• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

"securityRiskFeature" not hiding Security-Risk score

skibidi

New Pleskian
Server operating system version
Ubuntu 24.04 x86_64
Plesk version and microupdate number
18.0.80.6
According to this Plesk KB article the Security-Risk score in WP-Toolkit should be hidden with:
Code:
[ext-wp-toolkit]
securityRiskFeature = false

But this setting does not appear to work in the (current) WP-Toolkit 6.11.2-10791 version, the Security-Risk score is still visible.

I'd like to hide it bc the "Security-Risk" rating can be misleading. As I understand it, the score represents the severity of known vulnerabilities in WP core, plugins and themes. It does not indicate whether a WP installation is compromised or whether its files have been tampered with.

We already had some cases where customers referred to a 0.0 rating as evidence that recurring malicious files could not originate from their WP installation. Ofc, a 0.0 vulnerability risk score does not mean the installation itself is clean or uncompromised.

Is "securityRiskFeature = false" still supported, or is there currently another way to hide this rating while keeping vulnerability detection enabled?

Thanks.
 
Back
Top