Skip to content

Configure WordPress security and integrity

Use WordPress Management for WordPress AutoShield policy and selected-site security actions. Integrity monitoring checks WordPress core against official checksums. These Enhance WebUI workflows have separate settings and exclusions.

WordPress Management with server scope, Settings and site-selection controls

Open Settings for one server, or select sites for an action. Select the image to view it full size; use your browser's Back command to return.

Support users need site/server access and permission for the chosen security, settings or exclusion action. Back up sites before removing plugins or repairing files. Check any XML-RPC, cron or custom login requirements.

  1. In WordPress Management, choose Local or one secondary server in Server scope. Settings requires one specific server.
  2. Open Settings and review WordPress protection. Enable WordPress AutoShield for daily enforcement.
  3. Choose the child policies below. Check descriptions carefully: some switches turn a feature off when enabled.
  4. Click Save settings and check the result.
Policy Effect and recovery
Update WordPress site list Discover new sites before scheduled protection. If off, maintain a valid site list; selected-site operations retain their explicit selection.
Automatic WordPress updates Enables site auto-update policy during AutoShield. Turning this off stops enabling it; use Manage WordPress auto updates to disable existing site policy.
Vulnerability report Generate the scheduled report. Delivery also needs its notification choice and a configured channel.
Disable WordPress cron Disable request-triggered cron. Configure an external scheduler separately.

WordPress Settings showing AutoShield, discovery, automatic updates, vulnerability reporting and integrity controls

Choose the AutoShield master and child policies for one server. The displayed values are saved choices; child switches do not apply daily policy while AutoShield is off. Select the image to view it full size; use your browser’s Back command to return.
Policy Effect and recovery
Initialize secure keys Fill missing WordPress authentication keys; retain existing keys.
Disable dashboard file editing, Disable pingbacks, Disable XML-RPC Apply their separate restrictions. Re-enable only the capability a site needs.
Enforce secure permissions Apply cPFence’s WordPress permissions. Turning this off does not restore old permissions.
WordPress hardening Apply supported file/directory hardening; off removes the supported rules on the next run. nginx does not enforce .htaccess rules, so do not assume this provides PHP-upload blocking there.
Limit login attempts, Login CAPTCHA, Idle logout Manage WordPress authentication protection. Idle logout defaults to 120 minutes; existing custom timeouts are retained. WordPress CAPTCHA is separate from WAF CAPTCHA.

WordPress Settings showing secure keys, dashboard editing, pingbacks, permissions and hardening policies

Review hardening policies against the site’s required permissions and features. Select the image to view it full size; use your browser’s Back command to return.
Policy Effect and recovery
Rename admin user Rename the default admin account. Record the resulting identity and verify sign-in; off does not rename it back.
Restrict risky post content Restrict unfiltered HTML on future edits. Existing posts are not cleaned.
Remove blacklisted plugins, Remove cache plugins Remove the configured blacklist or supported cache/Redis plugins. Off does not reinstall them.

WordPress Settings showing XML-RPC, login limits, CAPTCHA, idle logout, administrator rename and risky-content policies

Keep the intended authentication and editor capabilities; saved child choices are separate from a one-off site action. Select the image to view it full size; use your browser’s Back command to return.
Policy Effect and recovery
Deploy custom MU plugin, Required plugin bundle Deploy the configured custom MU plugin or install the required bundle. Off does not remove existing installations.
Database malware scan, Database optimization Run these daily tasks. Optimization adds database work; use available capacity.
Security headers Add headers to WordPress responses; this does not configure every static or non-WordPress response.
Clear LiteSpeed cache, Exclude login page from LiteSpeed cache Purge supported caches or keep login pages uncached for WAF CAPTCHA. Use the explicit login-cache action to re-enable caching later.

WordPress Settings showing database, security-header, plugin-bundle and LiteSpeed policies plus notification choices

Choose database, plugin and cache policies separately from their notification options. The image shows saved choices, not packaged defaults. Select the image to view it full size; use your browser’s Back command to return.

Fresh defaults have AutoShield on, automatic updates off and login CAPTCHA off. Read the target’s saved policy; existing settings can differ.

2. Apply a security action to selected sites

Section titled “2. Apply a security action to selected sites”

Open Choose action → WP-AutoShield for a one-off security change. Protection → Run WP-AutoShield applies the current eligible policy; other categories contain the explicit feature actions.

  1. Follow the site-selection steps.
  2. Choose the security operation from the WP-AutoShield action catalogue.
  3. Review its targets and confirm. Check the site’s resulting settings and health.

Read every per-site result under Finished or Needs attention. Daily policy can reapply after a one-off change; add an appropriate exclusion for a lasting exception.

WP-AutoShield Protection category showing Run WP-AutoShield

Run the current eligible policy for the reviewed sites, then inspect each final result. Select the image to view it full size; use your browser’s Back command to return.

Open Edit Configuration Files → WP-AutoShield exclusions and add the intended site path. Preserve existing entries and save. WP-AutoShield site list, Blacklisted plugins and Required plugin bundle are separate lists. An AutoShield exclusion does not disable malware, integrity or WAF protection.

Follow Exclude sites from AutoShield for account/site path examples and reversing earlier changes. See Additional CSS and editor features for risky-content restrictions, or Remove the security MU plugin for server-wide removal.

For database scanning, follow database-scan exceptions using its separate result-pattern and site lists. For an infected installation, follow Clean an infected WordPress site.

Use WordPress Integrity to filter sites, run a selected-site check and read recorded findings, actions and earlier checks. The settings below control policy rather than proving a completed clean result.

In WordPress Settings, use Integrity monitoring, Automatic file action and Integrity schedule. Equivalent controls are available under Threat & Malware Detection → Settings. There they are labeled WordPress Integrity Check, Integrity Auto-Repair and WordPress Integrity schedule.

Choice Packaged default Effect
Integrity monitoring On Check WordPress core files; full/smart scans also include enabled integrity checks.
Automatic file action Off When enabled, quarantine applicable unexpected files and conditionally repair core files when safe.
Integrity schedule Daily Choose Daily or Hourly. This schedule does not change attached full/smart checks.

Before enabling automatic action, review exclusions and backups. Check each finding’s actual action. For recovery, see quarantine results.

Detection Settings showing WordPress Integrity Check, Integrity Auto-Repair and WordPress Integrity schedule

The Detection Settings labels refer to the same integrity choices. Read the target’s saved values before changing them. Select the image to view it full size; use your browser’s Back command to return.

To manage exceptions, open Threat & Malware Detection → Advanced Tools → Integrity exclusions. Set the Advanced Tools server targets separately from the single-server scan summary. A Site path excludes that site; File Name is an exact basename and can exempt that filename across sites on the targeted server. Remove the same entry to resume checking. Use filename exceptions narrowly.

Integrity Check Exclusions form with Site path, File Name and separate exclude and unexclude buttons

Whole-site and filename exceptions have different scope. The blank form does not show a submitted exclusion. Select the image to view it full size; use your browser’s Back command to return.

For core repair, follow Restore WordPress core files. Check website health afterward; repairing core does not establish that plugins, themes and accounts are clean.

Focused tasks: login/XML-RPC controls, permissions/hardening, editors/headers/pingbacks and identify sites needing investigation.

From a root terminal on the server hosting the sites, enable daily AutoShield:

Terminal window
cpfence --wp-autoshield-on

Configure its child choices in WordPress Settings or /etc/cpfcli/config.conf. The chosen daily protections run at 06:10 server time. To turn daily enforcement off, use cpfence --wp-autoshield-off; earlier site changes remain in place. To apply the eligible saved policy now, use cpfence --run-wp-autoshield and read each step’s final result.

For ordinary one-off security commands, first generate and review the local site list. Use the focused access, permissions and editor tasks for their paired actions and confirmations. Manual bulk tools ignore daily AutoShield exclusions; their CLI scope is the hosting server, not the cluster or checked WebUI rows.

Task Command
Enable integrity monitoring cpfence --enable-integrity-check
Disable integrity monitoring cpfence --disable-integrity-check
Enable automatic file action cpfence --enable-auto-file-action
Disable automatic file action cpfence --disable-auto-file-action
Choose daily checks cpfence --set-check-frequency daily
Choose hourly checks cpfence --set-check-frequency hourly

Changing the frequency saves policy; it does not enable monitoring or run a scan immediately. Before automatic action, review backups and exclusions. It can quarantine eligible unexpected files and repair eligible core files, so inspect each finding’s recorded action rather than assuming everything was quarantined.

Use the actual full installation path, for example:

Terminal window
cpfence --exclude-integrity-site /var/www/SITE_USER/public_html

Replace SITE_USER and the path with the intended installation. To resume checking that site:

Terminal window
cpfence --del-exclude-integrity-site /var/www/SITE_USER/public_html

For an exact trusted basename:

Terminal window
cpfence --exclude-integrity-file trusted-file.php

Remove that same exception when it is no longer needed:

Terminal window
cpfence --del-exclude-integrity-file trusted-file.php

A filename exception can apply across sites on this server. Keep it narrow. The current site/file lists are /etc/cpfcli/wp-integrity/exclude-sites.txt and /etc/cpfcli/wp-integrity/exclude-files.txt; they are separate from /var/log/cpfenceav/wp-exclude-list.txt for daily AutoShield. The exclusion commands save entries but do not restore files already changed or quarantined.

  • Keep WordPress core, plugins and themes up to date.
  • Use strong passwords and appropriate two-factor authentication for administrator accounts.
  • Remove unused or outdated extensions and keep usable files/database backups.
  • If a site uses an additional security plugin such as Wordfence, review login-plugin compatibility before combining login protections.

The built-in login-limit policy allows five failed attempts within its five-minute window. Idle logout defaults to 120 minutes with saved custom timeouts retained. Secure-key initialization fills missing values, and risky-content restrictions affect future editing rather than removing existing injected posts. Check site requirements and the final results of each protection.

The full original feature families and current CLI alternatives remain in bulk WordPress management and the WordPress command reference.