cPFence v4 public beta is here.

Explore v4
News

WordPress Security Made Easy with cPFence’s New Features

WordPress core-file layers with checksum marks, a protection boundary and quarantine separation.

WordPress is the most popular and powerful CMS on the internet. Its flexibility, extensive features, and ease of use make it a top choice for websites of all kinds. But as amazing as WordPress is, it comes with a significant caveat: if it’s not secured correctly, it can become an open gateway for hackers.

Now, even if you’ve taken all the right steps to secure your WordPress installations, shared hosting environments bring their own set of challenges. Sometimes, users unknowingly leave vulnerabilities behind. Imagine this: a user sets up a WordPress installation to test a theme or plugin but doesn’t even complete the installation process. The site is left stuck on the “install” step, allowing a hacker to simply add their details and effectively “own” a site on your server. Scenarios like this aren’t just hypothetical—they happen all the time. And no matter how much you try to educate clients, mistakes like these are inevitable.

This is where file integrity checks become your best friend. By monitoring WordPress core files, file integrity checks help identify unauthorized changes, unexpected files, or incomplete setups before they lead to disaster.

At cPFence, we’ve introduced a WordPress Security Module designed specifically to address these challenges. Let’s take a closer look at its powerful features:

No passwordless SSH needed for normal cPFence v4+ operation. Only remote WordPress backups/restore and MultiRun need it. If you do not use those two features, you can disable passwordless SSH access and the rest of v4+ will keep working.

1. WordPress Integrity Check

This feature scans your WordPress installations to ensure all core files are intact and unaltered. It catches unauthorized changes, missing files, or any files that shouldn’t be there. If something is amiss, you’ll know about it immediately. This proactive approach adds a critical layer of protection against hackers exploiting overlooked vulnerabilities.

In cPFence v4+, choose one server in WordPress Management and open Settings → Integrity monitoring. For a focused check and recorded findings, use Threat & Malware Detection → WordPress Integrity. Read each finding and its actual action; a submitted check is not a clean result. CLI policy controls are cpfence --enable-integrity-check and cpfence --disable-integrity-check, run as root on the intended server.

2. Auto File Action

Unexpected files found during an integrity check can either be logged for manual review or, when eligible, quarantined with automatic file action enabled. It can also repair eligible altered WordPress core files when safe. Review each finding’s recorded action rather than assuming every file was quarantined. This automation is a lifesaver when managing multiple sites on shared hosting servers.

Use Automatic file action in the same Settings drawer, review backups and exclusions first, then save and check the result. CLI alternatives are cpfence --enable-auto-file-action and cpfence --disable-auto-file-action. See quarantine and recovery before restoring or trusting a finding.

3. Flexible Frequency Settings

You control how often the integrity checks run. Choose between hourly for high-risk environments or daily for regular monitoring. This flexibility ensures that your WordPress sites are always under watch without overwhelming your server resources.

Choose Integrity schedule → Hourly or Daily and Save settings. CLI equivalents are cpfence --set-check-frequency hourly and cpfence --set-check-frequency daily. Changing frequency saves policy; it does not enable monitoring or run a scan immediately.

WordPress Settings showing Integrity monitoring, Automatic file action and Integrity schedule.
Saved Local policy: integrity monitoring On, automatic file action On and hourly checks. Select the image to view it full size; use your browser’s Back command to return.

4. WordPress Site Listing

cPFence can now generate a detailed list of all WordPress installations on your server, complete with their paths and respective owners. This feature simplifies management, giving you a clear overview of what’s installed and who’s responsible for it. It’s a must-have tool for hosting providers and server admins alike.

Use cpfence --generate-wp-sites-list on the hosting server. The current WebUI lists sites in WordPress Management with server scope, search and owner filters. Explicitly select the intended sites before a bulk action.

WordPress Management site inventory with scope, filters and separate visible or filtered selection.
Private site and owner details are concealed; filtering the list does not select sites for an operation. Select the image to view it full size; use your browser’s Back command to return.

Customizing Security: Exclusions for Trusted Sites and Files

A standout feature of the cPFence WordPress Security Module is its flexibility. You can exclude specific websites or files from the integrity check to avoid unnecessary alerts or actions on trusted paths and files. Simply add the paths of websites you want to exclude to:
/etc/cpfcli/wp-integrity/exclude-sites.txt.

Similarly, if there are specific files you don’t want flagged or quarantined, you can list their names in:
/etc/cpfcli/wp-integrity/exclude-files.txt.

In the WebUI, open Threat & Malware Detection → Advanced Tools → Integrity exclusions and review its separate server targets. Use the full Site path for a whole-site exception, or an exact basename under File Name. Filename exceptions can apply across sites on the targeted server, so keep them narrow. The matching Unexclude control removes an exception.

Integrity Check Exclusions showing separate blank Site path and File Name controls.
Whole-site paths and filename exceptions have different scope; the fields show native placeholders, not saved exceptions. Select the image to view it full size; use your browser’s Back command to return.

CLI alternatives are cpfence --exclude-integrity-site /var/www/SITE_USER/public_html and cpfence --exclude-integrity-file trusted-file.php; replace the placeholders with the intended target. Remove the same entry with --del-exclude-integrity-site or --del-exclude-integrity-file. These are separate from daily AutoShield exclusions in /var/log/cpfenceav/wp-exclude-list.txt, and removing an exception does not restore a file already changed or quarantined.

This customization ensures that the module works seamlessly with your setup, focusing only on genuine risks without interfering with trusted configurations.

Why These Features Matter

Whether it’s catching unauthorized file changes, preventing overlooked installations from becoming vulnerabilities, or automating responses to threats, cPFence’s WordPress Security Module provides the tools you need to stay ahead of potential problems. These features are particularly valuable on shared hosting servers, where multiple users and varying levels of expertise can lead to security gaps.

With cPFence, you’re not just securing WordPress—you’re ensuring peace of mind. The WordPress Security Module works quietly in the background, leaving you free to focus on growing your business, not worrying about hacked sites or server vulnerabilities.

For more detailed guidance on securing and managing WordPress with cPFence, check out these helpful resources:

These resources offer step-by-step instructions and tips to make the most of cPFence’s powerful tools.

Ready to make your WordPress hosting bulletproof? Explore the new features of cPFence today and experience the difference proactive security makes.

Your server’s security isn’t optional—it’s essential.

Keep WordPress Security Simple

Your server’s security isn’t optional—it’s essential. Try cPFence v4+ and manage integrity monitoring and site protection from one place.

Start free trial
← Back to all articles
KEEP EXPLORING
All articles