Skip to content

Remove the cPFence security MU plugin

The cPFence security MU plugin supplies XML-RPC restrictions, login limits, WordPress CAPTCHA, idle logout and security headers. It loads automatically in WordPress.

  1. In WordPress Management, choose the server and open Settings.
  2. Turn these five child policies off: Disable XML-RPC, Limit login attempts, Login CAPTCHA, Idle logout and Security headers. Select Save settings.

WordPress Settings showing Disable XML-RPC, Limit login attempts, Login CAPTCHA and Idle logout

Turn off these four security-MU child policies on the intended server; the fifth, Security headers, is farther down. Select the image to view it full size; use your browser’s Back command to return.

WordPress Settings showing the Security headers child policy and Save settings

Also turn Security headers off, then save. The displayed saved values illustrate the controls, not the required off state. Select the image to view it full size; use your browser’s Back command to return.
  1. As root on that server, run:

    Terminal window
    cpfence --bulk-remove-mu-plugin
  2. Read the result and check site sign-in and response headers.

Manage custom MU plugin is a separate action for your uploaded PHP plugin; it does not mean removal of cPFence’s built-in security plugin.