Troubleshooting the Vulnerability Scanner
Watchful's Vulnerability Scanner checks your website for a wide range of security issues and configuration problems.
Depending on your site, the scan may include checks for:
- Site configuration and security best practices
- Known core and plugin vulnerabilities
- Core filesystem integrity
- File and folder permissions
- Malware signatures
- Suspicious or malicious files
- Blacklist status
Some of these checks are more complex than others and may take additional time or server resources to complete. If the Vulnerability Scanner fails before completing, the problem is often related to a server timeout or insufficient resources.
Try the following troubleshooting steps.
1. Disable Basic Authentication
The Vulnerability Scanner does not function when HTTP Basic Authentication is enabled on the website.
Basic Authentication is commonly used to password-protect development or staging sites and is often configured using an .htpasswd file.
If your site displays a browser username and password prompt before WordPress loads:
- Disable Basic Authentication on the website.
- Disable Basic Authenticationfor the site in Watchful's site settings (see details here).
- Run the Vulnerability Scanner again.
- Re-enable Basic Authentication after the scan has completed, if required.
If you are unsure how Basic Authentication is configured on your server, contact your web host.
2. Increase the PHP max_execution_time
The Vulnerability Scanner may require more time to complete on larger or more complex websites, or sites with many user accounts.
If the server terminates PHP processes before the scan has finished, increasing the PHP max_execution_time value may resolve the problem.
For example, in cPanel:
- Log in to cPanel.
- Open MultiPHP INI Editor or the equivalent PHP configuration tool provided by your host.
- Locate
max_execution_time. - Increase the value.
- Save the changes.
- Return to Watchful and run the Vulnerability Scanner again.
For example, if max_execution_time is currently set to 30, try increasing it to 120 or 300.
If this setting is not available in your hosting control panel, contact your web host and ask them to increase the PHP execution time for the site.
3. Increase the server resources
The Vulnerability Scanner performs a number of filesystem, configuration and security checks. On sites with many files, plugins or extensions, these operations can require additional CPU and memory.
If the scan continues to time out, check the resources available to your hosting account.
In particular, consider increasing:
- Available CPU resources
- RAM or PHP memory
- Other hosting resource limits that may restrict long-running PHP processes
On shared hosting, these limits are usually controlled by your hosting provider. You may need to contact your host or upgrade the site's hosting plan.
After increasing the available resources, run the Vulnerability Scanner again.
Still having problems?
If the scan continues to fail after completing the steps above, contact Watchful support from the Watchful Dashboard.
When opening a support request, include the site name and any error message displayed by the Vulnerability Scanner.
Search Knowledge base
Most popular
- Add a Joomla website to Watchful
- Add a website to Watchful
- Add a WordPress website to Watchful
- Does Watchful support managed hosts like WP Engine, Flywheel, and Pantheon?
- How do I generate reports for my clients?
- How to add Tags to your WordPress & Joomla websites in Watchful
- How to use the Auto Update Scheduler
- How to use the Auto Updater
- Managing your auto-updating softwares
- Three ways to backup your website with Watchful