Use plugin-first setup when you want Help4 CDN asset rewriting, cache control, security scanning, WAF visibility, POP selection, and virtual-patching intelligence without moving the whole DNS zone immediately.
Keep a browser tab open to test the public site after saving.
Managed clients: if Help4 operations already provisioned your domain, use the key/secret pair from your private service handoff. Do not paste credentials into support tickets or screenshots.
Open WordPress admin. Go to Plugins, then Add New.
Choose Upload Plugin. Select help4-cdn-plugin.zip, then click Install Now.
Activate Help4 CDN. After install, click Activate Plugin. A Help4 CDN menu item appears in the admin sidebar.
Configure Help4 CDN
Open Help4 CDN in WordPress admin and fill in the connection fields.
The Help4 CDN 0.2.1 settings screen groups connection, validated DNS state, managed placement, browser cache, content targeting, proxy, and WAF controls.
Enable CDN rewriting. Check Enable CDN rewriting when you are ready for approved assets to use the Help4 delivery hostname.
Confirm the API base URL. Use the Help4 control-plane URL from your service handoff. If Help4 gave you a managed value, leave it as provided.
Add API key and secret. Paste Help4 API key and Help4 API secret. Leave the legacy bearer token blank unless Help4 specifically tells you to use it.
Review the delivery hostname. Free accounts use assigned Help4 city hostnames. Pro and Enterprise validate the assigned production domain for Help4 DNS, full proxy, and WAF coverage.
Select coverage. Choose pages, posts, products, asset classes, and any available POP city coverage for your plan.
Save Changes. The plugin syncs the site profile, cache policy, and routing preference back to Help4.
Open Help4 CDN, then use Cache Tools to clear the homepage, the current page, selected paths, or the whole assigned domain. The WordPress admin bar also provides quick cache actions to administrators.
Use the narrowest clear. Clear the affected page or path after a focused edit. Use a full-domain clear after a theme, menu, plugin, or site-wide layout change.
Keep automatic invalidation enabled. Publishing, deleting, commenting, taxonomy changes, menu edits, and supported optimization changes clear the related public URLs automatically.
Let Help4 coordinate compatible caches. A full clear also flushes supported WordPress object and page-cache layers so the origin and assigned POPs do not disagree.
Private data stays private: the plugin does not turn authenticated, checkout, account, admin, or other private responses into public cache entries.
Use Security Center
Open Help4 CDN, then Security Center to run a managed website scan, verify WordPress core files against official checksums, review recent administrative activity, and inspect site-scoped CDN/WAF events.
All plans
WordPress core integrity verification.
Login, user, theme, and plugin activity history.
Security-hardening status checks.
Site-scoped scan and event visibility when provisioned.
Entitled controls
WAF sensitivity and managed bot or under-attack mode.
Edge HTTPS and canonical security headers.
Enterprise IP, country, ASN, user-agent, and path access rules.
HTTP/2, gzip, Brotli, and transport-policy status.
Access rules are live security policy. Add a tested allow rule for administrator access before applying broad block rules. Controls unavailable to the active plan remain read-only or disabled.
Test after saving
Load the home page in a private browser window.
Open browser developer tools and check an image, CSS, or JS request.
Confirm approved assets use the Help4 delivery hostname.
Check that admin pages still load normally.
Run a cache refresh after publishing a small test change.
Use the Help4 ZIP download and increase the WordPress/PHP upload limit if needed.
Help4 CDN menu does not appear.
Plugin was installed but not activated, or the account lacks admin permission.
Activate the plugin and confirm the logged-in user can manage options.
Delivery hostname is blank.
The site has not synced with Help4 yet.
Check API key/secret, save again, then ask Help4 to verify the service profile.
Assets still load from origin.
Rewriting is disabled or no content/asset classes are selected.
Enable rewriting and select the pages/posts/products or asset classes that should use CDN.
A cache clear reports an error.
The site entitlement is pending, credentials are invalid, or the control plane rejected the requested scope.
Confirm the registered domain and credentials, then retry the narrow path clear before using a full clear.
Security scan is unavailable.
The domain is not yet provisioned for managed scanning.
Finish domain assignment and DNS validation; local WordPress integrity checks remain available.
WAF controls are disabled.
The site is not on a Pro/Enterprise full-proxy plan or paid domain validation has not passed.
Use static CDN mode or upgrade/validate before enabling full proxy + WAF.
Ready for full DNS coverage?
After plugin-first testing, you can move the whole domain to Help4 nameservers for DNS-managed CDN routing, full-site proxying, WAF coverage, and virtual patching.