Minimum Requirements; Activation and First-Run Behavior
Purpose
This article explains the basic environment needed to run CMSSPM, what happens when the plugin is activated, and what to expect the first time you open it. The goal is to help you confirm that the plugin is installed correctly and behaving normally before you begin reviewing scan results.
Where to find it
This article belongs in the Installation section because it covers setup expectations rather than security findings or dashboard interpretation. It is most useful immediately after installation or when verifying that a new environment is ready for CMSSPM.
Minimum requirements
CMSSPM is intended to run in a standard, supported WordPress environment with administrative access. At a minimum, you should expect to need:
- a working WordPress installation,
- an administrator account with permission to install and activate plugins,
- a hosting environment that supports normal WordPress plugin operation,
- network access for any checks that depend on remote lookups or external validation,
- a generally modern PHP and WordPress environment.
Some scanners or checks may depend on your specific hosting setup, DNS configuration, TLS setup, email configuration, or other site-level protections already in place. Because of that, not every site will produce identical results or have access to every optional capability.
What happens during activation
When CMSSPM is activated, it registers its admin functionality and adds the Posture Management menu to wp-admin. This gives you access to the Overview Dashboard and the related security sections used by the plugin.
Activation itself does not mean a full scan has already been completed, and it does not automatically mean every security control has been enforced. In most cases, activation prepares the plugin for use, but the actual security posture data becomes meaningful only after you review the plugin and run a scan.
Depending on the current state of the site, some plugin data structures, options, or default settings may also be created or initialized during activation.
What to expect on first run
The first time you open CMSSPM, you should expect to see the main admin pages and the overall plugin structure, even if there is little or no scan history yet. A site that has not been scanned may show empty areas, baseline values, prompts to begin scanning, or limited results until the first scan is completed.
Your first run is mainly about confirming that:
- the plugin loads correctly,
- the admin menu is present,
- the dashboard is accessible,
- no obvious activation or permission problems are blocking normal use.
After that, the next step is usually to run your first scan so the dashboard has real findings and scoring data to work with.
Recommended next steps
After activation and first access:
- confirm the plugin appears in the wp-admin menu,
- open the Overview Dashboard,
- review any initial settings or notices,
- run your first scan,
- use the scan results as your initial security posture baseline.
If the plugin activates but the dashboard does not populate immediately, that is not necessarily a problem. Many of the useful results only appear after the first scan has completed.
Notes and scope
This article is only meant to explain general setup and first-run expectations. It does not cover every scanner dependency, hosting edge case, or advanced environmental requirement.
As CMSSPM evolves, minimum requirements and first-run behavior may also change based on added features, broader scan coverage, or future editions. If the plugin later introduces environment validation, setup notices, or compatibility checks, those details should be documented here as they become formalized.
