Start here
Rooted Dev Studio Security Toolkit Pro adds advanced investigation, monitoring, containment, and reporting tools to Rooted Dev Studio Security Toolkit. Install and activate the free plugin first, then install Pro and activate your license.
Installation
- Install and activate Rooted Dev Studio Security Toolkit.
- Upload the Rooted Dev Studio Security Toolkit Pro ZIP package provided with your purchase under Plugins → Add Plugin → Upload Plugin.
- Activate Rooted Dev Studio Security Toolkit Pro.
- Open the Rooted Dev Studio Security Toolkit Pro license screen, enter your license key, and activate it for this website.
- Open Rooted Dev Studio Security Toolkit and review the dashboard before enabling additional controls.
Recommended first setup
- Run the security health checks and read each recommendation.
- Configure login lockout thresholds for your site.
- Enable two-factor authentication for administrator accounts and store recovery codes safely.
- Create a trusted file baseline after confirming the site is clean and current.
- Create a trusted security-configuration baseline.
- Review trusted devices and active WordPress sessions.
Dashboard and security score
The dashboard summarizes WordPress configuration checks and preventative hardening. A score is a practical guide, not proof that a website is free from compromise. Review failed and critical checks before making changes.
Two-factor authentication
Each user configures two-factor authentication from their own WordPress profile using a time-based authenticator app. Scan the QR code, verify a newly generated six-digit code, and securely store the recovery codes shown after setup.
If a verification code is rejected
- Confirm the authenticator entry is time based.
- Confirm the phone time is set automatically.
- Wait for a fresh code rather than reusing one that is about to expire.
- Replace the authenticator entry if a new setup key was generated.
Login protection
Login lockouts temporarily block repeated failed sign-in attempts. Test this feature with a temporary non-administrator account and a separate browser. Keep hosting access available while testing.
Trusted devices and sessions
Trusted Devices lets a signed-in user recognize the current browser without weakening normal login requirements. The Sessions screen helps administrators review and revoke active WordPress sessions.
File intelligence
Create a trusted fingerprint only after reviewing the current installation. Manual scans compare monitored files against that baseline and classify expected software activity, planned maintenance, and unexplained changes.
Maintenance windows
Open a maintenance window before intentionally editing plugin or theme files. Choose the narrowest scope and shortest practical duration. A maintenance window explains activity; it does not automatically make a file safe.
Suspicious-code scan
The selected pattern scan identifies code patterns that deserve review. A match is not proof of malware, and a clean scan is not proof that every malware family is absent.
Security drift
Security Drift compares important WordPress settings with a trusted configuration baseline. Review changes to public registration, active plugins, user privileges, and other monitored settings before trusting a new baseline.
Incident correlation
Related authentication, administration, file, and configuration events are grouped into an incident view. Use the evidence and surrounding administrator activity to determine whether a change was expected.
Emergency Lockdown
Emergency Lockdown captures an incident snapshot before temporarily blocking high-risk administration and remote authentication paths. It is a containment aid, not proof of compromise or a replacement for professional incident response.
Incident snapshots and reports
Snapshots preserve local evidence summaries without including passwords, authentication cookies, session tokens, database credentials, API keys, or WordPress secret salts. Security Reports provide filtered review and JSON or CSV exports.
Updates and support
An active Pro license provides Rooted Dev Studio Security Toolkit Pro updates and customer support. Rooted Dev Studio Security Toolkit is updated separately through WordPress.org after directory approval.
Need help? Contact support@rooteddevstudio.com and include the WordPress version, PHP version, Rooted Dev Studio Security Toolkit versions, and the exact message shown. Do not email passwords, license secrets, recovery codes, or private keys.
