Skip to content

Change WordPress login and XML-RPC controls

  1. Select the intended installations.
  2. Open Choose action → WP-AutoShield → Access, then choose the required action below.
  3. Review targets, confirm, and inspect each site’s result.
  4. Test login, password recovery and any affected integrations.
Task Current action and meaning
Restrict remote XML-RPC Disable XML-RPC blocks the endpoint; Enable XML-RPC restores it for required integrations.
Limit failed logins Enable login limits applies the supported repeated-login policy; Disable login limits reverses it.
Add WordPress CAPTCHA Enable login CAPTCHA adds the math check to eligible authentication forms; Disable login CAPTCHA removes it. Hosted WAF CAPTCHA is separate.
End idle sessions Enable idle logout applies the idle policy; Disable idle logout reverses it. The default is 120 minutes, with existing custom timeouts retained.
Replace the default login name Rename default admin changes the default administrator identity. Record the resulting name and communicate it privately to the owner.

WP-AutoShield Access group showing administrator rename, XML-RPC, login-limit and CAPTCHA actions

Choose the exact Access action for the selected sites. Renaming the default admin is separate from enabling or disabling login controls. Select the image to view it full size; use your browser’s Back command to return.

WP-AutoShield Access group showing complete login-limit, CAPTCHA and idle-logout action pairs

Scroll within the chooser to see both idle-logout entries. Inspect results and test the affected login flow after confirmation. Select the image to view it full size; use your browser’s Back command to return.

Keep LiteSpeed login pages uncached when required for CAPTCHA. An XML-RPC exception does not disable all login protection.

WordPress Settings showing XML-RPC, login limits, CAPTCHA, idle logout and administrator-name policies

Review these child policies in one server’s Settings before a lasting exception. Their saved values do not prove the selected-site action has completed. Select the image to view it full size; use your browser’s Back command to return.

From a root terminal on the server hosting the sites, review /var/log/cpfenceav/wp-sites-list.txt, then use the required command below. These commands use that server’s listed installations, not checked WebUI rows. Read the inventory and confirmation prompts before proceeding.

Protection Enable Disable
Math CAPTCHA on login, registration and lost-password forms cpfence --bulk-enable-wp-captcha cpfence --bulk-disable-wp-captcha
Idle logout cpfence --bulk-enable-wp-idle-logout cpfence --bulk-disable-wp-idle-logout
Limit Login cpfence --bulk-enable-wp-limit-login cpfence --bulk-disable-wp-limit-login
XML-RPC access cpfence --bulk-enable-wp-xmlrpc cpfence --bulk-disable-wp-xmlrpc

To replace the default administrator login:

Terminal window
cpfence --bulk-rename-wp-admin

Check each site’s final output. Record new administrator usernames privately and share them with the site owners before their next login. Test login and recovery forms; check integrations after an XML-RPC change. If you temporarily disable Limit Login for troubleshooting, enable it again after maintenance. Combine it with idle logout where appropriate.

For a lasting CAPTCHA, idle-logout or XML-RPC exception, also review the daily child policy above. Keep other login protections enabled for sites that need XML-RPC access.