Welcome to Hardening WordPress with WP-CLI and Automated Malware Scanning on VPS. When hosting WordPress on an unmanaged VPS, relying solely on graphical security plugins leaves you vulnerable. You need server-level hardening and automation.

1. The Power of WP-CLI for Security

WP-CLI (WordPress Command Line Interface) allows you to manage WordPress installations directly from the SSH terminal. This means you can update core, themes, and plugins without ever logging into the vulnerable wp-admin dashboard. Furthermore, WP-CLI can verify core file integrity.

2. Automating Updates with Cron

The most common vector for WordPress compromises is outdated plugins. You can create a simple bash script that uses WP-CLI to update all plugins and themes automatically. By adding this script to your server's crontab (e.g., 0 3 * * * /usr/local/bin/update-wp.sh), you ensure your site is patched every night at 3 AM.

3. Verifying Core Checksums

A crucial security check is verifying that your core WordPress files haven't been maliciously modified. Using WP-CLI, you can run wp core verify-checksums. This command compares the hashes of your local files against the official WordPress repository. Any discrepancy indicates a likely compromise.

4. Server-Level Malware Scanning (ClamAV/Maldet)

Don't rely on PHP-based scanners within WordPress, as advanced malware can hide itself from PHP processes. Instead, install server-level tools like ClamAV and Linux Malware Detect (Maldet). Configure Maldet to scan your /var/www/html directory daily, tying it into inotify for real-time monitoring of file uploads.

5. Locking Down File Permissions

Ensure that your web server user (e.g., www-data) only has the absolute minimum permissions required. Directories should generally be 755, and files 644. More importantly, configure your wp-config.php to be 400 or 440, readable only by the owner and group, preventing unauthorized reads if directory traversal occurs.

Conclusion

By moving your security posture from the application layer to the server and command-line layer using WP-CLI and OS-level scanners, you dramatically reduce the attack surface of your WordPress VPS installations.