Administration
Site health, alerts and firewall.
What the site does by itself and how it tells you when something breaks: System status, background jobs, alert e-mails, the domain and mail check, updates that undo themselves, the firewall and unused accounts.
System status
Settings → System status shows everything in one table: the server, the database, mail, backups, background jobs, the domain and mail records, accounts and access. Green is fine, yellow needs a look, red needs action. Claude reads the same with get_health.
Background jobs
The site publishes scheduled news, sends mail and webhooks, makes backups, checks links, deletes old personal data and checks itself in the background. The table under Background jobs (cron) shows when each job last ran, when it last worked and the last error.
- Jobs run on visits too, after the page is sent – a site without cron still works.
- For exact timing, add the cron line from System status to your hosting (every 5 minutes). The installer shows it on its last screen.
- A job that fails three times in a row is reported by the alert e-mail.
Alert e-mails
When something goes wrong – a backup or an update failed, mail or a webhook could not be delivered, a job keeps failing, an address without a page is requested often, an address was blocked – the site sends one e-mail with everything since the last one, at most one an hour. It goes to the site e-mail, or to the address in System status → Alerts. Claude sees the same events with list_events.
Domain and mail
Once a day the site checks the domain it sends mail from and its own address:
- SPF and DMARC – when one is missing, System status shows the exact record to add at your DNS provider.
- DKIM – looked up under the common selectors; if your mail provider uses its own, all is well.
- Certificate and domain – how many days are left, with a warning three weeks ahead.
Check now runs the check at once. A site on a local or test address is not checked.
After an update
When an update has been installed, the site asks itself whether the new version runs – the home page and the administration must answer without a server error. If they do not, the previous files come back right away and the alert e-mail tells you. A site that cannot reach itself keeps the new version.
Firewall
Settings → Firewall is off until you switch it on. It guards the public site and the Claude connection, never the administration, so you cannot lock yourself out. Addresses of your local network are never blocked.
- Blocked addresses and networks – one per line, e.g.
203.0.113.7or198.51.100.0/24. - Blocked countries – two-letter codes, e.g.
RU, CN. They work behind Cloudflare (choose it under The site runs behind) or when the hosting sends the country. - Requests per minute from one address – 120 is plenty for people and stops aggressive scrapers. The Claude connection is not limited.
- Block probing – an address that asks five times in an hour for addresses of other systems that do not exist here (
/wp-login.php,/.env,/xmlrpc.php…) is blocked for 24 hours. Missing images and old links of a moved site never count.
The tab lists the addresses blocked for a while, with an Unblock button, and the last 50 refused requests.
Accounts and access
System status lists administrators without two-step sign-in, accounts not used for 90 days, Claude connections not used for 60 days and connections without an expiry, each with a link to fix it. In Settings → General → Suspend automatically you can let the site block unused accounts and revoke unused Claude connections once a day. Every suspension is in the change log, and one click in Users reactivates an account.