The Security Tab: Score, Hardening and File Checks
Read your security score, switch on the hardening options and scan your files for tampering.
Every WordPress app on the OpenLiteSpeed template has a Security tab. It has seven sections in a menu on the left: Overview, Sign-in, Firewall, Under Attack, Updates & scans, Hardening and Activity. This article covers the Overview, Hardening and file checks. The other sections have their own articles: sign-in protection and firewall, blocking and Under Attack mode.
Apply to site
Switches on the Security tab are drafts until you press Apply to site in the bar at the bottom. The bar tells you how many changes are waiting and has a Discard button. FlyNode installs a small must-use plugin called FlyNode Security on your site. You can see it in WP Admin under Plugins, Must-Use tab; it has no menu of its own, all settings are in this tab. Pressing Apply also updates the plugin to the newest version.
The score
The Overview shows a score out of 100 and a list of what needs attention. It checks, among other things, that WordPress, plugins and themes are up to date, that no user is called admin, that the site address uses HTTPS, that debug mode is off, that the PHP version still gets security fixes, that administrators use two-factor sign-in, and that the protections on this tab are switched on. Items with a Fix button switch the protection on for you (press Apply to site afterwards). Items with Open take you to the right section.
Hardening
The Hardening section has one switch for each of these:
- Turn off the theme and plugin editor: nobody can edit site code from inside WP Admin, even after a stolen login.
- Block XML-RPC: closes the old remote-access door used to guess passwords in bulk. Turn it off only if an app such as the WordPress mobile app needs it.
- Never run PHP from the uploads folder: a malicious upload can no longer run as code.
- Protect backups, logs and version files: blocks downloads of .sql, .bak, .log and .git files and readme.html.
- Hide the WordPress version.
- Hide login names: stops visitors listing usernames through
?author=1and the REST API. - Send security headers: protection against clickjacking and content sniffing.
- Force HTTPS in browsers (HSTS): browsers remember for a year to use only HTTPS. Switch it on only when your whole site works over HTTPS. It is not part of "Turn on all recommended".
File integrity scan
In Updates & scans, Scan now checks WordPress core files and your plugins' files against the official versions, and looks for PHP files in the uploads folder and for known malware signatures. Common harmless leftovers, such as error_log files, are grouped so they do not bury real findings, and you can delete the error logs from the same place.
A file you do not trust can be quarantined. That moves it out of your site; it is not deleted, and you can put it back from the quarantine list.
A scan is a check, not a cleanup service. If it finds modified core files or unknown PHP in uploads, take a backup, restore the core files or the plugin from a clean copy, change your passwords, and look at the activity log for how it happened.
On a staging copy the Security tab only shows updates; settings and scans are managed on the live site.
Still stuck?
Open a support ticket from your dashboard and include the container name.