Skip to content

Schedule a WordPress command

Prefer the existing AutoShield settings for recurring protection. A separate cron job is appropriate only for an additional reviewed task.

cPFence’s bulk tools can help with recurring maintenance. Choose the task you need below; do not schedule the whole list. Run these from root on the server hosting the sites, after checking its current sites list and testing the intended command manually.

Task Current command
Rebuild the WordPress sites list cpfence --generate-wp-sites-list
Run the configured AutoShield policy cpfence --run-wp-autoshield
Export vulnerability findings cpfence --vuln-export
Back up WordPress files and databases cpfence --bulk-backup-wp-sites -y
Scan WordPress databases cpfence --bulk-scan-wp-databases -y
Optimize WordPress databases cpfence --bulk-optimize-wp-databases -y

Keep backup retention, storage and exclusions configured before scheduling backups. Local backups do not need passwordless SSH; remote backups do. A database scan produces findings, not proof that every malicious row was cleaned.

Task Current example
Update plugins now cpfence --bulk-auto-update-all-sites plugins
Enable future plugin auto updates cpfence --enable-wp-auto-updates plugins
Disable future plugin auto updates cpfence --disable-wp-auto-updates plugins
Disable request-triggered WordPress cron cpfence --bulk-disable-wp-cron -y
Enable request-triggered WordPress cron cpfence --bulk-enable-wp-cron -y
Run due WordPress cron events cpfence --bulk-run-due-wp-cron -y
Switch the site language cpfence --bulk-switch-wp-language -y en_US
Discourage search-engine indexing cpfence --bulk-disable-search-engine-index -y
Allow search-engine indexing cpfence --bulk-enable-search-engine-index -y
Enable maintenance mode cpfence --bulk-enable-maintenance-mode -y
Disable maintenance mode cpfence --bulk-disable-maintenance-mode -y

For component choices, see updates and future policy. Disabling WordPress cron does not create a replacement scheduler. Arrange one before relying on scheduled posts or plugin events. Replace en_US with the intended locale. Maintenance mode changes visitor access; always plan how to disable it afterwards.

Task Current example
Disable dashboard file editing cpfence --bulk-disable-wp-file-edit -y
Enable dashboard file editing cpfence --bulk-enable-wp-file-edit -y
Disable pingbacks cpfence --bulk-disable-wp-pingback -y
Enable pingbacks cpfence --bulk-enable-wp-pingback -y
Initialize missing secure keys cpfence --bulk-set-wp-secure-keys -y
Apply secure permissions cpfence --bulk-set-wp-permissions -y
Enable WordPress hardening cpfence --bulk-enable-wp-hardening -y
Disable WordPress hardening cpfence --bulk-disable-wp-hardening -y
Disable XML-RPC cpfence --bulk-disable-wp-xmlrpc -y
Enable XML-RPC cpfence --bulk-enable-wp-xmlrpc -y
Enable login limits cpfence --bulk-enable-wp-limit-login -y
Disable login limits cpfence --bulk-disable-wp-limit-login -y
Enable idle logout cpfence --bulk-enable-wp-idle-logout -y
Disable idle logout cpfence --bulk-disable-wp-idle-logout -y
Rename the default administrator cpfence --bulk-rename-wp-admin -y
Restrict scripts in posts cpfence --bulk-disable-xss-in-wp-posts -y
Allow scripts in posts cpfence --bulk-enable-xss-in-wp-posts -y
Enable login CAPTCHA cpfence --bulk-enable-wp-captcha -y
Disable login CAPTCHA cpfence --bulk-disable-wp-captcha -y
Restore core files cpfence --bulk-force-wp-core-files -y

Keep daily AutoShield policy consistent with one-off changes. Core replacement can overwrite customizations; account renaming changes the login, and script restrictions do not remove existing injected content. Review those tasks before scheduling them.

Task Current example
Clear LiteSpeed Cache cpfence --bulk-clear-litespeed-cache -y
Apply supported LiteSpeed configuration cpfence --bulk-configure-ls-plugin -y
Install LiteSpeed Cache cpfence --bulk-install-ls-plugin -y
Enable LiteSpeed Redis cpfence --bulk-enable-ls-redis -y
Reset LiteSpeed configuration cpfence --bulk-reset-ls-plugin -y
Remove conflicting cache plugins cpfence --bulk-uninstall-cache-plugins -y
Remove blacklisted plugins cpfence --bulk-uninstall-bl-plugins -y
Install the required plugin bundle cpfence --bulk-install-plugin-bundle -y
Install the prepared custom MU plugin cpfence --bulk-install-custom-mu-plugin -y
Remove the prepared custom MU plugin cpfence --bulk-uninstall-custom-mu-plugin -y

Redis needs a working eligible connection; configuration/reset actions are broader than cache purges. Check the configured bundle, blacklist or custom MU plugin before scheduling its action. Removal can affect site behavior, and MU plugins load automatically.

  1. Sign in as root to the server that owns the intended installations.
  2. Test the current cpfence command manually and check its targets and output.
  3. Inspect existing schedules before opening crontab -e.
  4. Add the intended schedule. For an additional vulnerability export at 02:00:
0 2 * * * /usr/bin/cpfence --vuln-export
  1. Save, then inspect the job’s recorded results after its first scheduled run.

Test one intended command before adding it to cron, check its logs after the first run, and keep cPFence updated. Avoid running additional maintenance at the same time as existing protection or backup schedules.

Find other current tools with filtered help:

Terminal window
cpfence --help | grep bulk

The IP-list tools --bulk-whitelist-ip and --bulk-blacklist-ip take a reviewed URL or file; see IPDB policies before scheduling a firewall change. Do not schedule interactive IP prompts without their required values.

Use the public cpfence command instead of retired /opt/cpfence wrappers. The -y examples above belong to the named supported commands; do not append it to unrelated commands. Do not create a second owner for an existing daily protection task.