WP Toolkit 6.10.0 — cPanel & WHM Update
Security Risk ratings for WordPress sites and components WP Toolkit now introduces a Security Risk rating for WordPress sites and individual components. This rating helps administrators quickly identify which vulnerable sites or plugins require attention first. As part of this change, the previous Vulnerabilities wi…
Affected Versions
6.10.0
Security Risk ratings for WordPress sites and components WP Toolkit now introduces a Security Risk rating for WordPress sites and individual components. This rating helps administrators quickly identify which vulnerable sites or plugins require attention first. As part of this change, the previous Vulnerabilities wi…
WP Toolkit 6.10.0
2026 April 14
Security Risk ratings for WordPress sites and components
WP Toolkit now introduces a Security Risk rating for WordPress sites and individual components. This rating helps administrators quickly identify which vulnerable sites or plugins require attention first.
As part of this change, the previous Vulnerabilities widget was replaced with a new Security Risk widget, and the WordPress Vulnerabilities tab was redesigned and renamed to Vulnerable Components. The new tab displays installed WordPress components along with their Security Risk ratings. Selecting a component expands the view to show detailed information about the underlying vulnerabilities.
WP Toolkit now uses the Security Risk rating throughout the interface, including:
- Site cards, where the Vulnerabilities label was replaced with a Security Risk label.
- The Mass Security screen, which now shows site information in a separate tab with a dedicated Security Risk column.
- Email notifications, which were redesigned to focus on Security Risk rating changes rather than raw vulnerability counts.
WordPress installations can now be sorted by Security Risk, allowing administrators to prioritize remediation more efficiently.
As part of this redesign, the Ignore Low‑Risk Vulnerabilities feature was removed, as it is no longer meaningful when Security Risk ratings are used.
Redesigned WP Toolkit plugin interface
WP Toolkit includes a redesigned WordPress integration plugin UI to support the new Security Risk feature and related workflows.
Administrators can now:
- Change autoupdate settings directly from the WP Toolkit plugin.
- Purchase Vulnerability Protection directly from within the plugin.
To customize the Vulnerability Protection purchase URL on cPanel servers, set the following option in the /usr/local/cpanel/3rdparty/wp-toolkit/var/etc/config.ini file:
whmVirtualPatchesUpsellUrl = <custom URL>
For improved security, WP Toolkit now uses secure one‑time login links when logging in to WordPress from WP Toolkit.
The WP Toolkit link inside the WordPress admin interface was also moved under the Dashboard menu by default.
Mass plugin rollout and automated site scanning
WP Toolkit can now mass‑install the WP Toolkit plugin on all existing WordPress sites on a server.
To enable this behavior, add the following line to the /usr/local/cpanel/3rdparty/wp-toolkit/var/etc/config.ini file:
rolloutIntegrationPluginToExistingSites = true
Plugin installation is rate‑limited to 100 sites per hour to avoid excessive server load.
This option will be enabled by default on all cPanel servers purchased via retail channels.
WP Toolkit can now also scan automatically for new WordPress instances every 24 hours. To enable scheduled scans, add the following line to the /usr/local/cpanel/3rdparty/wp-toolkit/var/etc/config.ini file:
scanInstancesPeriodically = true
Improvements to plugins, themes, and filtering
WP Toolkit now includes improved filtering capabilities:
- Plugins and Themes tabs on site cards now support filtering by component name.
- Global Plugins and Themes screens can be filtered by domain and component name.
Cron behavior and update improvements
Server administrators can now control how often wp-cron.php scheduled tasks run by default using the wpCronFrequency configuration option. The default frequency was changed from once per hour to every five minutes.
The Take over wp-cron.php option will now always create a replacement scheduled task automatically.
Smart Update and Smart PHP Update now generate text logs for successful prognoses, rather than only for failed updates.
Performance and reliability improvements
WP Toolkit now pre‑downloads the latest WordPress archive on clean installation and refreshes it once per day.
Performance was improved for the following operations:
- Site data refresh
- Switching themes
- Activating or deactivating plugins
WP Toolkit plugin performance was improved.
The default HTTP timeout for connections to wordpress.org was increased from 15 seconds to 60 seconds. Multiple security‑related improvements were also implemented.
Other changes
- The
wp-cli instance infocommand now also displays the minor WordPress version available for update. - A new WordPress Security widget was added to the WHM Home screen.
- WP Guardian (cPanel addon) – 50-site pack is now available for purchase from the cPanel Store.
- WP Toolkit log files are now correctly rotated when ProtectSystem is set to full.
- WP Toolkit now works correctly on CloudLinux 9 Solo.
- Ongoing Smart Update or Smart PHP Update tasks no longer block access to the WP Toolkit interface under certain conditions.
- CLI option
-passwordis now fully deprecated for security reasons. Use theADMIN_PASSWORDenvironmental variable instead.
Bug fixes
This release includes multiple fixes that improve Smart Update reliability, WordPress cloning and copying, UTF‑8 handling in the UI, and plugin activation workflows.
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System