panel server; SSH access |
| Interactive cluster sessions | cpfence --multirun, cpfence --multirun manual |
MultiRun steps; review server selection and interactive prompts |
| Website IDs and resources | cpfence --list-website-uuids, cpfence --website-resource-monitor, cpfence --server-status |
Inspect the chosen server; UUID output is /var/log/cpfenceav/website-uuid-list.txt |
| Homelinks | cpfence --create-user-homelinks, cpfence --remove-user-homelinks |
Owned-link behavior |
| Permissions | cpfence --fix-permissions-dry, cpfence --fix-permissions |
Preview first; Apply changes ownership across the server |
| Temporary SSH support | cpfence --add-support-key, cpfence --del-support-key |
Access expires after six hours; remove it earlier when finished |
| Server-wide SMTP | cpfence --enable-global-smtp, cpfence --disable-global-smtp |
SMTP scope and consequences |
| Site logs | cpfence --monitor-site-logs |
Choose the intended website UUID; Ctrl-C closes the stream |
| Disk throughput | cpfence --disk-speed-check |
Uses temporary test data and I/O; run only with spare disk capacity and a suitable maintenance window |
For delays, follow slow command diagnosis. For a PostgreSQL directory warning, follow working-directory guidance.
