Skip to content
Witen

Recovery and maintenance

Disconnect or remove Witen

Disconnecting stops future reporting to Witen. Removing a product also means reviewing local rules, credentials, and kept data. Back up the installation first.

Stop reporting to Witen

Turn off the connection and event-sharing controls in the plugin, or remove Warden’s enrollment and sensor credentials from its configuration and restart it. Check environment variables and managed configuration too. Revoke the installation credential in your Witen dashboard when you retire it.

Local protection keeps working after you disconnect. Disconnecting cannot retract events already delivered. Account data requests follow the privacy policy.

WordPress

  1. Back up the database and the site’s .htaccess. Export any local activity you want to keep.
  2. Turn off sharing with Witen and any separate Warden event delivery. Remove Witen connection constants or secrets from managed configuration if you are retiring the site.
  3. Deactivate Witen Blocker in Plugins. Deactivation preserves settings and stops its scheduled work.
  4. Review the persistent Apache sections named Witen Blocklist and Witen Hardening. Remove only those marked sections if you want their rules lifted; preserve WordPress and other plugins’ sections.
  5. Delete the plugin through WordPress when you are ready to erase its plugin data. Verify normal pages and /wp-login.php. Keep the backup until you have checked login access.

Matomo

  1. Download the local security log and back up the exact private state directory configured for this instance.
  2. Uncheck the Witen connection and save. Pending shared events are discarded. Disable separate Warden delivery if configured.
  3. Deactivate Witen in Matomo’s plugin administration, or run the command below from the Matomo directory.
  4. Uninstall through Matomo. Both deactivation and uninstall preserve the private state directory for recovery.
  5. If you want to erase local data, remove only this instance’s verified private state directory after uninstalling. Preserve other applications’ temporary directories and state.
./console plugin:deactivate Witen

The state directory is selected by WITEN_MATOMO_STATE_DIR, or a private witen-matomo-… directory under the system temporary directory. Resolve the actual configured path before removing it.

Warden on Linux

  1. Keep independent console access. Back up /etc/witen/warden.toml, private credentials, and /var/lib/witen.
  2. Review sudo warden blocked --source all. Use sudo warden unban IP while the daemon is running for addresses you need to release.
  3. Stop and disable the Warden service with your host’s service manager, then remove the package or portable installation.
  4. Inspect the remaining firewall state. Remove only verified Warden-owned objects; keep the host’s other tables, chains, and policies.
  5. Remove private configuration, credentials, and state only when you no longer need recovery. Revoke the retired installation in your Witen dashboard.

Changing the backend to null does not lift previously applied bans. For the nft backend, Warden owns inet witen; the host’s inet filter table belongs to the host and must be preserved.