Security

How to apply security measures in WP Toolkit

Ecenica WordPress Manager powered by WP Toolkit includes built-in security measures that harden your WordPress site against common attacks. You can apply them with one click or enable individual settings from the 8Security Measures* tab.

How to access WP Toolkit security measures

  1. Log in to Ecenica Dashboard
  2. Open your Ecenica WordPress hosting service.
  3. Click WordPress Manager
  4. Select your WordPress installation
  5. Click Apply security critical measures
  6. Enable all security measures by clicking Apply All or instead pick and choose the WordPress security measures you wish to apply.

WordPress security measures explained

Restrict access to files and directories

Blocks direct HTTP access to sensitive WordPress files and folders. This prevents attackers from viewing file contents or directory listings.

Configure security keys

Updates the security keys and salts in your wp-config.php file. These keys encrypt cookies and passwords, making them harder to crack.

Block directory browsing

Stops visitors from viewing folder contents when no index.php file exists. Without this, attackers can browse your file structure.

Block access to wp-config.php

Prevents HTTP access to wp-config.php, which contains your database credentials. This file should never be accessible via a browser.

Disable PHP execution in cache directories

Stops PHP scripts from running in cache folders. If an attacker uploads a malicious PHP file to a cache directory, this setting stops it from executing.

Change default database table prefix

Changes your database tables from the default wp_ prefix to a random value. Many automated attacks target tables with the default prefix.

Block access to sensitive files

Prevents HTTP access to files like readme.html, license.txt, and wp-config-sample.php. These files reveal your WordPress version and configuration.

Block access to xmlrpc.php

Stops access to xmlrpc.php, which attackers use for brute force attacks and DDoS amplification. Most sites don’t need this file.

Forbid PHP execution in wp-includes

Prevents PHP scripts from running in the wp-includes directory. This directory contains core WordPress files that shouldn’t execute directly.

Forbid PHP execution in wp-content/uploads

Stops PHP execution in your uploads folder. This prevents attackers from running malicious scripts they may have uploaded.

Disable scripts concatenation

Turns off JavaScript concatenation in the WordPress admin. This can help if you notice broken admin pages after applying security measures.

Turn off pingbacks

Disables pingbacks, which attackers can use for DDoS attacks. Pingbacks notify other sites when you link to them, but most sites don’t need this feature.

Disable file editing

Removes the theme and plugin editor from the WordPress Dashboard. This prevents administrators from editing PHP files through the admin interface.

Enable bot protection

Blocks common malicious bots from accessing your site. This reduces unwanted traffic and potential security probes.

Block access to .htaccess and .htpasswd

Prevents HTTP access to Apache/LiteSpeed configuration files. These files can reveal server settings and password information.

Block author scans

Stops attackers from enumerating usernames through author archives. This makes brute force attacks harder.

Change default administrator username

Changes the default admin username to a different value. Many attacks target the default username.

Reverting changes

Most security measures can be reverted. Find the setting in the Security Measures tab and toggle it off. The change takes effect immediately.

When to use each setting

The security measures marked with a red exclamation mark are critical for all WordPress sites. The orange triangle settings are recommended but may affect specific plugins or themes.

If a plugin stops working after applying a security measure, revert that setting and check the plugin’s documentation.

Troubleshooting

My site broke after applying security measures. Revert the most recently applied setting and test your site. Some plugins need access to files or directories that these measures block.

I can’t edit themes or plugins. This is expected when Disable file editing is enabled. Access your files through cPanel File Manager or FTP instead.

A plugin needs xmlrpc.php. Some plugins use XML-RPC for remote access. If you need it, revert the Block access to xmlrpc.php setting.

Related articles

Was this guide helpful?

Need help with this?

Open a ticket and link to this guide so our team can see what you have tried.

View support tickets

Power your business with Ecenica Hosting

Built for WordPress and serious websites. Fast, secure and supported by real people in the UK.

Ecenica hosting services represented by a connected red route across London