Protection levels and key levels
Two kinds of level decide what gets through. A protection level decides what every visitor may send to a site. A key level decides what an API key or an app connected over MCP may do in the panel.
Protection levels
Section titled “Protection levels”| Level | In short |
|---|---|
| Off | No rules and no limits. The site is served exactly as it would be without Security. |
| Standard | Refuses requests no visitor makes - secret files, PHP in uploads, scanners - and limits logins and request rates generously. |
| Strict | Standard, plus XML-RPC and outside wp-cron refused, tighter limits, more headers, and no plugin installs from wp-admin. |
The tables show each level as it ships. The fleet default and a site’s own settings can change any row on top of its level, except under Off, which nothing switches back on.
Refused requests
Section titled “Refused requests”A refused request gets a 403, whoever sends it.
| What it is | Off | Standard | Strict | |
|---|---|---|---|---|
| Sensitive files | .env and .git, wp-config backups, debug.log and SQL dumps. Nothing a visitor ever asks for, and the first thing a scanner does. | Allowed | Refused | Refused |
| PHP in uploads | A PHP file under wp-content/uploads is how most break-ins end: an upload that runs. Media never needs to. | Allowed | Refused | Refused |
| Install scripts | wp-admin/install.php and setup-config.php, which only an unfinished install needs. | Allowed | Refused | Refused |
| Scanner user agents | Tools that announce themselves - sqlmap, Nikto, WPScan, Nuclei and the like. | Allowed | Refused | Refused |
| User enumeration | /?author=N and the REST users list to anyone not signed in: how login names are harvested for guessing. | Allowed | Refused | Refused |
| XML-RPC | Requests to xmlrpc.php. | Allowed | Limited | Refused |
| wp-cron.php from outside | Requests to wp-cron.php from the internet. The panel runs WordPress cron itself. | Allowed | Allowed | Refused |
Rate limits
Section titled “Rate limits”Each limit counts per visitor address. The burst is how many requests may arrive at once before the rate applies.
| What it is | Off | Standard | Strict | |
|---|---|---|---|---|
| Login attempts | POST requests to wp-login.php, per address. Keep the burst small: Traefik gives a visitor who pauses a few seconds a full burst again. | No limit | 20 a minute, bursts of 2 | 6 a minute, bursts of 2 |
| XML-RPC | Requests to xmlrpc.php, per address. Jetpack’s servers are never limited. Keep the burst small, as for logins. | No limit | 30 a minute, bursts of 2 | No limit |
| Requests | Everything else, per address. | No limit | 50 a second, bursts of 500 | 10 a second, bursts of 100 |
| Assets | Stylesheets, scripts, images and fonts under wp-content and wp-includes, per address. | No limit | 200 a second, bursts of 4,000 | 100 a second, bursts of 1,000 |
Headers
Section titled “Headers”| What it is | Off | Standard | Strict | |
|---|---|---|---|---|
| X-Content-Type-Options | nosniff: a browser runs a file as what the server says it is, never as what it looks like. | Not sent | Sent | Sent |
| X-Frame-Options | SAMEORIGIN: other sites cannot show this one in a frame. Embeds of this site elsewhere stop working. | Not sent | Not sent | Sent |
| Strict-Transport-Security | Browsers use HTTPS only, for a year. Hard to undo once sent: only for a site that stays on HTTPS. | Not sent | Not sent | Sent |
| Referrer-Policy | strict-origin-when-cross-origin: other sites learn which site a visitor came from, not which page. | Not sent | Not sent | Sent |
Inside the site
Section titled “Inside the site”| What it is | Off | Standard | Strict | |
|---|---|---|---|---|
| No PHP in uploads | Apache will not run a PHP file under wp-content/uploads. Set outside the site, so its own .htaccess cannot switch it back on. | Off | On | On |
| No file editor | Removes the theme and plugin editor from wp-admin, so a stolen admin login cannot rewrite PHP with it. | Off | On | On |
| No installs from wp-admin | Plugins and themes cannot be installed or updated from wp-admin. Updates from the panel keep working. | Off | Off | On |
Key levels
Section titled “Key levels”An API key, and an app connected over MCP, has one of three levels. The levels nest: Manage can do everything Read only can, and Full everything Manage can. Someone signed in to the panel always has Full.
| Level | What it may do | Endpoints it reaches | Endpoints that need exactly it |
|---|---|---|---|
| Read only | See sites, servers, jobs, backups, the WordPress inventory, mail, traffic and settings, and list files. Never a file’s contents, a command’s output or a password. | 72 | 72 |
| Manage | Also work inside every site as its WordPress admin could: create sites; plugins, themes and core; WP-CLI, shell and REST calls; files; WordPress and FTP logins; backups and restores; each site’s protection, malware scans and quarantine; custom schedules. It can read whatever a site holds, licence keys included, and what it sets up in a site stays when you revoke it. | 154 | 82 |
| Full | Everything: also the panel itself (servers, settings, mail and DNS, offsite destinations, the plugin catalog, recipes and the keys entered for them, the blocked addresses), the backup policy (backup schedules, deleting backups, switching them off), deleting or moving sites, and updating the panel. | 228 | 74 |
The counts are of the 228 endpoints that need a key. 6 more answer without one: GET /api/health, POST /api/auth/login, POST /api/auth/login/totp, POST /api/auth/forgot-password, POST /api/auth/reset-password, POST /api/auth/confirm-email.
Each endpoint’s level is in the API reference. A request above the key’s level is refused with 403, and the answer names both levels.