Skip to content

Manage WordPress sites in bulk

Use WordPress Management to apply one operation to an explicit set of WordPress sites. This guide covers the Enhance WebUI. For security policies, see WordPress security and integrity; for recovery, see WordPress backups.

WordPress site table with filters, selection controls and Choose action

Filter the table, then select the sites to change. Select the image to view it full size; use your browser's Back command to return.

Support users need site/server access and the permission for the chosen action. Back up sites before updates, deletion or resets. Start with one site.

  1. Open WordPress Management and choose Server scope. Check notices for unavailable secondary servers.
  2. Use Search, Owner and Updates, then Apply filters to find sites. Filters narrow the table; they do not select sites.
  3. Select individual rows, Select all visible, or Select all … filtered sites. The filtered option includes matching sites beyond the current page. Use Clear selection to start again.
  4. Click Choose action. Use Bulk tools or WP-AutoShield, then choose a category or search for the operation.
  5. If options appear, fill them and click Review action; otherwise the target confirmation opens directly. Check the action, site count and servers, then confirm. Cancel submits nothing.

WordPress action menu with Bulk tools and WP-AutoShield tabs, category filters and named actions

Choose the tab and category for the task, or use the action search. This image shows navigation; each focused guide shows its own task controls. Select the image to view it full size; use your browser's Back command to return.

Refresh checks stored update information across the server scope; it does not install updates. Generate WordPress sites list and remote-backup enable/disable also use the server scope, rather than checked rows.

Follow component updates, one plugin, one theme or future auto-update policy.

Action Options and expected effect
Update WordPress components Choose All components, WordPress core, Plugins, Themes or Translations. Installs available updates for that component on selected sites.
Update one plugin / Update one theme Choose a repository slug or package source. For a repository slug, click Verify slug before reviewing the action; editing the slug requires verification again.
Manage WordPress auto updates Choose Enable/Disable and the component. This changes future update policy; it does not run an update immediately.
Manage plugin auto updates / Manage theme auto updates Choose Enable/Disable and verify the single component’s slug. Check each site’s actual result, including a component that is absent.

Automatic translation updates have a compatibility limitation: WordPress may still apply them after the translation auto-update option is disabled. Treat that switch as a stored policy choice, not a guarantee that all translation updates stop.

Bulk tools Plugins category showing package installation, Manage plugin by slug, cache removal, plugin bundle and custom MU entries

Choose the required plugin action; package-source fields and installed-plugin operations are described below. Select the image to view it full size; use your browser’s Back command to return.

Focused steps cover plugin installation, enable/disable, uninstall, bundles, custom MU plugins, theme installation, activation and deletion.

Install plugin or ZIP, Install theme or ZIP and single-component update forms offer Repository slug, HTTPS URL, Server path, Stored upload, and Upload ZIP. Choose a trusted source and fill its field. Verify repository slugs; a server path must exist on the execution server. An upload still needs a successful installation result.

In Install plugin or ZIP, use Slug, URL or path for the first three sources, Stored upload for a saved package, or ZIP file for a new upload.

Install plugin or ZIP source form with package fields and selected-target sections

The plugin installation form shows the package-source fields and target sections. Select the image to view it full size; use your browser's Back command to return.
Action Options and consequences
Manage plugin by slug Enter Installed plugin slug and choose Enable, Disable or Uninstall in Operation. Disabling preserves the plugin; uninstalling removes it and may invoke its cleanup.
Uninstall cache plugins Removes the supported cache/Redis plugins from selected sites, with LiteSpeed Cache excluded from this removal. Keep reinstall packages/settings if recovery may be needed.
Install plugin bundle Installs the configured required bundle. Administrators can inspect Required plugin bundle in Edit Configuration Files before applying it.
Manage custom MU plugin Choose Install/Uninstall and a stored PHP file or New MU plugin file. MU plugins load automatically. Delete stored file removes the stored upload from the current server scope; it does not substitute for uninstalling a deployed plugin.
Activate theme by slug Enter Installed theme slug. Activation changes the site’s presentation.
Delete theme by slug Enter Installed theme slug to delete an installed inactive theme. Switch away from an active theme first and preserve a copy for recovery.

After completion, check the site’s plugin/theme version, activation and public pages. Disabling a daily installation/removal setting does not reverse extensions already installed or removed.

Follow create, list, password reset or delete/reassign for focused steps.

Action What to supply and check
Create WordPress user Enter username, email, password and role. The create form does not accept commas in the password. Check that this account is intended on every selected site.
List WordPress users Choose All roles or one role; review the per-site export/output.
Reset all passwords Choose a role carefully: All roles is broad. It generates new passwords for matching users.
Reset one user password Supply login, email or numeric ID. Enter a New password when you need a known replacement; leaving it blank generates one.
Delete user and reassign content Supply login, email or numeric ID. Content is reassigned to an available administrator; a site without a suitable administrator can be skipped.
Delete user without reassignment Deletes the account and its associated content using WordPress deletion behavior. Preserve a backup; do not depend on the trash to recover everything.

Reset commands skip WordPress’s reset email; the WebUI hides passwords from output. Use a known replacement for an individual account or arrange WordPress password recovery. Generated passwords are not revealed in the job log.

For overdue posts or plugin events, follow Run overdue WordPress cron events.

Action group How to use it
Enable WordPress Cron, Disable WordPress Cron, Run due WordPress Cron Enable/disable request-triggered cron or execute due events now. Disabling request-triggered cron does not create an external scheduler; arrange one for scheduled posts and plugin tasks.
Enable search-engine indexing / Disable search-engine indexing Change WordPress’s visibility preference. This preference is not access control.
Enable maintenance mode / Disable maintenance mode Show/remove WordPress maintenance mode. Confirm the public site recovers after disabling it.
Optimize databases Optimizes selected WordPress databases. Expect database work; schedule it when the host has spare capacity and preserve a backup.
Switch WordPress language Enter a valid locale such as en_US. Check installed resources and the resulting language.
Clear LiteSpeed cache Purges the selected sites’ supported cache; subsequent requests may rebuild it.
Install LiteSpeed plugin / Configure LiteSpeed plugin Install the plugin or apply its supported configuration. Check site behavior and retain any custom settings first.
Enable LiteSpeed Redis / Enable LiteSpeed heartbeat Apply the corresponding plugin configuration. Redis needs a working eligible connection.
Enable login-page caching / Disable login-page caching Change LiteSpeed’s login-page cache policy. Uncached login pages are needed for WAF CAPTCHA behavior.
Reset LiteSpeed plugin Resets its configuration; it is broader than a cache purge. Record custom configuration before confirming.

Choose WP-AutoShield in the action picker for these actions. Use the security guide to configure daily policy, integrity monitoring and exclusions.

Action Intended outcome
Run WP-AutoShield Apply the target server’s configured policy to selected eligible sites; policy exclusions still matter.
Rename default admin Rename the default account. Check the per-site output and resulting login.
Enable XML-RPC / Disable XML-RPC Permit/restrict XML-RPC independently of pingbacks.
Enable login limits / Disable login limits Turn WordPress repeated-login protection on/off.
Enable login CAPTCHA / Disable login CAPTCHA Change the WordPress authentication CAPTCHA.
Enable idle logout / Disable idle logout Change idle-session protection.
Enable security headers / Disable security headers Change headers on WordPress responses.
Set secure keys Initialize missing keys; a site with existing nonempty keys retains them.
Set secure permissions Apply secure WordPress file permissions; record custom requirements first.
Enable dashboard file editing / Disable dashboard file editing Permit/restrict the built-in plugin/theme editor.
Enable pingbacks / Disable pingbacks Change default pingback options.
Enable WordPress hardening / Disable WordPress hardening Apply/remove supported hardening rules.
Enable scripts in posts / Restrict scripts in posts Permit/restrict unfiltered HTML for editing; this does not remove existing scripts.
Uninstall blacklisted plugins Remove plugins in the configured blacklist. Keep a backup for recovery.
Scan databases for malware Scan selected WordPress databases. Inspect findings; a database finding is separate from a filesystem finding.
Export vulnerability report Produce the selected sites’ report. Review the recorded output location; a report does not install fixes.

Restore WordPress core files, under Bulk tools, replaces modified core with clean copies. It does not restore the database. Review backups and exclusions first; check public pages afterward.

Action Scope and purpose
Back up selected sites / Restore selected sites Use checked site rows to create or restore a verified site-file archive and database export pair. Restore replaces current site data.
Enable remote backups / Disable remote backups Change future storage for the reviewed server scope.

Follow the backup and restore steps for schedules, exclusions, remote destinations, snapshot selection and recovery.

The output shows Running, then Finished or Needs attention.

  • Finished: the run completed. It can include sites that failed or were skipped; each failed site is listed in the output and in that command’s error log on its server, such as /var/log/wordpress-disable-cron-error.log.
  • Needs attention: the run itself failed, a ZIP plugin or theme update failed, or no final status arrived.

Read every site’s result before treating the action as complete.

After a lost connection, check the site and recorded outcome before retrying. If scope or permissions changed, refresh and review again. Confirmed targets do not grow when a secondary server joins.

Check website health after updates. Reverse policy changes with their paired action; recover deleted data from a suitable backup.

Other focused tasks: LiteSpeed setup, presets, purge, reset, Redis, heartbeat, login cache, maintenance, indexing, database optimization, language, site inventory and scheduling a command.

Use a root terminal on the server hosting the sites. Start by generating its WordPress list:

Terminal window
cpfence --generate-wp-sites-list

Review /var/log/cpfenceav/wp-sites-list.txt and retain only the intended installations for ordinary manual bulk tools. Regenerating the list can restore discovered entries, so check it again before each run. Read site inventory for the current format.

Choose one task, read its prompts and check each site’s final output. The original feature groups remain available with their current arguments in the WordPress command reference:

Feature group Follow the task guide
Daily AutoShield, integrity and exceptions Security policy and integrity; exclusions
Updates, automatic updates and vulnerability reports Updates; future policy; vulnerability reports
XML-RPC, login limits, CAPTCHA, idle logout and admin rename Access controls
Permissions, keys and hardening Permissions and hardening; keys and editor controls
Editors, pingbacks, response headers and risky content Editorial controls
Cron and overdue scheduled posts Cron controls
LiteSpeed installation, presets, Redis, heartbeat, login caching, purge and reset Use the focused LiteSpeed tasks linked above.
Plugin/theme installation, activation, removal, bundles and custom MU plugins Use the focused extension tasks above; source packages and installed slugs have different requirements.
User creation, lists, password resets and deletion Use the focused user tasks above; interactive commands prompt for fields, while automatic variants need arguments.
Maintenance, indexing and language Maintenance; indexing; language
Database scans, optimization and core-file recovery Database scans; optimization; core restore

Commands ending in -auto generally skip confirmation; explicit update-policy components also apply without prompts. Prepare the exact scope and backups first. Keep generated passwords and user exports private.

For example, to block XML-RPC on the reviewed local sites:

Terminal window
cpfence --bulk-disable-wp-xmlrpc

Review site integrations first and use the paired enable action only where required. Existing configured daily protections can reapply a reversed setting; use the security guide to match recurring policy. These native v4+ actions do not require passwordless SSH between cluster servers.