โš™๏ธ

Settings & Account

Configure SMTP, enable 2FA, customize your brand identity, manage team roles, and set notification preferences.

๐Ÿ“ง

How to configure SMTP outbound email

Essential

By default, WP Warden sends reports and alerts from a system mail server. Configuring your own SMTP ensures emails arrive from your own domain (e.g. reports@youragency.com) with better deliverability and full white-label appearance.

  1. Go to Settings โ†’ Email tab

    Click Settings in the sidebar, then select the Email tab at the top.
  2. Find the “Outbound Mail (SMTP)” section

    This section is at the top of the Email tab.
  3. Fill in your SMTP credentials
    • SMTP Host โ€” your mail server hostname (e.g. smtp.gmail.com)
    • SMTP Port โ€” 587 for TLS, 465 for SSL, 25 for unencrypted
    • Username โ€” the email address or login (e.g. reports@youragency.com)
    • Password โ€” use the show/hide toggle to check your entry
    • From Email โ€” the address that appears as the sender
    • From Name โ€” the display name in email inboxes (e.g. “WP Warden Agency”)
  4. Click Save

    The Save button at the top is only enabled when there are unsaved changes. Click it to save your SMTP settings.
  5. Test the connection

    After saving, click Send Test Email. WP Warden sends a test email to your logged-in account’s email address. A green โœ… badge confirms success; a red โŒ shows the error message.
Screenshot: Settings โ†’ Email tab โ€” SMTP section Screenshot: Settings โ†’ Email tab โ€” SMTP section

The SMTP configuration form with all fields filled in, and the Send Test Email button.

๐Ÿ’ก

Common providers: Gmail โ†’ smtp.gmail.com:587 (use an App Password if 2FA is on). SendGrid โ†’ smtp.sendgrid.net:587 (use your API key as the password). Mailgun โ†’ smtp.mailgun.org:587. Amazon SES โ†’ email-smtp.us-east-1.amazonaws.com:587.

โš ๏ธ

The Send Test Email button is automatically disabled when you have unsaved changes โ€” this prevents testing a configuration that hasn’t been saved yet. Always save first, then test.

๐Ÿ”

How to enable two-factor authentication (2FA)

Security

Protect your WP Warden account with a second verification step. WP Warden supports TOTP authenticator apps (Google Authenticator, Authy, 1Password) and email-based one-time codes.

  1. Open your Profile

    Click your name or avatar in the top-right corner of the dashboard, then select My Profile from the dropdown menu.
  2. Click the Security tab

    On your Profile page, click the Security tab. This tab only appears on your own profile โ€” not when viewing a teammate’s profile.
  3. Choose your method
    • Authenticator App (TOTP) โ€” most secure, and selected by default. Scan a QR code with your authenticator app and enter the 6-digit time-based code.
    • Email Verification โ€” simpler. A one-time code is sent to your registered email on each login. Requires your agency’s SMTP to be configured.
  4. Verify your method

    For Authenticator App: click Setup 2FA to generate a QR code, scan it with your app (or enter the manual key shown below it), then enter the 6-digit code it displays. For Email Verification: click Send Email Code, then enter the code you receive.
  5. Click Enable 2FA and save your backup codes

    Click Enable 2FA. WP Warden generates 8 single-use backup codes. Copy and store these in a safe place (password manager recommended). If you lose access to your authenticator or email, these codes let you log in.
  6. Complete setup

    2FA is now active on your account. Your next login will require the second factor.
Screenshot: Profile โ†’ Security tab โ€” 2FA setup Screenshot: Profile โ†’ Security tab โ€” 2FA setup

The 2FA setup showing the QR code, the confirmation code entry field, and the generated backup codes.

๐Ÿ’ก

If you switch phones or lose your authenticator, use a backup code to log in. Then go to your Profile โ†’ Security tab and regenerate new backup codes (old codes are invalidated immediately).

โ„น๏ธ

Administrators can see each team member’s 2FA status in Settings โ†’ Users, but there’s no admin-triggered way to remotely disable or reset a user’s 2FA โ€” a locked-out user must use one of their saved backup codes to regain access.

๐ŸŽจ

How to customize brand identity

White-Label

WP Warden is fully white-labeled. Configure your logo, colors, signature, and messaging so every report, email, and client portal shows only your agency’s brand.

  1. Go to Settings โ†’ Brand tab

    Click Settings in the sidebar, then select the Brand tab.
  2. Set your brand core
    • Brand Name โ€” shown in reports, emails, and the client portal header
    • Brand Color โ€” hex color for report headings, portal accent, and email buttons
    • Agency Logo โ€” your agency logo; appears in report headers and portals
    • Report Tagline โ€” short phrase under your logo (e.g. “Keeping your website healthy”)
  3. Use a tone preset (optional)

    Click one of the four preset buttons to instantly apply a brand color + matching tagline suggestion: Corporate Blue, Standard Indigo, Professional Emerald, or Bold Orange.
  4. Configure your email signature
    • Profile Photo URL โ€” optional headshot photo URL
    • LinkedIn / Twitter / Website โ€” clickable links in the signature

    Signature name, title, and a closing message are configured separately, under Settings โ†’ Reports tab โ†’ Report Signature.

  5. Configure report settings (optional)

    Toggle the Agency Cover Page on/off (Dark or Light style). Add a Watermark text. Configure the email sender display name and reply-to address. Add a Social Proof footer (badge image, testimonial quote). Enter an Unsubscribe URL for GDPR compliance.
  6. Save

    Click Save in the header. Changes apply to all future reports and portal interactions immediately.
Screenshot: Settings โ†’ Brand tab Screenshot: Settings โ†’ Brand tab

The brand core fields, tone preset buttons, email signature fields, and report options.

๐Ÿ’ก

Check the Hide WP Warden Branding toggle to remove “Powered by WP Warden Watchdog” from all reports and portals for a completely clean white-label experience.

๐Ÿ‘ฅ

How to manage team members and roles

Team

Administrators can add, edit, suspend, and delete users. Each user has a role (Administrator, Manager, or Viewer) that controls what they can access.

  1. Go to Settings โ†’ Users tab

    Click Settings in the sidebar, then select the Users tab. Only Administrators can see this tab.
  2. View the user list

    All current users are listed with their name, email, role, 2FA status, and account status (Active / Suspended).
  3. Edit a user

    There’s no dedicated edit mode: change a user’s role directly from the dropdown on their row, and (for Viewers) set their linked client from the dropdown that appears next to it. To edit their name or other profile details, open the โ‹ฎ menu on their row and choose View User Profile.
  4. Suspend a user

    Open the โ‹ฎ menu on a user row and click Suspend User to prevent them from logging in. Their work history is preserved. Click Restore User from the same menu to re-enable them.
  5. Reset a password

    Open the โ‹ฎ menu on a user row. Click Manually Reset Password to set a new temporary password yourself โ€” the user must change it on next login. Or click Send Reset Link for a self-service password reset link.
  6. Set a Viewer’s linked client

    For Viewer-role users, a Linked Client dropdown appears. Select the client whose portal this viewer accesses on login. The linked client name is shown as a badge on the user row.
  7. Delete a user

    Open the โ‹ฎ menu on a user row and click Delete to permanently remove the user. This action cannot be undone. Consider suspending instead if you may need to restore access later.
Screenshot: Settings โ†’ Users tab Screenshot: Settings โ†’ Users tab

The user list showing name, email, role badge, 2FA status, and action buttons per row.

โ„น๏ธ

Role summary: Administrator โ€” full access. Manager โ€” manage sites, clients, reports, backups; cannot manage users or tenant settings. Viewer โ€” read-only; logs in and is redirected directly to their linked client’s white-label portal.

๐Ÿ””

How to configure notification preferences

Alerts

Control exactly which events trigger email notifications. Enable only the alert types you care about to avoid inbox overload.

  1. Go to Settings โ†’ Notifications tab

    Click Settings in the sidebar, then select the Notifications tab.
  2. Review the notification categories
    • Email Alert Configuration โ€” enable/disable email alerts, optionally send via your own SMTP, and set the Primary Alert Email
    • Security Alerts โ€” Vulnerability detections (master toggle with sub-toggles for Plugin, Theme, Core), Zombie site detection
    • Site Monitoring โ€” Downtime, Uptime recovery, Cron failures, Site conflicts, PHP errors, Broken links (with a failure-count threshold), SSL expiry, Domain expiry, Site disconnected, DNS health, File integrity, Malware signature, Brute force
    • Update Alerts โ€” Updates available, Visual regression, Safe update failures, Automated update
    • Backup Failures โ€” Backup failure, Backup ready, Restoration events
    • WooCommerce Alerts โ€” Payment failures (master toggle with sub-toggles for Gateway down, Pending orders, Failed payments, Low/out of stock)
    • Ticket Notifications โ€” New support ticket submissions
  3. Toggle categories on or off

    Only the Vulnerability detections toggle under Security Alerts and the WooCommerce Alerts (Payment failures) toggle work as master switches โ€” turning either off disables its sub-toggles, which you can also expand to fine-tune independently. Every other section (Site Monitoring, Update Alerts, Backup Failures, Ticket Notifications) is a set of individual checkboxes with no group master toggle.
  4. Set your Primary Alert Email (optional)

    By default, alerts go to your login email. Enter a different address in the Primary Alert Email field to route all alert emails there instead โ€” useful for a shared team inbox. Check Send alerts using my custom SMTP settings to deliver them through the SMTP server configured on the Email tab.
  5. Save

    Click Save. Changes take effect immediately on the next alert dispatcher run.
Screenshot: Settings โ†’ Notifications tab Screenshot: Settings โ†’ Notifications tab

The notification categories with master toggles, the Security sub-toggles expanded, and the custom alert email field.

๐Ÿ’ก

If you use a Patchstack API key, vulnerabilities with an active virtual patch are automatically downgraded to Warning severity and will not trigger Critical alert emails โ€” reducing noise without missing real threats.

โ„น๏ธ

The Vulnerability master toggle cascades to Plugin, Theme, and Core sub-toggles. Toggling the master on/off sets all three sub-toggles simultaneously. You can then individually fine-tune each sub-toggle.

๐Ÿ”—

How to set up integration webhooks (Slack, Discord, Teams)

Alerts

Send your alerts straight into Slack, Discord, Microsoft Teams, or any custom automation webhook โ€” independently of the email notifications configured on the Notifications tab. Filter by alert type and site, batch into digests, chain escalations to an on-call channel, and preview or test every delivery before relying on it.

  1. Go to Settings โ†’ Integrations tab

    Click Settings in the sidebar, then select the Integrations tab, and click Add Webhook.
  2. Choose a provider and paste the webhook URL

    Pick Slack, Discord, Microsoft Teams, or Generic (JSON) for your own automation (Zapier, n8n, Make). Paste the incoming webhook URL from that platform, give it a name, and set a minimum severity โ€” the webhook only fires for alerts at or above that level.
  3. Filter by alert type and site (optional)

    By default a webhook fires for every alert type on every site. Uncheck All alert types to pick specific types (e.g. only downtime and backup failures), and uncheck All sites to scope it to a subset of your fleet โ€” handy for routing a client’s alerts to their own channel.
  4. Set a cooldown to avoid repeat noise (optional)

    Set Cooldown to suppress repeat deliveries for the same site and alert type within that many minutes. Leave it at 0 to deliver every matching alert with no suppression.
  5. Switch to hourly/daily digest mode (optional)

    Change Delivery frequency from Real-time to Hourly digest or Daily digest to roll up every matching alert into a single summary message instead of one message per alert. Once the webhook is saved, use the Test Digest button on its row to preview exactly what that rolled-up message will look like โ€” using whatever is really queued right now, or canned example alerts if the queue is empty โ€” without waiting for the next scheduled send and without consuming the real queue.
  6. Chain an escalation (optional)

    Set If still unresolved after to a number of minutes and choose another one of your webhooks under notify โ€” if an alert delivered to this webhook is still unresolved after that window, it’s automatically forwarded to the target webhook too (e.g. a general Slack channel escalating to an on-call Teams channel). An alert is only ever escalated once per target.
  7. Save, then test it

    Click Add Webhook to save, then click Test on its row. WP Warden sends your most recent real alert that matches this webhook’s filters (relabeled “[TEST]”), or a canned fake alert if none match yet โ€” either way, a successful delivery confirms the URL and payload format are correct.
  8. Review delivery history

    Click History on a webhook’s row to see its last 20 delivery attempts โ€” status (delivered, failed, skipped by cooldown, or escalated), alert type, site, timestamp, and error message if it failed.
  9. Duplicate, edit, or remove a webhook

    Use Duplicate to clone an existing webhook’s configuration as a starting point for a new one. If another webhook escalates to the one you’re about to disable or delete, WP Warden warns you by name first โ€” since that source webhook would otherwise stop escalating silently with no further warning.
Screenshot: Settings โ†’ Integrations tab Screenshot: Settings โ†’ Integrations tab

The Add/Edit Webhook modal showing provider selection, alert type and site filters, cooldown, digest frequency, and escalation fields.

๐Ÿ’ก

These webhooks are entirely separate from the email notifications on the Notifications tab โ€” you can run both at once, e.g. email for your own team and a Slack webhook scoped to a specific client’s sites for their channel.

โ„น๏ธ

Deleting or disabling a webhook that another webhook escalates to no longer fails silently โ€” WP Warden checks for dependents first and warns you which webhook(s) would stop escalating before you confirm.

๐Ÿ’ณ

How to manage subscriptions & billing plans

Billing

Manage your WP Warden subscription directly from Settings โ†’ Subscriptions. Every account is on the same flat-rate plan โ€” $3 per site/month โ€” with unlimited team members and storage included, so there’s nothing to compare or switch between.

  1. Go to Settings โ†’ Subscriptions tab

    Click Settings in the sidebar, then select the Subscriptions tab at the top. This tab is restricted to users with the **Administrator** role.
  2. Check your trial or billing status

    If you’re still in your 14-day free trial, a banner shows how many days remain and the exact date it ends. Once you’ve subscribed, this section instead shows your current site count, monthly cost, and next billing date.
  3. Understand your bill

    Your monthly cost is simply your active site count ร— $3/site (or ร— $36/site on annual billing) โ€” there are no tiers, feature gates, or per-plan limits to track. Adding or removing sites adjusts your bill automatically on the next cycle.
  4. Subscribe or manage billing

    Click Set Up Payment to start billing through Lemon Squeezy, or Manage Billing & Invoices to update your card, view invoices, or cancel โ€” this opens Lemon Squeezy’s secure customer portal.
๐Ÿ’ก

No manual plan switching: Since every account is on the same flat rate, there’s nothing to upgrade or downgrade between โ€” your bill just scales automatically with the number of sites you’re managing.

๐Ÿ”‘

How to create and use an API key

Developer

WP Warden includes a versioned, scoped public REST API (/api/v1/public) for connecting third-party tools, scripts, and AI agents to your fleet data โ€” separate from the internal API the dashboard itself uses. This guide covers creating a key, calling the API directly, and wiring it into popular external tools.

  1. Go to Settings โ†’ API Keys tab

    Click Settings in the sidebar, then select the API Keys tab.
  2. Click Create API Key

    Give the key a descriptive name (e.g. “LM Studio integration” or “Zapier automation”) so you can tell keys apart later.
  3. Choose scopes

    Pick only the scopes this integration actually needs: sites:read, alerts:read, alerts:write, backups:read, backups:write, or updates:read. A key can only call endpoints covered by its scopes โ€” everything else returns a 403.
  4. Copy your key immediately

    Your new key (format pax_pub_...) is shown exactly once, right after creation. Copy it into a password manager or secrets vault now โ€” WP Warden only stores a hash of it, so it can never be shown again. If you lose it, revoke it and create a new one.
  5. Authenticate your requests

    Send the key as a Bearer token on every request:
    curl -H "Authorization: Bearer pax_pub_..." https://wpwarden.io/api/v1/public/sites
    Every response is scoped to your tenant automatically โ€” there’s no parameter for selecting a different tenant, by design.
  6. Explore the OpenAPI spec

    Click View OpenAPI spec โ†’ on the API Keys tab (or open /api/v1/public/openapi.json directly) to see every available endpoint, its parameters, and its response shape. This spec is publicly readable with no key required, so integration tools can discover the API before you’ve created a key.
  7. Connect it to an external tool
    • Postman / Insomnia โ€” Import the spec directly from /api/v1/public/openapi.json (File โ†’ Import โ†’ Link), then set an Authorization header of type Bearer Token using your key.
    • Open WebUI โ€” Under Workspace โ†’ Tools, add a new tool by OpenAPI URL, pointing at your /openapi.json endpoint, and supply the key as the tool’s Bearer token โ€” every endpoint becomes a callable function for your chat model.
    • LM Studio โ€” If your loaded model supports tool/function calling, define one function per endpoint you want to expose (name, description, and parameters straight from the OpenAPI spec), and have the function’s handler send the actual HTTP request with your key attached as the Bearer header.
    • ChatGPT Custom GPT Actions โ€” In the GPT editor, add a new Action, import from the OpenAPI URL, and set Authentication to API Key โ†’ Bearer, pasting in your key.
    • Zapier / n8n / Make โ€” Use their generic HTTP or Webhook module: set the URL to an endpoint under /api/v1/public, choose the method, and add an Authorization header with your Bearer token.
  8. Revoke a key you no longer need

    Click Revoke next to any key on the API Keys tab. Revoked keys stop working immediately but stay listed for audit history โ€” they’re never deleted outright.
๐Ÿ’ก

Rate limit: each key can make up to 60 requests per minute. Build in basic retry/backoff logic in any automation you connect, in case you hit that ceiling.

โ„น๏ธ

The public API is intentionally narrow: sites, alerts, backups, and update history only, matching the six scopes above. It will not expose client data, billing, or team management โ€” treat it as a safe, limited-blast-radius credential to hand to third-party tools.