Master Site Lockdown Security
Follow this guide to configure WP Site Lockdown correctly, review risks, lock down your website safely, monitor file changes, and use every major protection screen included in the plugin.
Three things other WordPress security plugins do not give you.
Site Lock, White Label Options, and Redirect Monitor are not hidden upsells or afterthoughts here. They are built directly into WP Site Lockdown so agencies and site owners can lock down file-changing actions, present branded security, and catch hidden redirect attacks from one free plugin.
Site Lock protection
Lock the site after cleanup so file-changing actions are blocked until maintenance is intentional and approved.
See Site LockWhite label options
Turn security into your branded client platform with custom names, menu identity, colors, icons, and access profiles.
See White LabelRedirect Monitor
Test public pages as different visitor profiles to catch unauthorized redirects that only appear to certain visitors.
See Redirect MonitorCommand Center
Use the Command Center as the main security cockpit for the site. It brings infection scan results, folder health, Watch Dog integrity checks, firewall status, lock status, security headers, user security, and login security settings into one view.
When to use this:
Open this first after installation, after cleanup, after updates, or any time you need a fast read on whether the site is protected.
How to use it:
- Review the Infection Scan panel and open the scanner if suspicious items are found.
- Check the Folder & File Health Score and use problem buttons to jump into the affected area.
- Review the Watch Dog cards for file changes, core checks, software health, and risk review.
- Confirm Site Lock, Security Headers, and User Security status before handing the site back to the client.
Important: Do not lock the site until updates, cleanup, and testing are complete.
Folder & File Auditor
The main auditor screen summarizes file and folder problems across the installation and gives quick links into specific areas that need review.
When to use this:
Use this before locking the site and after cleanup to make sure expected folders and files are recognized.
How to use it:
- Review the score and count of issues.
- Click a problem button to inspect the area connected to that warning.
- Fix, ignore, include, delete, or allow items based on the actual file review.
- Return to this hub and confirm the health score improves.
Important: The score is a guide. Always review the actual file or folder before making destructive changes.
Content Folder Auditor
Review folders and files detected directly inside wp-content. This helps identify unexpected folders, hidden files, or content that should not be part of a clean site.
When to use this:
Use this during setup, after malware cleanup, or when unexpected folders appear inside wp-content.
How to use it:
- Scan the listed folders and confirm which ones belong to the site.
- Use View or Download where available before making decisions.
- Ignore known-safe items that should stop lowering the score.
- Delete only confirmed unwanted or malicious items.
Important: Never remove a folder just because it is unfamiliar. Confirm it is not used by a plugin, theme, cache, backup, or custom workflow.
Plugins Folder Auditor
Inspect plugin directories for unknown items, leftover folders, hidden files, or suspicious content inside the plugins directory.
When to use this:
Use this when a site has plugin issues, infection warnings, abandoned plugins, or folders left behind after plugin removal.
How to use it:
- Compare listed plugin folders with the active and inactive plugin list.
- Investigate folders that do not match installed plugins.
- Download or view suspicious files before acting.
- Ignore valid custom plugin folders only after confirming they are safe.
Important: Custom plugins and mu-plugin helpers can look unfamiliar. Verify ownership before deleting.
Themes Folder Auditor
Review the themes directory and identify unused themes, modified theme folders, unknown theme directories, or extra files that should be cleaned up.
When to use this:
Use this when preparing a site for protection or when suspicious files are found inside the themes directory.
How to use it:
- Confirm the active theme and any required parent or child themes.
- Review inactive themes that may no longer be needed.
- Investigate folders that are not recognized as normal themes.
- Remove only themes that are confirmed unnecessary and backed up.
Important: Child themes and custom themes may be required even if they do not come from WordPress.org.
Uploads Folder Auditor
Review uploaded content for executable files, suspicious folders, and unexpected items that often appear when a site has been abused.
When to use this:
Use this after infection cleanup or when the site has a history of file upload abuse.
How to use it:
- Look for PHP, script, archive, or executable files inside uploads.
- Review unknown folders created outside the normal year/month media structure.
- Download suspicious files for manual inspection when needed.
- Delete only confirmed malicious files and rerun checks afterward.
Important: Uploads folders are often large. Treat scanner results as leads that need confirmation.
.htaccess Auditor
Review .htaccess files found within the WordPress installation so redirect rules, access controls, and suspicious injected directives can be inspected.
When to use this:
Use this when the site redirects unexpectedly, blocks normal requests, or has recent malware cleanup work.
How to use it:
- Locate every .htaccess file found by the auditor.
- View or download the file before making changes.
- Compare rules against known-good WordPress, plugin, or host rules.
- Remove suspicious directives only after confirming they are not required.
Important: A bad .htaccess edit can break the site. Keep a backup before changing rules.
Infection Scanner
Run focused scans against WordPress files and database areas to find suspicious items that require review.
When to use this:
Use this during first setup, after suspected infection, after cleanup, and on a maintenance schedule.
How to use it:
- Choose Everything for a full site review or select a focused area.
- Wait for the scan to finish and review the summary counts.
- Open findings and inspect the actual files before deleting or ignoring.
- Download a report when results need to be shared with a client, host, or technician.
Important: A scanner finding is a warning that needs review, not automatic proof of malware.
Firewall Security
The Firewall Security area inspects suspicious WordPress traffic before it becomes a bigger problem. It includes Smart Block mode, Monitor Only tuning, Emergency Shield, payload and request probes, rate limiting, trusted allowlists, immediate blocklists, Cloudflare edge actions, custom block pages, event timeline logging, and email alerts.
When to use this:
Use Firewall Security when the site needs active request protection, when a bot or scanner is probing WordPress, or when you want Cloudflare to challenge confirmed bad IPs before repeat requests reach the website.
How to use it:
- Start with Monitor Only when tuning rules, then move to Smart Block when you are ready to enforce protection.
- Use Emergency Shield only during active attacks or urgent lockdown situations.
- Review payload, REST, XML-RPC, rate-limit, and HTTP method protections based on the site type.
- Connect Cloudflare to restore the real visitor IP, push confirmed bad IPs to edge challenges, and remove automatic edge rules from the website when needed.
- Use the Firewall Event Timeline to review blocked requests, IP status, request URI, and severity without logging internal settings changes.
Important: Emergency Shield is for temporary whole-site attack response. Use Smart Block for normal ongoing protection.
Site Lock
Site Lock is one of the strongest differentiators in WP Site Lockdown. When it is active, protected actions are blocked so locked files are not changed unexpectedly after cleanup, approval, or client handoff.
When to use this:
Use this message as confirmation that Site Lock is preventing a file-changing action.
How to use it:
- Read the warning before continuing.
- Unlock the site only if the change is expected and approved.
- Complete the update, installation, deletion, or repair action.
- Lock the site again immediately after testing.
Important: This is intentional protection, not an error. Unlock only for planned maintenance.
Security Headers
Configure browser security headers that help protect visitors and reduce common browser-side attack surfaces.
When to use this:
Use this after the site is stable and ready for hardening.
How to use it:
- Enable headers that fit the website and hosting environment.
- Test the front end, admin, forms, embeds, and checkout after changes.
- Adjust policies if legitimate content is blocked.
- Save and verify header output.
Important: Strict headers can break embeds, frames, scripts, or third-party tools when configured too aggressively.
User Security
Configure account protections that can reduce risk from weak administrator practices, account abuse, and unsafe user behavior.
When to use this:
Use this after confirming how administrators, customers, members, or editors normally use the site.
How to use it:
- Review each user security option and what it blocks.
- Enable settings that match the site’s workflow.
- Test administrator login and normal user login after changes.
- Document any setting that affects clients, editors, members, or customers.
Important: User security controls should be tested on membership, ecommerce, LMS, and client portal sites before handoff.
Login Security
Protect the WordPress login screen, customize the login URL, control brute-force protection, review login activity, and revoke active sessions.
When to use this:
Use this when you want tighter control over how users reach the WordPress login screen and how failed authentication attempts are handled.
How to use it:
- Enable a custom login URL when the site should hide the default wp-login.php entry point.
- Configure failed-attempt limits, lockout timing, and tracking methods for the login workflow.
- Review active lockouts and login activity to understand what is happening at the login screen.
- Refresh or revoke active sessions when suspicious access appears or a cleanup handoff requires session control.
Important: Test custom login URLs, lockout settings, and session revocation on staging or during a maintenance window before handing the site back to a client.
File Change Monitor
File Change Monitor compares current files against the trusted baseline and reports added, modified, or removed files.
When to use this:
Use this after updates, cleanup, or suspicious activity to understand exactly what changed.
How to use it:
- Create or confirm the baseline before reviewing changes.
- Review change groups by added, modified, and removed files.
- Confirm expected changes after updates.
- Investigate unexpected changes before refreshing the baseline.
Important: Do not refresh the baseline until unexpected changes have been reviewed.
Core Check
Core Check compares WordPress core files against official checksums to identify modified, missing, or unexpected core files.
When to use this:
Use this when core files may be modified, after cleanup, or as part of regular security maintenance.
How to use it:
- Run Core Check from Watch Dog.
- Review modified, missing, or unexpected core files.
- Replace modified core files with clean copies when appropriate.
- Retest after repair to confirm core integrity.
Important: Do not treat wp-content results as core issues. Core Check is focused on WordPress core files.
Software Health
Software Health checks plugins and themes for maintenance concerns such as outdated, unknown, abandoned, or otherwise risky software.
When to use this:
Use this during audits and ongoing maintenance to identify software that creates long-term risk.
How to use it:
- Run Software Health from Watch Dog.
- Review plugins and themes that need attention.
- Update, replace, remove, or investigate risky software.
- Document exceptions when old software must remain.
Important: A plugin can be functional and still represent maintenance risk if it is abandoned or unknown.
Risk Review
Risk Review identifies local security concerns that may weaken the site even when malware is not present.
When to use this:
Use this after setup and as part of recurring maintenance reviews.
How to use it:
- Run Risk Review from Watch Dog.
- Review each local risk item and its status.
- Fix risks that can be safely corrected.
- Ignore only when the risk is understood and accepted.
Important: Risk review is about reducing exposure, not only removing infections.
Redirect Monitor
Redirect Monitor is built to catch one of the sneakiest hacked-site behaviors: unauthorized redirects that may only appear for certain visitors, devices, bots, or referral profiles.
When to use this:
Use this after cleanup, after changing redirect rules, or any time you want a quick check for suspicious redirect behavior that may only appear for certain visitors.
How to use it:
- Add the important paths or same-site URLs that should be tested.
- Add legitimate third-party domains that are allowed redirect destinations.
- Choose the scan coverage and schedule that match the site’s risk level.
- Run a redirect scan and review grouped findings before taking action.
Important: Add known payment processors, booking systems, and other legitimate third-party destinations to the allowed domains list before treating a redirect as unauthorized.
Update Monitor
Update Monitor checks WordPress core, installed plugins, and installed themes for pending updates and can send email alerts only when updates are available.
When to use this:
Use this for maintenance workflows where you want a focused update check without creating unnecessary email noise when everything is current.
How to use it:
- Run the combined update check to review core, plugin, and theme updates together.
- Review each pending update and open the update action when maintenance is ready.
- Choose a scheduled monitor frequency when recurring checks are needed.
- Enable email alerts for the monitored inbox that should receive update notices.
Important: Review updates on a safe maintenance schedule and keep backups available before applying plugin, theme, or core changes.
Password Reset Enforcement
Require selected user roles to reset their passwords, invalidate active sessions for those users, and send them through the WordPress password reset flow on their next valid login attempt.
When to use this:
Use this after a cleanup, after a suspected account compromise, when staff changes, or any time selected roles need fresh passwords before they continue using the site.
How to use it:
- Select the user roles that should be required to change their passwords.
- Leave your own account unchecked unless you intentionally want to include yourself.
- Run the enforcement to flag users and invalidate their active sessions.
- Use the Current Status panel to review or clear pending enforcement when needed.
Important: Enforcing password resets logs affected users out and blocks normal access until they complete the reset process.
Public File Exposure Check
Test whether sensitive backup, log, configuration, database, and metadata files are publicly reachable from the website URL, then review only actionable exposed, blocked, redirected, or review-needed paths.
When to use this:
Use this after cleanup, before client handoff, after a migration, or whenever you need to confirm that sensitive files are not exposed publicly.
How to use it:
- Check a specific file or path when you know exactly what needs to be tested.
- Run the common exposure check to test standard sensitive paths in one pass.
- Review critical, warning, blocked, and unknown totals in the summary.
- Block or remove any reachable sensitive files, then rerun the check to confirm the fix.
Important: A blocked result means the server is preventing public access. A reachable sensitive file should be removed or blocked immediately.
File Remover
Quickly search for specific files or file extensions that may need review or removal across the WordPress installation.
When to use this:
Use this when you know a specific filename, extension, or pattern needs to be found quickly.
How to use it:
- Search by a specific filename when you know what you are looking for.
- Search by extension when investigating risky file types.
- Review results carefully before removing anything.
- Rerun scanner and auditor checks after cleanup.
Important: Mass-removing files by extension can be risky. Confirm results before deletion.
Blacklist Check
Review domain and IP reputation details, including transparency and blacklist-style checks useful during cleanup and support tickets.
When to use this:
Use this when a browser, host, search engine, or client reports warnings about the site.
How to use it:
- Run the blacklist check from Security Tools.
- Review domain and IP reputation sections.
- Save results for the client or hosting provider if escalation is needed.
- Retest after cleanup and delisting steps are complete.
Important: Reputation systems can lag after cleanup. A clean site may still need time or a manual review request.
Plugin Refresher
Replace WordPress.org plugin files with fresh copies when a plugin may be modified, corrupted, or infected.
When to use this:
Use this after infection cleanup or when plugin files do not match expected clean versions.
How to use it:
- Select the plugin that should be refreshed.
- Confirm the plugin comes from WordPress.org and does not contain custom edits.
- Run the refresh and test the site afterward.
- Rerun scanner and Watch Dog checks to verify improvement.
Important: Do not refresh custom plugins or plugins with direct code modifications unless you have a backup.
Theme Refresher
Replace WordPress.org theme files with clean copies when a theme may be modified, corrupted, or infected.
When to use this:
Use this when theme files are suspected of infection or unwanted edits.
How to use it:
- Confirm the theme comes from WordPress.org.
- Confirm there are no custom edits that need to be preserved.
- Run the refresh and test the front end.
- Rerun scanner, auditor, and Watch Dog checks.
Important: Custom child themes and edited commercial themes should not be refreshed blindly.
Permissions Check
Review WordPress file and folder permissions and compare current values against recommended permissions.
When to use this:
Use this before enabling Site Lock, after a host migration, or when permissions may be too loose.
How to use it:
- Run the permissions review from Security Tools.
- Review good, medium attention, and high-risk groups.
- Correct unsafe permissions through the plugin, hosting tools, or shell access.
- Retest after changes to confirm the status.
Important: Permission recommendations can vary by hosting environment. Confirm host requirements when needed.
SSL Information
Review SSL certificate health, expiration timing, domain coverage, issuer details, and server context from one focused screen.
When to use this:
Use this before launch, after DNS or hosting changes, and whenever visitors report certificate or browser trust warnings.
How to use it:
- Enter or confirm the website domain.
- Run the SSL check and review the health card.
- Confirm expiration, domain match, covered names, issuer details, and server IP.
- Resolve certificate, CDN, or hosting issues before handoff.
Important: SSL warnings can damage visitor trust quickly, so review certificate status before launch and after DNS or hosting changes.
White Label Options That Make Security Feel Like Yours
White Label Options make WP Site Lockdown stand apart from typical WordPress security plugins. Turn the plugin into a branded security experience for clients by renaming the plugin, updating author details, customizing the menu identity, uploading branded images, and choosing color schemes that match the business.
Why this matters
White labeling lets agencies, freelancers, and support teams present a polished branded security tool inside the WordPress admin area while still keeping the lockdown controls easy for clients to understand.
How to use it:
- Choose a brand theme or create a custom color scheme that matches the client brand.
- Rename the plugin, admin menu name, author name, and author link.
- Upload the brand banner, menu icon, and dark icon used throughout the admin experience.
- Use access profiles to decide which administrators can see or manage each protected area.
Client-ready advantage: This is how WP Site Lockdown becomes a professional, white-label security command center instead of another visible third-party tool.
Use the white label controls to deliver a premium branded lockdown experience for every client site.
Get PluginRecommended Setup
Recommended Setup guides the user through the most important setup items before the site is considered fully protected.
When to use this:
Use this during first-time setup and before client handoff.
How to use it:
- Work through each recommended setup card.
- Set alert frequencies and delivery email addresses.
- Create baselines only after cleanup and review are finished.
- Return to the setup screen until critical items are complete.
Important: Dismissed items should still be revisited before final handoff.
Email Notifications
Configure plugin update notices, security snapshot digests, automated reports, scan results, file change alerts, core alerts, software health alerts, and risk review alerts.
When to use this:
Use this after initial setup so important events are delivered to the right inbox.
How to use it:
- Set the default email recipient and global frequencies.
- Configure each notification type based on who needs it.
- Use Preview to verify email content and layout.
- Avoid noisy alert settings that make real warnings easy to miss.
Important: Send important alerts to a monitored inbox, not an unattended account.
Site Lockdown Security is free on WordPress.org

