Skip to content

Change WordPress editors, pingbacks and headers

  1. Select the sites.
  2. Open Choose action → WP-AutoShield → Hardening, then choose the required action.
  3. Review the targets, confirm, and inspect each site’s result and affected feature.
Requirement Action
Restrict plugin/theme editing in wp-admin Disable dashboard file editing; use Enable dashboard file editing when a trusted developer requires it.
Stop pingbacks Disable pingbacks; use Enable pingbacks for a required integration.
Add WordPress response headers Enable security headers; Disable security headers removes the supported set. Check CDN caches and actual responses; static/non-WordPress responses are separate.
Initialize authentication keys Set secure keys fills missing keys while retaining existing nonempty keys.
Restrict unfiltered post HTML Restrict scripts in posts; use Enable scripts in posts for a verified requirement. Existing posts are not cleaned.

WP-AutoShield Hardening group showing response headers, secure keys, dashboard editing and pingback actions

Choose the exact action matching the requirement; these entries have separate effects. Select the image to view it full size; use your browser’s Back command to return.

WP-AutoShield Hardening group showing dashboard editing, pingbacks, WordPress hardening and script-content actions

The lower entries include the paired script-content actions. They do not clean existing posts. Select the image to view it full size; use your browser’s Back command to return.

Advanced editors such as WPBakery or Elementor may need risky-content capabilities. Follow Additional CSS and editor features rather than changing every site’s policy.

Secure-key initialization does not rotate existing keys or log every existing user out. Preserve custom requirements before changing configuration.

WordPress Settings showing Initialize secure keys, Disable dashboard file editing and Disable pingbacks

Match the recurring keys, file-editor and pingback policies to the site’s requirements. Select the image to view it full size; use your browser’s Back command to return.

WordPress Settings showing Restrict risky post content

Risky-content policy controls unfiltered HTML on future edits; it is separate from dashboard file editing. Select the image to view it full size; use your browser’s Back command to return.

WordPress Settings showing Security headers and separate notification choices

Security headers affect WordPress responses. Saved child choices apply during eligible AutoShield work; check actual responses after an action. Select the image to view it full size; use your browser’s Back command to return.

From a root terminal on the server hosting the sites, review /var/log/cpfenceav/wp-sites-list.txt. The following actions use that local list, not checked WebUI rows. Read the inventory and confirmation prompts before applying one change.

Enable the supported WordPress header set:

Terminal window
cpfence --bulk-enable-sec-headers

Remove it when needed:

Terminal window
cpfence --bulk-disable-sec-headers

Check actual responses after clearing relevant CDN caches. Match the daily Security headers child policy to a lasting exception.

Disable the built-in plugin/theme editor:

Terminal window
cpfence --bulk-disable-wp-file-edit

Restore it for a trusted developer:

Terminal window
cpfence --bulk-enable-wp-file-edit

Reapply the restriction and intended daily policy after temporary maintenance.

Turn the default pingback options off:

Terminal window
cpfence --bulk-disable-wp-pingback

Restore them for a required integration:

Terminal window
cpfence --bulk-enable-wp-pingback

For a lasting exception, also turn the daily Disable pingbacks child policy off or exclude that site.

Restrict unfiltered HTML in future edits:

Terminal window
cpfence --bulk-disable-xss-in-wp-posts

Restore that capability when required:

Terminal window
cpfence --bulk-enable-xss-in-wp-posts

Communicate with developers before changing rich embeds or editor capabilities. This does not remove existing scripts, and the paired enable command cannot restore content removed by an editor. Check the actual editor behavior and final result on each site, then match Restrict risky post content to the intended recurring policy.