The cPFence MU (Must-Use) plugin provides several built-in security features for WordPress. If you prefer not to use it, you can safely remove it and prevent it from being reinstalled automatically by disabling the associated features.
Step 1: Understand What the MU Plugin Controls
The MU plugin enables five core security functions. If any of these remain enabled, cPFence will re-add the plugin automatically. You can view the full list here:
What Are the Security Features of the cPFence MU Plugin?
Step 2: Disable All MU Plugin Features
Use the WebUI to disable the features associated with the MU plugin:
- Log in to the cPFence WebUI.
- Navigate to System Settings.
- Disable all features listed in below.
1. autoshield_disable_wp_xmlrpc="off"
2. autoshield_wp_limit_login="off"
3. autoshield_wp_captcha="off"
4. autoshield_wp_idle_logout="off"
5. autoshield_security_headers="off"
Refer to this guide for details on how to adjust these settings:
Step 3: Remove the MU Plugin
Once all related features are disabled, run the following command to remove the MU plugin from all sites:
cpfence --bulk-remove-mu-plugin
This will ensure the plugin is removed and stays removed unless one of its features is re-enabled.
Need Further Assistance?
If you encounter any issues or need additional help, feel free to reach out to our support team via your client portal.
