Welcome to ToggleWP! Here are some simple tasks to get you started on your 14 day trial:

1 – Setting a site administrator

On the main menu go to ToggleWP > Manage. In the Security panel enable the “Security & Authentication” module by toggling it on.
Next, go to General > Settings and look for the “Administration Email Address”. It has now been changed from an email address to a drop down list of the site’s administrator user accounts.
If there is no user selected, pick the relevant admin and save the changes.

What does this do?
Previously this email address could be set to anything, and could end up sending emails to users who no longer have admin access to the site. The selected user now will be protected from deletion via the UI, or from having its role downgraded.

Why is this important?
By protecting the admin user it prevents technical site emails going to users who are no longer responsible for a site. Your administrator user account can’t be downgraded preventing you from performing maintenance on a site while you are still receiving site administrator emails.

2 – Securing your administrator user account domains

Go to ToggleWP > Manage, select the “Security & Auth” tab.

Scroll down to the “Allowed Admin Email Domains” section and click the button to “Auto-populate from existing admins”. One or more domain names will be added based on the email addresses used by current admin users. Click the save button at the bottom of the screen.

What does this do?
When a new administrator account is created its email domain will be checked against this allowed admins list. Domains not on that list will be blocked, showing the user attempting to create it an error. When the domain is

Why is this important?
It prevents new administrator users from being created from domains that haven’t been previously approved by the site administrator. This could be an innocent action like a client attempting to add a new user with a personal Gmail address rather than company email, but also more malicious attempts like cross site scripting attacks attempting to create a new admin user with a bogus domain.

3 – Protect the ToggleWP plugin from deactivation

Start by going to ToggleWP > Manage. In the “Admin” panel enable the “Plugin Control” module. Swap to the “Plugin Control” tab. Scroll down to find “Plugin Activation Emails” and “Plugin Deactivation Emails”, check them both and click the save button.

Next head over to ToggleWP > Plugin Manager. Find the ToggleWP plugin in the list and tick its “Protect” option. For bonus points add “This is a protected plugin” in the admin notes text area next to it. Save all changes at the bottom of the screen.

Image

What does it do?
The plugin emails will send a notification email to the site administrator when a new plugin has been installed and activated, or an existing plugin deactivated. The email includes information about the user who performed the change and the plugin involved.

Go to Plugins > All Plugins. Scroll down to find ToggleWP, it now has “Protected by ToggleWP” where the deactivate link would have been. It also has your “Example plugin note” next to it.

How does it help?
The plugin activation / deactivation emails can help you pre-empt issues before they become bigger problems. For example, you provide hosting services and the client maintains their own site. Your platform provides caching and the client installs a plugin with known compatibility issues. With an email alert you can get in touch with them pro-actively to discuss their needs, before they become frustrated and raise a support ticket.

For site designers handing sites over to their clients, plugin notes can be used as a polite reminder what different plugins do, and why they shouldn’t be removed.