Security

WordPress security, managed from day one.

MagicWP starts with secure defaults — automatic HTTPS and a managed firewall — then gives you a Security Center to harden each site with a switch. No fragile plugin stacks, no server configuration.

Automatic HTTPS
SSL, provisioned & renewed
Managed firewall
baseline, always on
Login protection
curb brute-force
Security headers
browser-level defense
Private database
not publicly exposed
Backups & restore
recover in one click
Secure defaults for every site

Protection at the platform level.

Security should not depend on a stack of fragile plugins. Core protections run for you; simple controls cover the common WordPress attack surfaces.

Automatic HTTPS

Provisioned and renewed for you

Baseline firewall

Enabled and managed by default

Disable XML-RPC

Close a common abuse vector

Login protection

Restrict wp-admin & wp-login

Security headers

Clickjacking & MIME defenses

Real IP

See the true client in logs

Private database

Never exposed to the internet

Backups & snapshots

Restore after risky changes

How it works

Secure by default, hardened on demand.

Automatic HTTPS

Every site served over HTTPS.

Your default MagicWP domain is HTTPS-ready, and connecting a custom domain provisions its SSL certificate automatically. Nothing to buy, upload, or renew by hand.

  • Protects visitor connections
  • No “Not Secure” warnings
  • Auto-renewing certificates
  • HTTPS on custom domains
https://yoursite.comSecure
SSL certificate
yoursite.com
Active
IssuerLet's Encrypt
Auto-renewOn · 60 days
ProtocolTLS 1.3 · HTTP/3
Managed firewall

A protection layer before you configure a thing.

A baseline firewall is enabled by default and managed automatically, so every site launches with a layer of protection already in place — one less task on the checklist.

  • On by default
  • Managed & updated for you
  • Blocks common abuse
  • No rules to write
Managed firewall
yoursite.com
Active
Request filteringbaseline firewall
brute-forcebad botsmalicious payloads
real visitorslegit crawlerstrusted APIs
Security Center

Hardening toggles that apply instantly.

Strengthen your site without server configuration or manual edits. Each switch takes effect immediately — turn on exactly the protections your site needs.

  • Disable XML-RPC
  • Protect wp-includes
  • Login Page Protection
  • Security Headers & Real IP
Hardening postureyoursite.com
100%
Fully hardened
All five protections active — each toggle applied instantly, no server config.
Live
Disable XML-RPCProtect wp-includesLogin ProtectionSecurity HeadersReal IP
Safer access & recovery

Protect the parts visitors never see.

Security is not only the public site — it is file access, database access, and getting back a good state when something goes wrong.

Private database

Each site gets its own MySQL-compatible database, never exposed to the public internet.

Temporary phpMyAdmin

Open time-boxed phpMyAdmin access from the dashboard when you need to inspect the database.

Secure SFTP

SFTP over SSH for themes, plugins, uploads, and config — with direct access kept protected.

Backups & restore

Automated daily backups, monthly retention, and on-demand snapshots — full, files, or database only.

Recommended setup

A strong starting point for most sites.

1Keep HTTPS enabledrecommended
2Use the managed baseline firewallrecommended
3Disable XML-RPC unless an integration needs itrecommended
4Enable Security Headersrecommended
5Enable Real IPrecommended
6Add Login Page Protectionrecommended
7Add wp-includes protection for extra hardeningrecommended
Recovery matters too

Security is also getting a good state back.

Prevention is only half of it. Automated backups and on-demand snapshots let you restore a site after a bad update, migration, file edit, or database change.

Backup types

Back up exactly what you need, on a schedule or on demand — and restore in a click from the dashboard.

What's included
Full backupFiles-onlyDatabase-only
Schedules
Automated dailyMonthly retainedOn-demand snapshots
Restore pointsyoursite.com
Today · 03:00Automated daily · 1.24 GBFullRestore
Before plugin updateOn-demand snapshotSnapshotRestore
Yesterday · 03:00Automated daily · 1.21 GBFullRestore
3 days ago · 03:00Automated dailyDatabaseRestore
Last monthMonthly retained · 1.18 GBFullRestore
Use cases

Built for WordPress teams.

Harden the attack surface, keep HTTPS active, reduce brute-force exposure, and recover from risky changes — from one dashboard.

Launching a new site

Start with HTTPS, firewall protection, and secure defaults already in place.

Hardening a project

Turn on XML-RPC protection, headers, login protection, and Real IP from the Security Center.

Protecting client sites

Give every client site a consistent baseline without custom server work.

Making risky changes

Snapshot before plugin updates, database edits, file changes, or migrations.

FAQ

Security questions, answered.

Does MagicWP include HTTPS?
Yes. MagicWP provides HTTPS for the default MagicWP domain and handles SSL for connected custom domains — provisioned and auto-renewed for you.
Is the firewall enabled by default?
Yes. Every site includes a baseline firewall that is enabled by default and managed automatically.
Can I disable XML-RPC?
Yes. The Security Center includes a Disable XML-RPC toggle. It is recommended for most sites unless a specific tool requires XML-RPC.
Can I protect the WordPress login page?
Yes. Login Page Protection restricts direct access to wp-admin and wp-login.php from unauthorized requests.
Which security headers are supported?
MagicWP can add X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, and Referrer-Policy.
Is the database public?
No. Each site's database is private and not exposed directly to the public internet. Temporary phpMyAdmin access is available from the dashboard when needed.

Protect WordPress without extra complexity.

Launch on MagicWP with HTTPS, firewall protection, hardening controls, secure access, and backups built in.