The Complete WHM Diagnostic & Maintenance Toolkit
26+ Enterprise Tools for
WHM & Server Auditing.
ForgeCommand equips WHM sysadmins and hosting providers with a battle-tested arsenal of 26 specialized diagnostic tools — covering WordPress audits, automated security hardening, low-overhead downtime investigations, disk bloat discovery, and server-to-server site migrations.
Part of the NodeForge Systems suite. Sync e-commerce catalogs via VortexSync and coordinate multi-node high-availability syncing using ForgeCluster.
Comprehensive Tool Suite
Every tool inside ForgeCommand is built for high-scale multi-account WHM environments with native root-level precision.
1. WordPress Audit & Security Suite
Audit, secure, and manage WordPress environments across all hosted cPanel accounts.
WP Plugin Auditor
Inventory and search installed plugins across all accounts. Identify vulnerable or outdated plugins, and perform mass activation, deactivation, updates, or installs.
WP Core Integrity Scan
Scan all cPanel accounts to verify WordPress core file integrity, detect modified checksums, and list outdated core versions.
WP Theme Auditor
Identify active and inactive themes installed on every WordPress site. Track `style.css` version numbers and flag unmaintained themes.
WP Must-Use (MU) Auditor
Detect and inspect plugins inside `wp-content/mu-plugins` that run automatically and cannot be deactivated via standard WP Admin.
WP Config Security Audit
Audit `wp-config.php` files for open `WP_DEBUG` modes, missing authentication keys, default `wp_` table prefixes, and exposed database credentials.
Automated WP Salt Rotator
1-click batch rotator for secret keys and authentication salts (`AUTH_KEY`, `SECURE_AUTH_KEY`, etc.) across single sites or all server accounts.
WP Search & Replace
Safe serialized-array database search and replace utility for domain changes, staging-to-production pushes, and HTTP-to-HTTPS migrations.
WP Permissions Auditor
Detect world-writable files (`777`), improper folder permissions (`666`), and dangerous ownership configurations across all web roots.
WP Version Inspector
Server-wide breakdown showing exact distribution of WordPress versions across every account on the host node.
2. Security, Hardening & Compliance
Automate header enforcement, IP blacklisting, SSL monitoring, and server-wide hardening.
Visual CSP Builder
Scan web pages, automatically detect external scripts, stylesheets, and fonts, and generate strict Content Security Policy HTTP headers.
Security Rollout Engine
Mass deploy security policies across accounts: inject Wordfence IP rules, enforce HSTS, restrict XML-RPC, and block brute-force login endpoints.
SSL Expiry & Validity Audit
Server-wide SSL certificate tracker flagging expiring certificates, self-signed SSLs, missing SANs, and AutoSSL renewal failures.
.htaccess Rule Auditor
Audit `.htaccess` files across all accounts to find syntax errors, dangerous overrides, infinite redirect loops, and malicious rewrite rules.
RBL Blacklist Monitor
Check server primary IP and account dedicated IPs against 20+ top DNSBL/RBL spam blacklists (Spamhaus, Barracuda, SORBS, etc.).
3. Performance & Traffic Diagnostics
Diagnose load spikes, analyze access logs, and monitor PHP-FPM pools in real time.
PHP-FPM Pool Monitor
Track active PHP-FPM worker pools, process states, max children limit hits, slow requests, and memory usage per cPanel account.
Live Traffic Monitor
Real-time HTTP request stream monitor filtering active requests, response codes, connected client IPs, and user agents by domain.
Historical Traffic Auditor
Parse Apache access logs over configurable time windows to pinpoint bandwidth hogs, bot crawlers, brute force attempts, and traffic spikes.
MySQL Slow Query Detective
Parse MySQL slow query logs to identify non-indexed queries, heavy table locks, long execution times, and database bottleneck queries.
Downtime Investigator
Priority-throttled (`nice 19` / `ionice class 2`) low-overhead investigator script that safely analyzes crash logs during severe load spikes without causing further outages.
4. Disk & Storage Intelligence
Reclaim wasted disk space, detect oversized logs, and clean up bloated databases.
Large Files Finder
High-speed filesystem scanner locating files over 500MB, orphaned tarballs, backup dumps, and uncompressed archives across `/home`.
Database Storage Auditor
Analyze database sizes, tables with high overhead/fragmentation, engine types (InnoDB vs MyISAM), and candidate tables for optimization.
Unoptimized Image Bloat Finder
Scan WordPress uploads directories to flag uncompressed raw PNG and high-resolution JPG images consuming gigabytes of disk space.
Server Log Auditor
Scan system logs, cPanel user `error_log` files, and web server logs to locate multi-gigabyte log accumulation eating up inodes and disk space.
Broken Link Crawler
Deep website crawler that checks internal links, asset dependencies, and external URLs to flag 404 errors and broken redirect chains.
5. System Administration & Migration
Automate server-to-server migrations, cron reviews, and PHP runtime configurations.
Automated Site Migrator
Server-to-server migration engine using SSH key authentication and rsync file transfer with automated MySQL database dumping and staging import.
Cron Jobs Auditor
Inspect system crontabs and per-user cPanel crons to find high-frequency tasks, failing scripts, and overlapping cron jobs.
PHP Runtime Auditor
Review active PHP handlers, installed extension modules, per-user `php.ini` directive overrides, and memory limits across accounts.
Redirect & HTTP Chain Tester
Diagnose HTTP 301/302 redirect chains, check maximum hop counts, detect infinite loops, and verify canonical domain rules.
Enterprise Use Cases
How sysadmins and hosting providers rely on ForgeCommand every day.
1. Remote Multi-Server Security & Resource Hardening
Sysadmins evaluate individual site directories and parse WordPress configuration structures using our low-overhead scanning daemons. Locate open debug variables, non-salted configurations, or vulnerable default table prefixes (`wp_`) before security incidents occur.
2. Low-Priority Site Downtime Investigation
When a server load average spikes, running heavy diagnostics can trigger crash loops. ForgeCommand investigator scripts run automatically at `nice 19` and `ionice class 2` to preserve CPU and disk I/O. Access logs are parsed directly via epoch offsets to summarize traffic spikes without loading slow interpreter runtimes.
3. Continuous Telemetry & Server-Wide Auditing
Our local monitoring daemon polls system stats, per-user memory RSS footprints, and network interface rates every 60 seconds. Telemetry data is recorded inside a localized SQLite file with auto-purging set to 30 days, keeping system storage metrics clean.
Professional Server Management.
Cancel anytime. No contracts. Full access to every tool.
- All 26+ Diagnostic Tools
- Unlimited Site Migrations
- Automatic Plugin Updates
- Priority Support
Enter the hostname of the WHM server you want to license.
Need the full toolkit? Save with the Server+ Suite bundle