You may occasionally receive an email from cPanel with a subject such as:
“Site vulnerabilities found”
These notifications are automatically generated by WP Toolkit, the WordPress management system available within cPanel. They are intended to alert you when a known security vulnerability has been identified in your WordPress installation, plugins or themes.
Is the email genuine?
Emails sent from your hosting server and referring to WP Toolkit are generally legitimate automated notifications from cPanel.
However, you do not need to click any links contained in the email. To check the warning safely:
- Log directly into your Hoopla Hosting account.
- Open your cPanel service.
- Select WP Toolkit under the Domains section.
- Locate the affected website and review the listed vulnerabilities.
You can also log directly into your WordPress Dashboard and select Dashboard → Updates.
Does this mean my website has been hacked?
No. A vulnerability notification does not mean that your website has already been compromised.
It means that WP Toolkit has identified a version of WordPress, a plugin or a theme that has a publicly reported security issue.
Terms such as High or Critical describe the potential seriousness of the vulnerability. They do not confirm that the vulnerability has been exploited on your website.
You should still investigate and resolve the warning as soon as reasonably possible.
What component is affected?
The notification will normally identify one of the following.
WordPress core
This refers to WordPress itself. Install the latest security update offered through WordPress Dashboard → Updates or cPanel → WP Toolkit.
You may not always need to upgrade to the newest major WordPress version. WordPress sometimes releases security fixes for older supported version branches. For example, a notification may refer to a vulnerability fixed in WordPress 7.x while a separate patched release is also available for websites running WordPress 6.x. Install the latest update offered for your website, then allow WP Toolkit to scan the site again.
WordPress plugin
Update the affected plugin from WordPress Dashboard → Plugins.
If no patched update is available, the safest option is normally to disable and remove the plugin until an updated version becomes available. If the plugin is required for an important website function, contact your website developer before removing it.
WordPress theme
Update the affected theme from WordPress Dashboard → Appearance → Themes.
Unused themes should be removed, except for one current default WordPress theme that may be retained for troubleshooting. If the vulnerable theme is your active theme and no update is available, contact your website developer for assistance.
All my plugins are updated. Why am I still receiving alerts?
The warning may relate to:
- WordPress core rather than a plugin.
- Your active WordPress theme.
- An inactive plugin or theme that remains installed.
- A vulnerability for which no patched update is currently available.
- A warning detected before an update was completed.
- A cached result awaiting WP Toolkit’s next scan.
- Another WordPress website within the same cPanel account.
Open WP Toolkit and check the specific website and component named in the warning.
What should I do before updating?
Most routine WordPress security updates complete without difficulty. However, updates can occasionally cause compatibility problems with older themes, plugins or custom website code.
Before making significant updates:
- Confirm that a recent website backup is available. See Restore files, databases or email from a backup.
- Update WordPress, plugins and themes.
- Test the website after updating.
- Check important functions such as forms, online ordering and customer login areas.
Websites using custom development, older plugins or heavily modified themes should be reviewed by the website’s developer.
Why do the emails keep repeating?
WP Toolkit may continue sending notifications while the vulnerable component remains installed.
You may also receive additional emails when:
- A new vulnerability is discovered.
- More than one website is affected.
- Several vulnerable components are installed.
- A vulnerability remains unresolved after a scan.
- A security update has only recently become available.
After applying the appropriate updates, WP Toolkit should clear the warning following a subsequent scan.
How can I stop or reduce these alerts?
The alerts stop once WP Toolkit no longer detects a vulnerable component, so the most effective way to reduce them is to fix what they report:
- Update or remove the vulnerable component. Update the plugin, theme or WordPress core named in the alert. If no fixed version is available, disable and remove it. Once WP Toolkit rescans the site, alerts for that component will stop.
- Remove what you don't use. Inactive plugins and themes still trigger alerts. Deleting them, along with any old or test WordPress sites in the same cPanel account, reduces the number of alerts you receive.
- Turn on automatic updates. In cPanel → WP Toolkit, open the website's update settings and enable automatic updates for plugins, themes and WordPress core. You can also set WP Toolkit to take automatic action when a vulnerability is detected. Security fixes are then applied without waiting for you. If your website relies on custom or older plugins, check with your developer first and make sure you have a recent backup.
- Send the alerts to someone else. Alerts are sent to the contact email address on your cPanel account. If a web developer looks after your website, you can change this address in cPanel → Contact Information so the alerts go to them instead.
- Detach the website from WP Toolkit. If you or your developer look after WordPress updates and security another way, you can stop WP Toolkit monitoring the website. In cPanel → WP Toolkit, open the menu for the website and select Detach. WP Toolkit will stop scanning that website and sending alerts about it. Your website, files and database are not affected. However, you will also lose WP Toolkit's update management and vulnerability checks for that website, so only detach it if its security is being looked after elsewhere. You can add the website back at any time by selecting Scan in WP Toolkit.
There is no setting to switch these alerts off while a website remains in WP Toolkit. They provide early warning of security issues that can allow attackers to take over or deface a website, so we recommend resolving the reported vulnerability rather than ignoring it.
Note: Some alert emails include a link to WHM's Contact Manager. That page is for server administrators and isn't available on web hosting accounts, so you can ignore that link.
When should I contact my website developer?
Contact your website developer when:
- An update causes part of the website to stop working.
- No secure update is available for an essential plugin or theme.
- The website contains custom plugins or custom theme development.
- You are unsure whether a major WordPress upgrade is compatible.
- The website displays errors after an update.
- You suspect that the website may already have been compromised.
What support does Hoopla Hosting provide?
Hoopla Hosting provides the hosting platform, cPanel and access to WP Toolkit.
Website maintenance, including testing updates, replacing unsupported plugins, resolving compatibility problems and repairing website code, is normally the responsibility of the website owner or their web developer.
If WP Toolkit continues showing a vulnerability after all available updates have been installed, please contact Hoopla Hosting and include:
- The affected domain name.
- The component named in the warning.
- The currently installed version.
- A screenshot or copy of the notification.
We can then check whether WP Toolkit is still detecting an outdated component or whether its vulnerability information has not yet refreshed.







