{"id":18365,"date":"2026-09-29T21:06:30","date_gmt":"2026-09-29T18:06:30","guid":{"rendered":"https:\/\/www.hyyat.com\/knowledgebase\/wordpress-vulnerability-scan-wp-toolkit\/"},"modified":"2026-09-29T21:06:30","modified_gmt":"2026-09-29T18:06:30","password":"","slug":"wordpress-vulnerability-scan-wp-toolkit","status":"publish","type":"docs","link":"https:\/\/www.hyyat.com\/en\/knowledgebase\/wordpress-vulnerability-scan-wp-toolkit\/","title":{"rendered":"How to Scan WordPress for Vulnerabilities and Secure It with WP Toolkit"},"content":{"rendered":"<div class=\"hy-tldr\" style=\"background:#f6f7fb;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:0 0 20px;line-height:1.8\"><strong>In short:<\/strong> The most common WordPress attacks are brute force, DDoS through XML-RPC, vulnerable plugins and themes, and code injection. WordPress Toolkit in cPanel (Applications section) scans your site and applies security measures such as blocking PHP execution in uploads, turning off pingbacks and protecting wp-config, and it updates WordPress and plugins from one place.<\/div>\n<p>WordPress is the most used content management system on the web, and that popularity has a price: it is also the most attacked. Not because it is insecure, but because one WordPress vulnerability opens the door to millions of sites. As soon as a WordPress site goes online, automated bots start checking it for weaknesses.<\/p>\n<p>Security hardening used to be long and manual, but <strong>WordPress Toolkit for cPanel<\/strong> makes it one click. See also what WordPress Toolkit is.<\/p>\n<h2>Common WordPress vulnerabilities<\/h2>\n<ul>\n<li><strong>Brute force and dictionary attacks:<\/strong> bots try to guess usernames and passwords, flooding the login with attempts.<\/li>\n<li><strong>DoS and DDoS attacks:<\/strong> attackers flood the site with requests to use up resources and slow it down or take it offline. WordPress&#8217;s XML-RPC system is often abused for this.<\/li>\n<li><strong>Core, plugin and theme vulnerabilities:<\/strong> bugs in code can be used to bypass logins, upload malicious code or gain extra privileges.<\/li>\n<li><strong>Code injection:<\/strong> attackers look for weaknesses that let them inject PHP, JavaScript or SQL code.<\/li>\n<\/ul>\n<h2>Security check with WordPress Toolkit<\/h2>\n<p>WordPress Toolkit is a complete WordPress management tool in cPanel: one dashboard for all your WordPress sites that automates installation, updates and backups. It checks for critical weaknesses during installation, and scans existing sites for weak security settings that you can fix with one click. Some measures can affect how certain plugins work, so apply them carefully or ask our support.<\/p>\n<p>You will find WordPress Toolkit under <strong>Applications<\/strong> on the cPanel home page. Your sites appear with their status and settings. If a site shows an orange warning next to <strong>Security<\/strong>, some recommended measures are not applied yet.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2020\/12\/2020-12-08_14-57-41.jpg\" alt=\"WordPress Toolkit in cPanel\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2020\/12\/2020-12-08_15-08-27.jpg\" alt=\"WordPress Toolkit security measures\" \/><\/p>\n<h2>Key security measures<\/h2>\n<ul>\n<li><strong>Block PHP execution<\/strong> in wp-includes and wp-content\/uploads, a common target for uploaded malicious files.<\/li>\n<li><strong>Block directory browsing<\/strong> and set secure permissions for wp-config.php and other files.<\/li>\n<li><strong>Bot protection<\/strong> to block bad bots that scan your site and waste resources.<\/li>\n<li><strong>Change the default &#8220;admin&#8221; username<\/strong>, which bots target in brute force attacks.<\/li>\n<li><strong>Turn off pingbacks<\/strong>, which rely on XML-RPC and can be abused in DoS attacks.<\/li>\n<li><strong>Hotlink protection<\/strong> to stop other sites from using your images and bandwidth.<\/li>\n<\/ul>\n<p>WordPress Toolkit also makes it easy to update WordPress core, plugins and themes from one screen and to enable automatic updates. Regular updates are the most important way to close known vulnerabilities.<\/p>\n<p class=\"hy-svc-link\" style=\"background:#fff5f7;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:20px 0;line-height:1.8\"><strong>Related service:<\/strong> <a href=\"https:\/\/www.hyyat.com\/en\/wordpress-hosting\/\">Hyyat Host WordPress hosting<\/a> is optimized and secured for WordPress, from $1.93\/month with free SSL.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In short: The most common WordPress attacks are brute force, DDoS through XML-RPC, vulnerable plugins and themes, and code injection. WordPress Toolkit in cPanel (Applications section) scans your site and applies security measures such as blocking PHP execution in uploads, turning off pingbacks and protecting wp-config, and it updates WordPress and plugins from one place. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"_eb_attr":"","inline_featured_image":false,"wprm-recipe-roundup-name":"","wprm-recipe-roundup-description":"","_templately_pack_id":"","_templately_imported_at":"","_templately_source":"","_templately_import_session_id":"","footnotes":""},"doc_category":[2222],"doc_tag":[],"class_list":["post-18365","docs","type-docs","status-publish","hentry","doc_category-2222"],"year_month":"2026-10","word_count":450,"total_views":0,"reactions":{"happy":0,"normal":0,"sad":0},"author_info":{"name":"admin","author_nicename":"admin","author_url":"https:\/\/www.hyyat.com\/en\/author\/admin\/"},"doc_category_info":[{"term_name":"\u0634\u0631\u0648\u062d\u0627\u062a \u0648\u0648\u0631\u062f\u0628\u0631\u064a\u0633","term_url":"https:\/\/www.hyyat.com\/kb\/%d8%b4%d8%b1%d9%88%d8%ad%d8%a7%d8%aa-%d9%88%d9%88%d8%b1%d8%af%d8%a8%d8%b1%d9%8a%d8%b3\/"}],"doc_tag_info":[],"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18365","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/comments?post=18365"}],"version-history":[{"count":0,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18365\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/media?parent=18365"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_category?post=18365"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_tag?post=18365"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}