Skip to content

Exclude sites from WordPress AutoShield

Use an exclusion when a site needs different WordPress settings. AutoShield skips matching sites during scheduled protection and Run WP-AutoShield.

  1. Open Edit Configuration Files on the server hosting the site.
  2. Choose WP-AutoShield exclusions.
  3. Add the site’s actual installation path, one entry per line. For example, /var/www/WEBSITE_ID/public_html/blog excludes that installation. An account root such as /var/www/WEBSITE_ID/ also matches WordPress installations beneath it.
  4. Save the change and check the result.
  5. In WordPress Management, select only the intended sites and use the appropriate action to reverse a previously applied setting.

Keep entries narrow: an account path affects more sites than an installation path. Preserve the rest of the exclusion list.

Alternatively, open Threat & Malware Detection → Advanced Tools, set its server targets, then choose WP-AutoShield Exclusions → Exclude / Unexclude Site. Enter the installation’s Full site path, use Exclude Site, and check the result. Use Unexclude Site with the same path to remove that exception. These buttons change AutoShield policy; they do not undo earlier site changes.

WP-AutoShield Site Exclusions form with Full site path, Exclude Site and Unexclude Site

Use the complete intended installation path and check the Advanced Tools targets. This is an AutoShield exception, not a malware or integrity exclusion. Select the image to view it full size; use your browser’s Back command to return.

Exclude MemberPress, similar membership installations and WordPress Multisite from AutoShield to avoid conflicts with their authentication and site rules. Review any hardening already applied and reverse it only on those sites.

For server-wide child settings, use WordPress security and integrity. For one-off operations, use the action catalogue.

You can also add or remove an exclusion from a root terminal on the server hosting the site:

Terminal window
cpfence --exclude-wp-site /var/www/WEBSITE_ID/public_html/blog

Replace the example with the actual installation path. To exclude an entire account, use its account root, such as /var/www/WEBSITE_ID/. Check the reported list afterward. Remove the same entry when you want AutoShield to apply again:

Terminal window
cpfence --del-exclude-wp-site /var/www/WEBSITE_ID/public_html/blog

Use these commands or the WebUI editor to update the managed exclusion policy, rather than changing its exported file by hand.

Undo earlier settings on the excluded site

Section titled “Undo earlier settings on the excluded site”

Excluding still leaves earlier changes in place. The WebUI’s selected-site actions are the simplest way to undo only what that site needs. If you use terminal bulk commands instead:

  1. Save a copy of /var/log/cpfenceav/wp-sites-list.txt.
  2. Edit the site list so it contains only the intended installations and their existing owners. Manual bulk commands do not apply the AutoShield exclusion list.
  3. Choose the required reversal below, inspect the inventory prompt and confirm the action.
  4. Check each site’s final result and behavior, then restore your saved site list. Inventory regeneration can repopulate it later; do not assume the small list remains permanent.
Setting to reverse Command
Hardening edits cpfence --bulk-disable-wp-hardening
Text-math CAPTCHA cpfence --bulk-disable-wp-captcha
Idle logout cpfence --bulk-disable-wp-idle-logout
Limit Login Attempts protection cpfence --bulk-disable-wp-limit-login
XML-RPC restriction cpfence --bulk-enable-wp-xmlrpc
Pingback restriction cpfence --bulk-enable-wp-pingback
Admin file-editor restriction cpfence --bulk-enable-wp-file-edit
Disabled default WordPress cron cpfence --bulk-enable-wp-cron
Filtering of risky post content cpfence --bulk-enable-xss-in-wp-posts
Automatic component updates cpfence --disable-wp-auto-updates

Choose only the setting that needs changing. Allowing risky content or removing protection has security consequences; do not run the whole table as a cleanup script. If you also need to remove the cPFence MU plugin from this excluded installation, back up its wp-content/mu-plugins/cpfence.php file before having the site administrator remove that file only. Preserve other MU plugins and check sign-in afterward. The security MU plugin guide explains the separate server-wide removal command; it does not target only checked sites.

For Multisite, this read-only terminal search can help locate configurations to review:

Terminal window
find /var/www -type f -name wp-config.php -exec grep -H 'MULTISITE' {} +

A matching comment or WP_ALLOW_MULTISITE line alone does not prove Multisite is active. Review the installation’s configuration, exclude its actual path, and reverse hardening only on that installation if needed.