Keeping your WordPress sites secure shouldn’t feel like rocket science, and with WP Umbrella, it doesn’t. This guide walks you through how to utilise our core security features, including Site health, Hardening, and Vulnerabilities. It also covers the advanced tools available through our paid security add-on, which gives you access to Malware scanning, a Firewall, and an Activity Log.
These tools work together to help you identify threats early, fix weak points, and automatically apply protections without compromising your site’s performance.
Estimated Time to Complete: 2 minutes
Prerequisites:
WP Umbrella plugin installed on your WordPress website
Access to your WP Umbrella account
(Optional but recommended) Security add-on enabled
Log into WP Umbrella and click on Security.

Instantly see if any plugins, themes, or the WordPress core have known vulnerabilities. Each entry includes:
Severity level
Update status
Recommended action
This lets you react before attackers can exploit these issues.

This section flags potential security risks related to your hosting environment or WordPress settings that your client can actually see and not understand. WP Umbrella highlights and explains:
SSL certificate status
WordPress & PHP version warnings
Inactive plugins/themes
WP_DEBUG status

You’ll also get actionable recommendations for fixing each issue.
For maximum protection enable the paid security add-on. The firewall applies virtual patches and blocks common attack vectors, removing the need for heavy security plugins without slowing your site down. Once it is activated, WP Umbrella starts blocking malicious traffic straight away, with no extra configuration needed. It also includes malware scanner, activity log and additional hardening options.

Here’s everything it protects against automatically:
Features | What It Does | Why It Matters |
Vulnerability Virtual Patching Firewal | Automatically blocks known vulnerabilities in WordPress core/themes/plugins and common attack vectors. | Prevents exploits before updates are applied or released. This helps you to protect your websites from new malwares and common attacks |
Disable Theme/File Editors | Removes built-in editors from the WP admin | Prevents attackers from injecting malicious code (and your clients from doing crazy stuff) |
Block readme.txt / WP version meta | Hides WordPress version info | Avoids being targeted by bots |
Disable User Enumeration | Stops attackers from discovering usernames | Defends against brute-force logins |
Restrict XML-RPC Access | Allows XML-RPC only for authenticated users | Reduces spam and attack surface |
Security Headers | Adds headers like X-Frame-Options, X-XSS-Protection | Defends against clickjacking, XSS, and more |
Block debug.log & sample config files | Prevents access to sensitive information from the debug.log file | Keeps internal configs private |
Disable Index Views | Blocks directory listing | Prevents accidental file exposure |
Block Proxy Comment Posting | Disables comments via third-party services | Reduces spam and abuse attempts |
Malware Scanning | Runs automated scans across your site files | Flags injected code and backdoors |
Activity Log | Records every login, user, plugin, theme, core and settings change, and flags brute-force, privilege escalation, unusual sign-ins and file tampering as they happen | Gives you full accountability to know who did what, from which IP and when, so you can investigate faster. |
The standard Hardening settings secure your site by hiding sensitive info, adding security headers, and disabling risky WordPress behaviours with zero performance impact. If you enable the premium Security add-on, the Firewall brings in virtual patching to actively block known vulnerabilities.
Unlike bulky plugins that often slow down your site, WP Umbrella is lightweight and built directly in. You get hardening, malware scanning, activity logging, and firewall protection all from one platform, without needing extra plugins installed.
Included with the paid Firewall, virtual patching protects your site by blocking known vulnerabilities the moment they are disclosed. It acts as a safety layer to prevent exploits before an official update is even released.
Between the Hardening and Firewall features, your site is protected against exploits in outdated software, user enumeration, and brute-force attacks via XML-RPC. It also stops access to sensitive files like readme.txt and debug.log, prevents proxy comment posting, defends against clickjacking, and stops file editor abuse within wp-admin.
Yes! Just click the "Rescan your site" button inside the Security bulk monitoring tab. Or it will get automatically scanned on daily basis.
Go through each item listed and update your plugins, themes, or WordPress core as needed. If you’re unsure, reach out to our friendly support team!
If WP_DEBUG is enabled on a live site, it can expose sensitive information. WP Umbrella lets you know if it's on so you can disable it when necessary.
Security is no longer something you can set and forget — but with WP Umbrella, it can be simple, automated, and reliable. 🎉
Whether you’re managing one website or a hundred, WP Umbrella gives you everything you need to monitor, fix, and prevent security issues — without the clutter of bloated plugins.