Schedule a WordPress command
Prefer the existing AutoShield settings for recurring protection. A separate cron job is appropriate only for an additional reviewed task.
Tools you can schedule
Section titled “Tools you can schedule”cPFence’s bulk tools can help with recurring maintenance. Choose the task you need below; do not schedule the whole list. Run these from root on the server hosting the sites, after checking its current sites list and testing the intended command manually.
Discovery, reports and backups
Section titled “Discovery, reports and backups”| Task | Current command |
|---|---|
| Rebuild the WordPress sites list | cpfence --generate-wp-sites-list |
| Run the configured AutoShield policy | cpfence --run-wp-autoshield |
| Export vulnerability findings | cpfence --vuln-export |
| Back up WordPress files and databases | cpfence --bulk-backup-wp-sites -y |
| Scan WordPress databases | cpfence --bulk-scan-wp-databases -y |
| Optimize WordPress databases | cpfence --bulk-optimize-wp-databases -y |
Keep backup retention, storage and exclusions configured before scheduling backups. Local backups do not need passwordless SSH; remote backups do. A database scan produces findings, not proof that every malicious row was cleaned.
Updates, cron and maintenance
Section titled “Updates, cron and maintenance”| Task | Current example |
|---|---|
| Update plugins now | cpfence --bulk-auto-update-all-sites plugins |
| Enable future plugin auto updates | cpfence --enable-wp-auto-updates plugins |
| Disable future plugin auto updates | cpfence --disable-wp-auto-updates plugins |
| Disable request-triggered WordPress cron | cpfence --bulk-disable-wp-cron -y |
| Enable request-triggered WordPress cron | cpfence --bulk-enable-wp-cron -y |
| Run due WordPress cron events | cpfence --bulk-run-due-wp-cron -y |
| Switch the site language | cpfence --bulk-switch-wp-language -y en_US |
| Discourage search-engine indexing | cpfence --bulk-disable-search-engine-index -y |
| Allow search-engine indexing | cpfence --bulk-enable-search-engine-index -y |
| Enable maintenance mode | cpfence --bulk-enable-maintenance-mode -y |
| Disable maintenance mode | cpfence --bulk-disable-maintenance-mode -y |
For component choices, see updates and future policy. Disabling WordPress cron does not create a replacement scheduler. Arrange one before relying on scheduled posts or plugin events. Replace en_US with the intended locale. Maintenance mode changes visitor access; always plan how to disable it afterwards.
Protection and permissions
Section titled “Protection and permissions”| Task | Current example |
|---|---|
| Disable dashboard file editing | cpfence --bulk-disable-wp-file-edit -y |
| Enable dashboard file editing | cpfence --bulk-enable-wp-file-edit -y |
| Disable pingbacks | cpfence --bulk-disable-wp-pingback -y |
| Enable pingbacks | cpfence --bulk-enable-wp-pingback -y |
| Initialize missing secure keys | cpfence --bulk-set-wp-secure-keys -y |
| Apply secure permissions | cpfence --bulk-set-wp-permissions -y |
| Enable WordPress hardening | cpfence --bulk-enable-wp-hardening -y |
| Disable WordPress hardening | cpfence --bulk-disable-wp-hardening -y |
| Disable XML-RPC | cpfence --bulk-disable-wp-xmlrpc -y |
| Enable XML-RPC | cpfence --bulk-enable-wp-xmlrpc -y |
| Enable login limits | cpfence --bulk-enable-wp-limit-login -y |
| Disable login limits | cpfence --bulk-disable-wp-limit-login -y |
| Enable idle logout | cpfence --bulk-enable-wp-idle-logout -y |
| Disable idle logout | cpfence --bulk-disable-wp-idle-logout -y |
| Rename the default administrator | cpfence --bulk-rename-wp-admin -y |
| Restrict scripts in posts | cpfence --bulk-disable-xss-in-wp-posts -y |
| Allow scripts in posts | cpfence --bulk-enable-xss-in-wp-posts -y |
| Enable login CAPTCHA | cpfence --bulk-enable-wp-captcha -y |
| Disable login CAPTCHA | cpfence --bulk-disable-wp-captcha -y |
| Restore core files | cpfence --bulk-force-wp-core-files -y |
Keep daily AutoShield policy consistent with one-off changes. Core replacement can overwrite customizations; account renaming changes the login, and script restrictions do not remove existing injected content. Review those tasks before scheduling them.
Plugins and LiteSpeed Cache
Section titled “Plugins and LiteSpeed Cache”| Task | Current example |
|---|---|
| Clear LiteSpeed Cache | cpfence --bulk-clear-litespeed-cache -y |
| Apply supported LiteSpeed configuration | cpfence --bulk-configure-ls-plugin -y |
| Install LiteSpeed Cache | cpfence --bulk-install-ls-plugin -y |
| Enable LiteSpeed Redis | cpfence --bulk-enable-ls-redis -y |
| Reset LiteSpeed configuration | cpfence --bulk-reset-ls-plugin -y |
| Remove conflicting cache plugins | cpfence --bulk-uninstall-cache-plugins -y |
| Remove blacklisted plugins | cpfence --bulk-uninstall-bl-plugins -y |
| Install the required plugin bundle | cpfence --bulk-install-plugin-bundle -y |
| Install the prepared custom MU plugin | cpfence --bulk-install-custom-mu-plugin -y |
| Remove the prepared custom MU plugin | cpfence --bulk-uninstall-custom-mu-plugin -y |
Redis needs a working eligible connection; configuration/reset actions are broader than cache purges. Check the configured bundle, blacklist or custom MU plugin before scheduling its action. Removal can affect site behavior, and MU plugins load automatically.
Add the cron job
Section titled “Add the cron job”- Sign in as root to the server that owns the intended installations.
- Test the current
cpfencecommand manually and check its targets and output. - Inspect existing schedules before opening
crontab -e. - Add the intended schedule. For an additional vulnerability export at 02:00:
0 2 * * * /usr/bin/cpfence --vuln-export- Save, then inspect the job’s recorded results after its first scheduled run.
Keep scheduled work predictable
Section titled “Keep scheduled work predictable”Test one intended command before adding it to cron, check its logs after the first run, and keep cPFence updated. Avoid running additional maintenance at the same time as existing protection or backup schedules.
Find other current tools with filtered help:
cpfence --help | grep bulkThe IP-list tools --bulk-whitelist-ip and --bulk-blacklist-ip take a reviewed URL or file; see IPDB policies before scheduling a firewall change. Do not schedule interactive IP prompts without their required values.
Use the public cpfence command instead of retired /opt/cpfence wrappers. The -y examples above belong to the named supported commands; do not append it to unrelated commands. Do not create a second owner for an existing daily protection task.
