App workflow WordPress

Configure Site Security PRO

Follow the paid feature setup documentation and validate its status and boundaries. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Read this guide as Markdown

Requirements and responsibilities

Illustrative situation

A client with a critical membership plugin is considering Site Security PRO while a vendor fix is pending. The agency must evaluate subscription, coverage and possible false blocks.

Choose the approach

Dashboard and application procedure

Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.

Step 1 of 5

Confirm eligibility and scope

Where
xCloud site and Site Security PRO panel
Permissions
Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
Inputs
Client site ID, current plan, affected plugin
Action
Open the named WordPress site's vulnerability panel and inspect the currently offered PRO features and billing terms.
Expected result
A reviewed option tied to one site.
Verify
Compare dashboard offer with client approval and affected component.
If it fails
If the panel is unavailable or price differs from a prior note, pause for current terms.

Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · Vulnerability Checker in xCloud · Site Security PRO setup and eligibility

Step 2 of 5

Capture a functional baseline

Where
Membership site and security logs
Permissions
Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
Inputs
Login, registration and renewal test accounts
Action
Run representative legitimate actions before protection changes. Record response and any existing security events.
Expected result
A baseline for detecting false positives.
Verify
Confirm test users can sign in and complete the allowed flow.
If it fails
If baseline already fails, resolve that issue before attributing later failures to PRO.

Sources: Manage WordPress plugins · Site Security PRO setup and eligibility

Step 3 of 5

Approve and enable protection

Where
xCloud Site Security PRO dashboard
Permissions
Authorized xCloud site owner with dashboard rights for the exact setting, backup, staging or restore action and a reviewed target.
Inputs
Named site, subscription approval, feature settings
Action
After explicit client approval for the displayed cost, enable PRO on the named site. Inspect the Vulnerabilities, Reports and Protection Modules views.
Expected result
PRO state visible for the intended site.
Verify
Confirm subscription and current module state in the dashboard.
If it fails
If activation stalls, do not assume rules are active; contact xCloud support with site ID.

Sources: Manage WordPress core, themes and plugins · xCloud agent capability boundaries · Site Security PRO setup and eligibility

Step 4 of 5

Test rules and business flows

Where
Membership application and PRO event views
Permissions
Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
Inputs
Legitimate login and renewal test
Action
Repeat the baseline journey, then compare protection events with expected requests. Investigate any blocked legitimate action before release.
Expected result
Protection enabled without observed business-flow regression.
Verify
Match request time to protection log and membership result.
If it fails
If a false block occurs, review rule handling with support rather than disabling all security silently.

Sources: Manage WordPress plugins · Site Security PRO setup and eligibility

Step 5 of 5

Plan eventual plugin fix

Where
Vendor advisory and agency change record
Permissions
Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
Inputs
Fixed version, test plan, owner
Action
Document a future plugin update or replacement when available. Record which staging and membership tests must pass before virtual mitigation can be retired.
Expected result
A permanent-remediation path with a named owner.
Verify
Review the vendor release and current installed version at the next window.
If it fails
If no fix emerges, reassess exposure and replacement instead of leaving an indefinite unowned exception.

Sources: Manage WordPress plugins · Create a staging environment in xCloud

Maintenance

Recovery decisions

AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

Supported scope

  • Confirm requirements and inspect resources mcp · read

    Discover the connected profile and operation schema first; only teams granted to the connection are visible.

    Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.

    Operation identifiers and scopes to discover

    teams.index, servers.show, sites.show

    Scopes: read:servers, read:sites

    xCloud MCP documentation and connection profiles · xCloud agent capability boundaries

Copyable agent brief

Manual checkpoints

  • Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
  • An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
  • Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
  • Reconcile data created after the chosen recovery point before any destructive restore.
Feature coverage

Sources

Continue

Explore all use cases