Site Lockdown Security is free on WordPress.org Get It Free
Complete Setup & Usage Guide

Master Site Lockdown Security

Follow this guide to configure WP Site Lockdown correctly, review risks, lock down your website safely, monitor file changes, and use every major protection screen included in the plugin.

Unique to WP Site Lockdown

Three things other WordPress security plugins do not give you.

Site Lock, White Label Options, and Redirect Monitor are not hidden upsells or afterthoughts here. They are built directly into WP Site Lockdown so agencies and site owners can lock down file-changing actions, present branded security, and catch hidden redirect attacks from one free plugin.

Overview

Command Center

Use the Command Center as the main security cockpit for the site. It brings infection scan results, folder health, Watch Dog integrity checks, firewall status, lock status, security headers, user security, and login security settings into one view.

DashboardSecurity StatusNext Actions

When to use this:

Open this first after installation, after cleanup, after updates, or any time you need a fast read on whether the site is protected.

How to use it:

  1. Review the Infection Scan panel and open the scanner if suspicious items are found.
  2. Check the Folder & File Health Score and use problem buttons to jump into the affected area.
  3. Review the Watch Dog cards for file changes, core checks, software health, and risk review.
  4. Confirm Site Lock, Security Headers, and User Security status before handing the site back to the client.

Important: Do not lock the site until updates, cleanup, and testing are complete.

Audits

Folder & File Auditor

The main auditor screen summarizes file and folder problems across the installation and gives quick links into specific areas that need review.

Health ScoreProblem ButtonsAudit Hub

When to use this:

Use this before locking the site and after cleanup to make sure expected folders and files are recognized.

How to use it:

  1. Review the score and count of issues.
  2. Click a problem button to inspect the area connected to that warning.
  3. Fix, ignore, include, delete, or allow items based on the actual file review.
  4. Return to this hub and confirm the health score improves.

Important: The score is a guide. Always review the actual file or folder before making destructive changes.

Audits

Content Folder Auditor

Review folders and files detected directly inside wp-content. This helps identify unexpected folders, hidden files, or content that should not be part of a clean site.

wp-contentFolder ReviewIgnore / Include

When to use this:

Use this during setup, after malware cleanup, or when unexpected folders appear inside wp-content.

How to use it:

  1. Scan the listed folders and confirm which ones belong to the site.
  2. Use View or Download where available before making decisions.
  3. Ignore known-safe items that should stop lowering the score.
  4. Delete only confirmed unwanted or malicious items.

Important: Never remove a folder just because it is unfamiliar. Confirm it is not used by a plugin, theme, cache, backup, or custom workflow.

Audits

Plugins Folder Auditor

Inspect plugin directories for unknown items, leftover folders, hidden files, or suspicious content inside the plugins directory.

PluginsUnknown FoldersCleanup Review

When to use this:

Use this when a site has plugin issues, infection warnings, abandoned plugins, or folders left behind after plugin removal.

How to use it:

  1. Compare listed plugin folders with the active and inactive plugin list.
  2. Investigate folders that do not match installed plugins.
  3. Download or view suspicious files before acting.
  4. Ignore valid custom plugin folders only after confirming they are safe.

Important: Custom plugins and mu-plugin helpers can look unfamiliar. Verify ownership before deleting.

Audits

Themes Folder Auditor

Review the themes directory and identify unused themes, modified theme folders, unknown theme directories, or extra files that should be cleaned up.

ThemesUnused CodeFolder Health

When to use this:

Use this when preparing a site for protection or when suspicious files are found inside the themes directory.

How to use it:

  1. Confirm the active theme and any required parent or child themes.
  2. Review inactive themes that may no longer be needed.
  3. Investigate folders that are not recognized as normal themes.
  4. Remove only themes that are confirmed unnecessary and backed up.

Important: Child themes and custom themes may be required even if they do not come from WordPress.org.

Audits

Uploads Folder Auditor

Review uploaded content for executable files, suspicious folders, and unexpected items that often appear when a site has been abused.

UploadsExecutable FilesMedia Safety

When to use this:

Use this after infection cleanup or when the site has a history of file upload abuse.

How to use it:

  1. Look for PHP, script, archive, or executable files inside uploads.
  2. Review unknown folders created outside the normal year/month media structure.
  3. Download suspicious files for manual inspection when needed.
  4. Delete only confirmed malicious files and rerun checks afterward.

Important: Uploads folders are often large. Treat scanner results as leads that need confirmation.

Audits

.htaccess Auditor

Review .htaccess files found within the WordPress installation so redirect rules, access controls, and suspicious injected directives can be inspected.

.htaccessRedirectsAccess Rules

When to use this:

Use this when the site redirects unexpectedly, blocks normal requests, or has recent malware cleanup work.

How to use it:

  1. Locate every .htaccess file found by the auditor.
  2. View or download the file before making changes.
  3. Compare rules against known-good WordPress, plugin, or host rules.
  4. Remove suspicious directives only after confirming they are not required.

Important: A bad .htaccess edit can break the site. Keep a backup before changing rules.

Scanner

Infection Scanner

Run focused scans against WordPress files and database areas to find suspicious items that require review.

Everything ScanPluginsDatabase

When to use this:

Use this during first setup, after suspected infection, after cleanup, and on a maintenance schedule.

How to use it:

  1. Choose Everything for a full site review or select a focused area.
  2. Wait for the scan to finish and review the summary counts.
  3. Open findings and inspect the actual files before deleting or ignoring.
  4. Download a report when results need to be shared with a client, host, or technician.

Important: A scanner finding is a warning that needs review, not automatic proof of malware.

Protection Firewall Protection

Firewall Security

The Firewall Security area inspects suspicious WordPress traffic before it becomes a bigger problem. It includes Smart Block mode, Monitor Only tuning, Emergency Shield, payload and request probes, rate limiting, trusted allowlists, immediate blocklists, Cloudflare edge actions, custom block pages, event timeline logging, and email alerts.

Smart BlockEmergency ShieldCloudflare EdgeEvent Timeline

When to use this:

Use Firewall Security when the site needs active request protection, when a bot or scanner is probing WordPress, or when you want Cloudflare to challenge confirmed bad IPs before repeat requests reach the website.

How to use it:

  1. Start with Monitor Only when tuning rules, then move to Smart Block when you are ready to enforce protection.
  2. Use Emergency Shield only during active attacks or urgent lockdown situations.
  3. Review payload, REST, XML-RPC, rate-limit, and HTTP method protections based on the site type.
  4. Connect Cloudflare to restore the real visitor IP, push confirmed bad IPs to edge challenges, and remove automatic edge rules from the website when needed.
  5. Use the Firewall Event Timeline to review blocked requests, IP status, request URI, and severity without logging internal settings changes.

Important: Emergency Shield is for temporary whole-site attack response. Use Smart Block for normal ongoing protection.

Protection Exclusive Advantage

Site Lock

Site Lock is one of the strongest differentiators in WP Site Lockdown. When it is active, protected actions are blocked so locked files are not changed unexpectedly after cleanup, approval, or client handoff.

Blocked ActionSafety MessageUnlock First

When to use this:

Use this message as confirmation that Site Lock is preventing a file-changing action.

How to use it:

  1. Read the warning before continuing.
  2. Unlock the site only if the change is expected and approved.
  3. Complete the update, installation, deletion, or repair action.
  4. Lock the site again immediately after testing.

Important: This is intentional protection, not an error. Unlock only for planned maintenance.

Protection

Security Headers

Configure browser security headers that help protect visitors and reduce common browser-side attack surfaces.

HeadersBrowser ProtectionPolicy

When to use this:

Use this after the site is stable and ready for hardening.

How to use it:

  1. Enable headers that fit the website and hosting environment.
  2. Test the front end, admin, forms, embeds, and checkout after changes.
  3. Adjust policies if legitimate content is blocked.
  4. Save and verify header output.

Important: Strict headers can break embeds, frames, scripts, or third-party tools when configured too aggressively.

Protection

User Security

Configure account protections that can reduce risk from weak administrator practices, account abuse, and unsafe user behavior.

AdminsUsersLogin Safety

When to use this:

Use this after confirming how administrators, customers, members, or editors normally use the site.

How to use it:

  1. Review each user security option and what it blocks.
  2. Enable settings that match the site’s workflow.
  3. Test administrator login and normal user login after changes.
  4. Document any setting that affects clients, editors, members, or customers.

Important: User security controls should be tested on membership, ecommerce, LMS, and client portal sites before handoff.

Protection

Login Security

Protect the WordPress login screen, customize the login URL, control brute-force protection, review login activity, and revoke active sessions.

Login URLLockoutsSessions

When to use this:

Use this when you want tighter control over how users reach the WordPress login screen and how failed authentication attempts are handled.

How to use it:

  1. Enable a custom login URL when the site should hide the default wp-login.php entry point.
  2. Configure failed-attempt limits, lockout timing, and tracking methods for the login workflow.
  3. Review active lockouts and login activity to understand what is happening at the login screen.
  4. Refresh or revoke active sessions when suspicious access appears or a cleanup handoff requires session control.

Important: Test custom login URLs, lockout settings, and session revocation on staging or during a maintenance window before handing the site back to a client.

Watch Dog

File Change Monitor

File Change Monitor compares current files against the trusted baseline and reports added, modified, or removed files.

Added FilesModified FilesRemoved Files

When to use this:

Use this after updates, cleanup, or suspicious activity to understand exactly what changed.

How to use it:

  1. Create or confirm the baseline before reviewing changes.
  2. Review change groups by added, modified, and removed files.
  3. Confirm expected changes after updates.
  4. Investigate unexpected changes before refreshing the baseline.

Important: Do not refresh the baseline until unexpected changes have been reviewed.

Watch Dog

Core Check

Core Check compares WordPress core files against official checksums to identify modified, missing, or unexpected core files.

WordPress CoreChecksumsIntegrity

When to use this:

Use this when core files may be modified, after cleanup, or as part of regular security maintenance.

How to use it:

  1. Run Core Check from Watch Dog.
  2. Review modified, missing, or unexpected core files.
  3. Replace modified core files with clean copies when appropriate.
  4. Retest after repair to confirm core integrity.

Important: Do not treat wp-content results as core issues. Core Check is focused on WordPress core files.

Watch Dog

Software Health

Software Health checks plugins and themes for maintenance concerns such as outdated, unknown, abandoned, or otherwise risky software.

PluginsThemesMaintenance

When to use this:

Use this during audits and ongoing maintenance to identify software that creates long-term risk.

How to use it:

  1. Run Software Health from Watch Dog.
  2. Review plugins and themes that need attention.
  3. Update, replace, remove, or investigate risky software.
  4. Document exceptions when old software must remain.

Important: A plugin can be functional and still represent maintenance risk if it is abandoned or unknown.

Watch Dog

Risk Review

Risk Review identifies local security concerns that may weaken the site even when malware is not present.

Local RisksHardeningReview

When to use this:

Use this after setup and as part of recurring maintenance reviews.

How to use it:

  1. Run Risk Review from Watch Dog.
  2. Review each local risk item and its status.
  3. Fix risks that can be safely corrected.
  4. Ignore only when the risk is understood and accepted.

Important: Risk review is about reducing exposure, not only removing infections.

Watch Dog Exclusive Advantage

Redirect Monitor

Redirect Monitor is built to catch one of the sneakiest hacked-site behaviors: unauthorized redirects that may only appear for certain visitors, devices, bots, or referral profiles.

Redirect TestsVisitor ProfilesEmail Alerts

When to use this:

Use this after cleanup, after changing redirect rules, or any time you want a quick check for suspicious redirect behavior that may only appear for certain visitors.

How to use it:

  1. Add the important paths or same-site URLs that should be tested.
  2. Add legitimate third-party domains that are allowed redirect destinations.
  3. Choose the scan coverage and schedule that match the site’s risk level.
  4. Run a redirect scan and review grouped findings before taking action.

Important: Add known payment processors, booking systems, and other legitimate third-party destinations to the allowed domains list before treating a redirect as unauthorized.

Watch Dog

Update Monitor

Update Monitor checks WordPress core, installed plugins, and installed themes for pending updates and can send email alerts only when updates are available.

Core UpdatesPlugin UpdatesTheme Updates

When to use this:

Use this for maintenance workflows where you want a focused update check without creating unnecessary email noise when everything is current.

How to use it:

  1. Run the combined update check to review core, plugin, and theme updates together.
  2. Review each pending update and open the update action when maintenance is ready.
  3. Choose a scheduled monitor frequency when recurring checks are needed.
  4. Enable email alerts for the monitored inbox that should receive update notices.

Important: Review updates on a safe maintenance schedule and keep backups available before applying plugin, theme, or core changes.

Tools

Password Reset Enforcement

Require selected user roles to reset their passwords, invalidate active sessions for those users, and send them through the WordPress password reset flow on their next valid login attempt.

Force ResetRole BasedSession Logout

When to use this:

Use this after a cleanup, after a suspected account compromise, when staff changes, or any time selected roles need fresh passwords before they continue using the site.

How to use it:

  1. Select the user roles that should be required to change their passwords.
  2. Leave your own account unchecked unless you intentionally want to include yourself.
  3. Run the enforcement to flag users and invalidate their active sessions.
  4. Use the Current Status panel to review or clear pending enforcement when needed.

Important: Enforcing password resets logs affected users out and blocks normal access until they complete the reset process.

Tools

Public File Exposure Check

Test whether sensitive backup, log, configuration, database, and metadata files are publicly reachable from the website URL, then review only actionable exposed, blocked, redirected, or review-needed paths.

Exposure CheckPublic PathsBackups & Logs

When to use this:

Use this after cleanup, before client handoff, after a migration, or whenever you need to confirm that sensitive files are not exposed publicly.

How to use it:

  1. Check a specific file or path when you know exactly what needs to be tested.
  2. Run the common exposure check to test standard sensitive paths in one pass.
  3. Review critical, warning, blocked, and unknown totals in the summary.
  4. Block or remove any reachable sensitive files, then rerun the check to confirm the fix.

Important: A blocked result means the server is preventing public access. A reachable sensitive file should be removed or blocked immediately.

Tools

File Remover

Quickly search for specific files or file extensions that may need review or removal across the WordPress installation.

Find FilesExtensionsCleanup

When to use this:

Use this when you know a specific filename, extension, or pattern needs to be found quickly.

How to use it:

  1. Search by a specific filename when you know what you are looking for.
  2. Search by extension when investigating risky file types.
  3. Review results carefully before removing anything.
  4. Rerun scanner and auditor checks after cleanup.

Important: Mass-removing files by extension can be risky. Confirm results before deletion.

Tools

Blacklist Check

Review domain and IP reputation details, including transparency and blacklist-style checks useful during cleanup and support tickets.

ReputationDomainIP

When to use this:

Use this when a browser, host, search engine, or client reports warnings about the site.

How to use it:

  1. Run the blacklist check from Security Tools.
  2. Review domain and IP reputation sections.
  3. Save results for the client or hosting provider if escalation is needed.
  4. Retest after cleanup and delisting steps are complete.

Important: Reputation systems can lag after cleanup. A clean site may still need time or a manual review request.

Tools

Plugin Refresher

Replace WordPress.org plugin files with fresh copies when a plugin may be modified, corrupted, or infected.

PluginsFresh InstallRepair

When to use this:

Use this after infection cleanup or when plugin files do not match expected clean versions.

How to use it:

  1. Select the plugin that should be refreshed.
  2. Confirm the plugin comes from WordPress.org and does not contain custom edits.
  3. Run the refresh and test the site afterward.
  4. Rerun scanner and Watch Dog checks to verify improvement.

Important: Do not refresh custom plugins or plugins with direct code modifications unless you have a backup.

Tools

Theme Refresher

Replace WordPress.org theme files with clean copies when a theme may be modified, corrupted, or infected.

ThemesFresh InstallRepair

When to use this:

Use this when theme files are suspected of infection or unwanted edits.

How to use it:

  1. Confirm the theme comes from WordPress.org.
  2. Confirm there are no custom edits that need to be preserved.
  3. Run the refresh and test the front end.
  4. Rerun scanner, auditor, and Watch Dog checks.

Important: Custom child themes and edited commercial themes should not be refreshed blindly.

Tools

Permissions Check

Review WordPress file and folder permissions and compare current values against recommended permissions.

PermissionsFilesFolders

When to use this:

Use this before enabling Site Lock, after a host migration, or when permissions may be too loose.

How to use it:

  1. Run the permissions review from Security Tools.
  2. Review good, medium attention, and high-risk groups.
  3. Correct unsafe permissions through the plugin, hosting tools, or shell access.
  4. Retest after changes to confirm the status.

Important: Permission recommendations can vary by hosting environment. Confirm host requirements when needed.

Tools

SSL Information

Review SSL certificate health, expiration timing, domain coverage, issuer details, and server context from one focused screen.

SSL HealthCertificate DetailsDomain Match

When to use this:

Use this before launch, after DNS or hosting changes, and whenever visitors report certificate or browser trust warnings.

How to use it:

  1. Enter or confirm the website domain.
  2. Run the SSL check and review the health card.
  3. Confirm expiration, domain match, covered names, issuer details, and server IP.
  4. Resolve certificate, CDN, or hosting issues before handoff.

Important: SSL warnings can damage visitor trust quickly, so review certificate status before launch and after DNS or hosting changes.

White Label + Access Control Exclusive Advantage

White Label Options That Make Security Feel Like Yours

White Label Options make WP Site Lockdown stand apart from typical WordPress security plugins. Turn the plugin into a branded security experience for clients by renaming the plugin, updating author details, customizing the menu identity, uploading branded images, and choosing color schemes that match the business.

Client BrandingCustom Plugin NameBrand ColorsAccess Profiles

Why this matters

White labeling lets agencies, freelancers, and support teams present a polished branded security tool inside the WordPress admin area while still keeping the lockdown controls easy for clients to understand.

How to use it:

  1. Choose a brand theme or create a custom color scheme that matches the client brand.
  2. Rename the plugin, admin menu name, author name, and author link.
  3. Upload the brand banner, menu icon, and dark icon used throughout the admin experience.
  4. Use access profiles to decide which administrators can see or manage each protected area.

Client-ready advantage: This is how WP Site Lockdown becomes a professional, white-label security command center instead of another visible third-party tool.

Make WordPress security look like your own platform.

Use the white label controls to deliver a premium branded lockdown experience for every client site.

Get Plugin
Settings

Email Notifications

Configure plugin update notices, security snapshot digests, automated reports, scan results, file change alerts, core alerts, software health alerts, and risk review alerts.

AlertsReportsPreviews

When to use this:

Use this after initial setup so important events are delivered to the right inbox.

How to use it:

  1. Set the default email recipient and global frequencies.
  2. Configure each notification type based on who needs it.
  3. Use Preview to verify email content and layout.
  4. Avoid noisy alert settings that make real warnings easy to miss.

Important: Send important alerts to a monitored inbox, not an unattended account.

GET PROTECTED

Lock down WordPress without opening your wallet

Install Site Lockdown Security and get Premium WordPress protection at no cost.