Skip to content
How to install

Protection levels and key levels

Two kinds of level decide what gets through. A protection level decides what every visitor may send to a site. A key level decides what an API key or an app connected over MCP may do in the panel.

Level In short
Off No rules and no limits. The site is served exactly as it would be without Security.
Standard Refuses requests no visitor makes - secret files, PHP in uploads, scanners - and limits logins and request rates generously.
Strict Standard, plus XML-RPC and outside wp-cron refused, tighter limits, more headers, and no plugin installs from wp-admin.

The tables show each level as it ships. The fleet default and a site’s own settings can change any row on top of its level, except under Off, which nothing switches back on.

A refused request gets a 403, whoever sends it.

What it is Off Standard Strict
Sensitive files .env and .git, wp-config backups, debug.log and SQL dumps. Nothing a visitor ever asks for, and the first thing a scanner does. Allowed Refused Refused
PHP in uploads A PHP file under wp-content/uploads is how most break-ins end: an upload that runs. Media never needs to. Allowed Refused Refused
Install scripts wp-admin/install.php and setup-config.php, which only an unfinished install needs. Allowed Refused Refused
Scanner user agents Tools that announce themselves - sqlmap, Nikto, WPScan, Nuclei and the like. Allowed Refused Refused
User enumeration /?author=N and the REST users list to anyone not signed in: how login names are harvested for guessing. Allowed Refused Refused
XML-RPC Requests to xmlrpc.php. Allowed Limited Refused
wp-cron.php from outside Requests to wp-cron.php from the internet. The panel runs WordPress cron itself. Allowed Allowed Refused

Each limit counts per visitor address. The burst is how many requests may arrive at once before the rate applies.

What it is Off Standard Strict
Login attempts POST requests to wp-login.php, per address. Keep the burst small: Traefik gives a visitor who pauses a few seconds a full burst again. No limit 20 a minute, bursts of 2 6 a minute, bursts of 2
XML-RPC Requests to xmlrpc.php, per address. Jetpack’s servers are never limited. Keep the burst small, as for logins. No limit 30 a minute, bursts of 2 No limit
Requests Everything else, per address. No limit 50 a second, bursts of 500 10 a second, bursts of 100
Assets Stylesheets, scripts, images and fonts under wp-content and wp-includes, per address. No limit 200 a second, bursts of 4,000 100 a second, bursts of 1,000
What it is Off Standard Strict
X-Content-Type-Options nosniff: a browser runs a file as what the server says it is, never as what it looks like. Not sent Sent Sent
X-Frame-Options SAMEORIGIN: other sites cannot show this one in a frame. Embeds of this site elsewhere stop working. Not sent Not sent Sent
Strict-Transport-Security Browsers use HTTPS only, for a year. Hard to undo once sent: only for a site that stays on HTTPS. Not sent Not sent Sent
Referrer-Policy strict-origin-when-cross-origin: other sites learn which site a visitor came from, not which page. Not sent Not sent Sent
What it is Off Standard Strict
No PHP in uploads Apache will not run a PHP file under wp-content/uploads. Set outside the site, so its own .htaccess cannot switch it back on. Off On On
No file editor Removes the theme and plugin editor from wp-admin, so a stolen admin login cannot rewrite PHP with it. Off On On
No installs from wp-admin Plugins and themes cannot be installed or updated from wp-admin. Updates from the panel keep working. Off Off On

An API key, and an app connected over MCP, has one of three levels. The levels nest: Manage can do everything Read only can, and Full everything Manage can. Someone signed in to the panel always has Full.

Level What it may do Endpoints it reaches Endpoints that need exactly it
Read only See sites, servers, jobs, backups, the WordPress inventory, mail, traffic and settings, and list files. Never a file’s contents, a command’s output or a password. 72 72
Manage Also work inside every site as its WordPress admin could: create sites; plugins, themes and core; WP-CLI, shell and REST calls; files; WordPress and FTP logins; backups and restores; each site’s protection, malware scans and quarantine; custom schedules. It can read whatever a site holds, licence keys included, and what it sets up in a site stays when you revoke it. 154 82
Full Everything: also the panel itself (servers, settings, mail and DNS, offsite destinations, the plugin catalog, recipes and the keys entered for them, the blocked addresses), the backup policy (backup schedules, deleting backups, switching them off), deleting or moving sites, and updating the panel. 228 74

The counts are of the 228 endpoints that need a key. 6 more answer without one: GET /api/health, POST /api/auth/login, POST /api/auth/login/totp, POST /api/auth/forgot-password, POST /api/auth/reset-password, POST /api/auth/confirm-email.

Each endpoint’s level is in the API reference. A request above the key’s level is refused with 403, and the answer names both levels.