Product docs

Security Center Documentation

Set up local WordPress security reviews, login protection, firewall controls, file-integrity checks, incidents, and optional cloud-connected security workflows.

Scope

Security Center is local-first, so setup guidance must separate free in-admin checks from optional cloud policy, monitoring, reporting, and response features.

For: WordPress administrators and agencies responsible for security review and response.

  • Free local checks remain useful without a paid plan or cloud connection.
  • Public SiteCheck output is not a private vulnerability assessment.
  • Do not publish raw scan payloads, report tokens, debug output, or internal paths.

Workflow

Setup and operating notes

Install And Review Locally

Install the WordPress plugin, open the Security Center area in wp-admin, and start with local checks for suspicious file changes, public-risk indicators, risky configuration, administrator drift, uploads, debug logs, and component changes.

Configure Protections

Use login protection, firewall rate-limiting and temporary blocking controls, incidents, audit views, and email notifications where they fit the site.

Connect Cloud Carefully

Cloud-assisted checks, policy sync, command polling, scheduled reports, virtual patching, and incident workflows belong to the connected plan layer when the active entitlement allows them.

Verified Sources

Where these claims come from