Troubleshooting

Last updated: 10th July 2026 for CC Security Essentials version 1.0

Introduction

Most websites will never encounter problems when using CC Security Essentials.

However, every WordPress website is different. Themes, plugins, hosting environments and server configurations can all influence how security features behave.

This guide provides practical steps to help identify and resolve the most common issues.

Whenever possible, begin by understanding the cause of a problem before making changes to your website’s configuration.


Before You Begin

Before investigating a specific issue, we recommend:

  1. Confirm that you’re using the latest version of CC Security Essentials.
  2. Ensure WordPress itself is up to date.
  3. Review Security Health for any recommendations.
  4. Run the relevant Verification test.
  5. Check the Diagnostics page for additional information.

These steps often identify the cause of an issue without requiring further investigation.


XML-RPC Verification Fails

Possible causes

  • XML-RPC protection isn’t enabled.
  • Another plugin is managing XML-RPC.
  • A caching layer is returning an unexpected response.
  • Your hosting provider already blocks XML-RPC.

What to do

  • Confirm that XML-RPC protection is enabled.
  • Save your settings again.
  • Clear any caches.
  • Run the verification test again.
  • Review the Diagnostics page.

If your hosting provider already blocks XML-RPC, the overall behaviour may still be secure even if the verification result differs from what you expected.


REST API Protection Doesn’t Behave as Expected

Possible causes

  • Another plugin is controlling REST API access.
  • Your website depends on public REST API endpoints.
  • A custom theme or plugin has introduced additional REST routes.

What to do

  • Temporarily disable REST API Protection.
  • Confirm whether the issue disappears.
  • Identify which application requires REST API access.
  • Decide whether visitor access should remain enabled or whether REST Rules in CC Security Essentials Pro would provide a better solution.

Comments Still Appear

Possible causes

  • Comments remain enabled for the selected content type.
  • Your theme provides custom templates.
  • A third-party commenting system is installed.
  • Existing comments are still displayed.

What to do

  • Review your Disable Comments configuration.
  • Confirm the correct content types are selected.
  • Clear any caches.
  • Test using a default WordPress theme if necessary.

Remember that disabling comments prevents new comments from being submitted but doesn’t automatically remove existing comments.


Verification Reports an Unexpected Result

Verification reflects the behaviour of your website.

Unexpected results don’t necessarily indicate a security problem.

Instead, they often highlight differences between your website’s environment and the assumptions made by the verification test.

Use Diagnostics to gather additional information before making changes.


After Updating WordPress

Major WordPress updates occasionally introduce changes that affect plugins.

After updating WordPress, we recommend:

  • reviewing Security Health
  • rerunning Verification
  • testing any enabled protections
  • confirming that your website behaves normally for both visitors and administrators

This usually takes only a few minutes and provides reassurance that everything continues to operate as expected.


Plugin Conflicts

WordPress websites commonly use multiple plugins.

Although CC Security Essentials is designed to work alongside other plugins, conflicts can occasionally occur when two plugins attempt to control the same feature.

Examples include:

  • XML-RPC protection
  • REST API restrictions
  • comment management
  • login security

Where practical, it’s usually better for a single plugin to manage each security feature.


Performance

CC Security Essentials has been designed to have minimal impact on your website’s performance.

Most features operate only when required and don’t affect normal page requests.

If you believe the plugin is affecting performance:

  • temporarily disable the affected feature
  • compare the behaviour
  • review Diagnostics
  • check whether another plugin is performing similar tasks

Import Problems

If you’re unable to import a configuration:

  • confirm that the file was exported by CC Security Essentials
  • ensure it hasn’t been modified
  • use compatible plugin versions
  • export the configuration again if necessary

I Can’t Access the Plugin

If the plugin menu isn’t visible:

  • ensure the plugin is activated
  • confirm you’re signed in as an administrator
  • check whether another plugin is modifying administrator capabilities

Before Contacting Support

Gathering a little information beforehand often makes resolving an issue much quicker.

We recommend:

  • noting the steps required to reproduce the issue
  • recording the version of WordPress
  • recording the version of CC Security Essentials
  • reviewing Diagnostics
  • running the relevant Verification tests
  • identifying any other security plugins that are active

The more information you can provide, the easier it is to identify the cause.


Frequently Asked Questions

Is something wrong if Security Health shows recommendations?

No.

Recommendations are intended to guide you towards potential improvements.

They’re not an indication that your website is compromised.


Should I disable other security plugins?

Not necessarily.

Many websites successfully use multiple security plugins.

However, it’s generally best to avoid multiple plugins managing the same security feature.


Can I damage my website by enabling a protection?

The plugin has been designed to minimise that risk by explaining each feature before you enable it.

If a protection isn’t suitable for your website, you can usually disable it again immediately.


What if I still can’t resolve the issue?

Review the Diagnostics page, gather as much information as possible, and consult the latest documentation before contacting support.


Best Practice

When troubleshooting:

  • Change one setting at a time.
  • Test the result.
  • Use Verification wherever available.
  • Review Diagnostics before making further changes.
  • Keep notes if you’re investigating a more complex issue.

A methodical approach almost always produces better results than changing several settings at once.


Related Articles

Continue with: