Ecenica WordPress Manager powered by WP Toolkit includes built-in security measures that harden your WordPress site against common attacks. You can apply them with one click or enable individual settings from the 8Security Measures* tab.
How to access WP Toolkit security measures
- Log in to Ecenica Dashboard
- Open your Ecenica WordPress hosting service.
- Click WordPress Manager
- Select your WordPress installation
- Click Apply security critical measures
- Enable all security measures by clicking Apply All or instead pick and choose the WordPress security measures you wish to apply.
WordPress security measures explained
Restrict access to files and directories
Blocks direct HTTP access to sensitive WordPress files and folders. This prevents attackers from viewing file contents or directory listings.
Configure security keys
Updates the security keys and salts in your wp-config.php file. These keys encrypt cookies and passwords, making them harder to crack.
Block directory browsing
Stops visitors from viewing folder contents when no index.php file exists. Without this, attackers can browse your file structure.
Block access to wp-config.php
Prevents HTTP access to wp-config.php, which contains your database credentials. This file should never be accessible via a browser.
Disable PHP execution in cache directories
Stops PHP scripts from running in cache folders. If an attacker uploads a malicious PHP file to a cache directory, this setting stops it from executing.
Change default database table prefix
Changes your database tables from the default wp_ prefix to a random value. Many automated attacks target tables with the default prefix.
Block access to sensitive files
Prevents HTTP access to files like readme.html, license.txt, and wp-config-sample.php. These files reveal your WordPress version and configuration.
Block access to xmlrpc.php
Stops access to xmlrpc.php, which attackers use for brute force attacks and DDoS amplification. Most sites don’t need this file.
Forbid PHP execution in wp-includes
Prevents PHP scripts from running in the wp-includes directory. This directory contains core WordPress files that shouldn’t execute directly.
Forbid PHP execution in wp-content/uploads
Stops PHP execution in your uploads folder. This prevents attackers from running malicious scripts they may have uploaded.
Disable scripts concatenation
Turns off JavaScript concatenation in the WordPress admin. This can help if you notice broken admin pages after applying security measures.
Turn off pingbacks
Disables pingbacks, which attackers can use for DDoS attacks. Pingbacks notify other sites when you link to them, but most sites don’t need this feature.
Disable file editing
Removes the theme and plugin editor from the WordPress Dashboard. This prevents administrators from editing PHP files through the admin interface.
Enable bot protection
Blocks common malicious bots from accessing your site. This reduces unwanted traffic and potential security probes.
Block access to .htaccess and .htpasswd
Prevents HTTP access to Apache/LiteSpeed configuration files. These files can reveal server settings and password information.
Block author scans
Stops attackers from enumerating usernames through author archives. This makes brute force attacks harder.
Change default administrator username
Changes the default admin username to a different value. Many attacks target the default username.
Reverting changes
Most security measures can be reverted. Find the setting in the Security Measures tab and toggle it off. The change takes effect immediately.
When to use each setting
The security measures marked with a red exclamation mark are critical for all WordPress sites. The orange triangle settings are recommended but may affect specific plugins or themes.
If a plugin stops working after applying a security measure, revert that setting and check the plugin’s documentation.
Troubleshooting
My site broke after applying security measures. Revert the most recently applied setting and test your site. Some plugins need access to files or directories that these measures block.
I can’t edit themes or plugins. This is expected when Disable file editing is enabled. Access your files through cPanel File Manager or FTP instead.
A plugin needs xmlrpc.php. Some plugins use XML-RPC for remote access. If you need it, revert the Block access to xmlrpc.php setting.