There was a problem loading the comments.

Securing WordPress with WordPress Toolkit in Plesk

Support Portal  »  Knowledgebase  »  Viewing Article

  Print

Step 1: Log in to Plesk

Open your browser and go to:

https://yourdomain.com:8443

Sign in with your hosting credentials.

ec5d5716ca4783e85e962cd2042718c16e05b314d20693ab94393234580ba2db6ec33b050efd4ad0?t=1d462ca30cc9f63ab2ff634a7e023cfc


Step 2: Open WordPress Toolkit

  1. In the left-hand menu, click WordPress

  2. You’ll see a list of all WordPress installations on your account


Step 3: Select the Site You Want to Secure

  1. Find the WordPress site you want to protect

  2. Click the small arrow to expand options

  3. Click “View” or just click the site’s name to open its details


Step 4: Click the “Check Security” Button

Inside the site’s dashboard, look for:

Security Status
Click “Check Security”

Plesk will scan your website and show a list of recommended protections.

35845b7a2f0decabffc7eef7af43ad5c88fe49a4242d96d2d4f0a24bb3506f6a0143b0e2b98fca6d?t=1e18963510efb90eb4c738b3d9d910cf


Step 5: Apply Recommended Security Measures

After the scan, you’ll see several security options you can enable:

Security Option What It Does
Disable file editing Prevents hackers from editing files through WP admin
Block access to wp-config.php Protects your configuration file from being read
Block access to .htaccess Secures your server configuration file
Disable directory browsing Prevents visitors from viewing folder contents
Restrict wp-content access Stops direct file access (e.g. PHP) in media folders
Security keys reset (optional) Generates new authentication keys

Just check the boxes for what you want to apply, then click “Secure”

ba2f66e26ed6a2cc98547b7dabed540a73db16e407afb78c63459c2e430f4d2446b316364af17550?t=83893b6cc188f048c0131e7020e18e3d


Step 6: Review Status After Applying

Once done:

  • The panel will show which actions were applied successfully

  • Any issues or skipped items will show with a warning or red icon

  • You can recheck security at any time


Step 7: Keep Security Features Enabled

Plesk’s WordPress Toolkit settings stay active unless changed. No need to redo them every day — but you can come back anytime to:

  • Reapply if settings are lost after a plugin/theme update

  • Review if you reinstall WordPress

  • Check security after a migration


Bonus Tips for a More Secure WordPress Site

Best Practice Why It Matters
Use strong passwords Prevents brute-force login attempts
Enable auto-updates for plugins/themes Fixes vulnerabilities as soon as they’re patched
Back up regularly So you can restore your site after an attack
Avoid outdated themes/plugins These are common hacker entry points
Limit login attempts or use CAPTCHA Stops bots from guessing your password

Share via
Did you find this article useful?  

Related Articles


Comments

Add Comment

Replying to  

CAPTCHA

On-Premise Help Desk Software by SupportPal
© Support Portal - WP Lighthost