Understanding WP Toolkit Security Notifications

You may occasionally receive an email from cPanel with a subject such as:

“Site vulnerabilities found”

These notifications are automatically generated by WP Toolkit, the WordPress management system available within cPanel. They are intended to alert you when a known security vulnerability has been identified in your WordPress installation, plugins or themes.

Is the email genuine?

Emails sent from your hosting server and referring to WP Toolkit are generally legitimate automated notifications from cPanel.

However, you do not need to click any links contained in the email. To check the warning safely:

  1. Log directly into your Hoopla Hosting account.

  2. Open your cPanel service.

  3. Select WP Toolkit under the Domains section.

  4. Locate the affected website and review the listed vulnerabilities.

You can also log directly into your WordPress Dashboard and select Dashboard → Updates.

Does this mean my website has been hacked?

No. A vulnerability notification does not mean that your website has already been compromised.

It means that WP Toolkit has identified a version of WordPress, a plugin or a theme that has a publicly reported security issue.

Terms such as High or Critical describe the potential seriousness of the vulnerability. They do not confirm that the vulnerability has been exploited on your website.

You should still investigate and resolve the warning as soon as reasonably possible.

What component is affected?

The notification will normally identify one of the following:

WordPress Core

This refers to WordPress itself.

Install the latest security update offered through:

WordPress Dashboard → Updates

or:

cPanel → WP Toolkit

You may not always need to upgrade to the newest major WordPress version. WordPress sometimes releases security fixes for older supported version branches.

For example, a notification may refer to a vulnerability fixed in WordPress 7.x while a separate patched release is also available for websites running WordPress 6.x. Install the latest update offered for your website, then allow WP Toolkit to scan the site again.

WordPress Plugin

Update the affected plugin from:

WordPress Dashboard → Plugins

If no patched update is available, the safest option is normally to disable and remove the plugin until an updated version becomes available.

If the plugin is required for an important website function, contact your website developer before removing it.

WordPress Theme

Update the affected theme from:

WordPress Dashboard → Appearance → Themes

Unused themes should be removed, except for one current default WordPress theme that may be retained for troubleshooting.

If the vulnerable theme is your active theme and no update is available, contact your website developer for assistance.

All my plugins are updated. Why am I still receiving alerts?

The warning may relate to:

  • WordPress core rather than a plugin.

  • Your active WordPress theme.

  • An inactive plugin or theme that remains installed.

  • A vulnerability for which no patched update is currently available.

  • A warning detected before an update was completed.

  • A cached result awaiting WP Toolkit’s next scan.

  • Another WordPress website within the same cPanel account.

Open WP Toolkit and check the specific website and component named in the warning.

What should I do before updating?

Most routine WordPress security updates complete without difficulty. However, updates can occasionally cause compatibility problems with older themes, plugins or custom website code.

Before making significant updates:

  1. Confirm that a recent website backup is available.

  2. Update WordPress, plugins and themes.

  3. Test the website after updating.

  4. Check important functions such as forms, online ordering and customer login areas.

Websites using custom development, older plugins or heavily modified themes should be reviewed by the website’s developer.

Why do the emails keep repeating?

WP Toolkit may continue sending notifications while the vulnerable component remains installed.

You may also receive additional emails when:

  • A new vulnerability is discovered.

  • More than one website is affected.

  • Several vulnerable components are installed.

  • A vulnerability remains unresolved after a scan.

  • A security update has only recently become available.

After applying the appropriate updates, WP Toolkit should clear the warning following a subsequent scan.

Can I disable these notifications?

This particular WP Toolkit vulnerability notification cannot currently be disabled from an individual cPanel account.

These notifications are intended to provide early warning of potentially serious WordPress security issues. We therefore recommend resolving the reported vulnerability rather than ignoring the notification.

When should I contact my website developer?

Contact your website developer when:

  • An update causes part of the website to stop working.

  • No secure update is available for an essential plugin or theme.

  • The website contains custom plugins or custom theme development.

  • You are unsure whether a major WordPress upgrade is compatible.

  • The website displays errors after an update.

  • You suspect that the website may already have been compromised.

What support does Hoopla Hosting provide?

Hoopla Hosting provides the hosting platform, cPanel and access to WP Toolkit.

Website maintenance—including testing updates, replacing unsupported plugins, resolving compatibility problems and repairing website code—is normally the responsibility of the website owner or their web developer.

If WP Toolkit continues showing a vulnerability after all available updates have been installed, please contact Hoopla Hosting and include:

  • The affected domain name.

  • The component named in the warning.

  • The currently installed version.

  • A screenshot or copy of the notification.

We can then check whether WP Toolkit is still detecting an outdated component or whether its vulnerability information has not yet refreshed.

Was this answer helpful? 0 Users Found This Useful (0 Votes)