What Are the Security Features of the cPFence MU-Plugin?

What Are the Security Features of the cPFence MU-Plugin?

The cPFence MU-Plugin provides 4 key security features designed to enhance the protection of your WordPress sites. These features include:

  1. Disabling XML-RPC: Prevents unauthorized access and mitigates XML-RPC-based attacks.
  2. Limiting Login Attempts: Protects against brute-force attacks by restricting the number of failed login attempts.
  3. Math Captcha for Login Pages: Adds an extra layer of security by requiring users to solve a simple math problem before logging in.
  4. Idle User Logout: Automatically logs out idle users to prevent unauthorized access to active sessions.

What If You Don’t Want to Use These Features?

If you prefer not to use the MU-Plugin’s features, you can safely remove the plugin. However, ensure that you first disable these features in the WP-AutoShield configuration. This prevents the MU-Plugin from being re-added automatically.

Alternatively, if you want to exclude specific sites from these security measures, you can add them to the exclusion list. This way, only the specified sites will remain unaffected by the plugin’s features.

Use the exclusion file /var/log/cpfenceav/wp-exclude-list.txt to exclude specific sites from the daily cron job.

Important Points to Remember

  • The exclusion list (wp-exclude-list.txt) affects only the automatic daily cron jobs.
  • The daily cron job applies only the measures enabled in your configuration file.
  • Manual commands bypass the exclusion list and provide flexibility to apply selected measures to specific sites in the wp-sites-list.txt file.
  • You can remove the MU Plugin server-wide running the command : cpfence --bulk-remove-mu-plugin

Need Assistance?

If you have additional questions or need help managing the MU-Plugin, please reach out to our support team via your client portal.

  • 0 Utilisateurs l'ont trouvée utile
Cette réponse était-elle pertinente?

Articles connexes

How to Perform and Export Wordpress Vulnerability Scans with cPFence?

cPFence provides powerful tools for identifying and analyzing Wordpress vulnerabilities. With the...

How to Generate a List of All WordPress Sites on Your Server?

cPFence provides an easy way to generate a comprehensive list of all WordPress sites on your...

How to Quickly Identify Infected WordPress Sites Using cPFence?

cPFence makes it easy to identify and clean infected WordPress sites on your server. Follow the...

How to Use WordPress Auto-Update Features in cPFence?

Managing WordPress sites securely and efficiently is now easier with cPFence's WordPress...

How to Clean an Infected WordPress Site?

Has your WordPress site been infected, and cPFence reported malware or other issues? Don’t worry;...