Skip to content
Start a Project
Menu
Rooted Dev Studio

Rooted Dev Studio Security Toolkit Documentation

Start here

Rooted Dev Studio Security Toolkit Pro adds advanced investigation, monitoring, containment, and reporting tools to Rooted Dev Studio Security Toolkit. Install and activate the free plugin first, then install Pro and activate your license.

Before making security changes: Create a current off-site backup and confirm you can access your hosting control panel or file manager.

Installation

  1. Install and activate Rooted Dev Studio Security Toolkit.
  2. Upload the Rooted Dev Studio Security Toolkit Pro ZIP package provided with your purchase under Plugins → Add Plugin → Upload Plugin.
  3. Activate Rooted Dev Studio Security Toolkit Pro.
  4. Open the Rooted Dev Studio Security Toolkit Pro license screen, enter your license key, and activate it for this website.
  5. Open Rooted Dev Studio Security Toolkit and review the dashboard before enabling additional controls.

Recommended first setup

  1. Run the security health checks and read each recommendation.
  2. Configure login lockout thresholds for your site.
  3. Enable two-factor authentication for administrator accounts and store recovery codes safely.
  4. Create a trusted file baseline after confirming the site is clean and current.
  5. Create a trusted security-configuration baseline.
  6. Review trusted devices and active WordPress sessions.

Dashboard and security score

The dashboard summarizes WordPress configuration checks and preventative hardening. A score is a practical guide, not proof that a website is free from compromise. Review failed and critical checks before making changes.

Two-factor authentication

Each user configures two-factor authentication from their own WordPress profile using a time-based authenticator app. Scan the QR code, verify a newly generated six-digit code, and securely store the recovery codes shown after setup.

If a verification code is rejected

Login protection

Login lockouts temporarily block repeated failed sign-in attempts. Test this feature with a temporary non-administrator account and a separate browser. Keep hosting access available while testing.

Trusted devices and sessions

Trusted Devices lets a signed-in user recognize the current browser without weakening normal login requirements. The Sessions screen helps administrators review and revoke active WordPress sessions.

File intelligence

Create a trusted fingerprint only after reviewing the current installation. Manual scans compare monitored files against that baseline and classify expected software activity, planned maintenance, and unexplained changes.

Maintenance windows

Open a maintenance window before intentionally editing plugin or theme files. Choose the narrowest scope and shortest practical duration. A maintenance window explains activity; it does not automatically make a file safe.

Suspicious-code scan

The selected pattern scan identifies code patterns that deserve review. A match is not proof of malware, and a clean scan is not proof that every malware family is absent.

Security drift

Security Drift compares important WordPress settings with a trusted configuration baseline. Review changes to public registration, active plugins, user privileges, and other monitored settings before trusting a new baseline.

Incident correlation

Related authentication, administration, file, and configuration events are grouped into an incident view. Use the evidence and surrounding administrator activity to determine whether a change was expected.

Emergency Lockdown

Emergency Lockdown captures an incident snapshot before temporarily blocking high-risk administration and remote authentication paths. It is a containment aid, not proof of compromise or a replacement for professional incident response.

Do not test Lockdown without recovery access. Confirm you can reach your hosting file manager and follow the Emergency Recovery guide included with the customer package.

Incident snapshots and reports

Snapshots preserve local evidence summaries without including passwords, authentication cookies, session tokens, database credentials, API keys, or WordPress secret salts. Security Reports provide filtered review and JSON or CSV exports.

Updates and support

An active Pro license provides Rooted Dev Studio Security Toolkit Pro updates and customer support. Rooted Dev Studio Security Toolkit is updated separately through WordPress.org after directory approval.

Need help? Contact support@rooteddevstudio.com and include the WordPress version, PHP version, Rooted Dev Studio Security Toolkit versions, and the exact message shown. Do not email passwords, license secrets, recovery codes, or private keys.