# WebTotem > Help center and documentation for WebTotem ## FAQ - Q: What is a suspicious event? A: Suspicious event - any event, either blocked or non blocked because of being low risk, with a sign of a malicious request; Blocked - a suspicious event, found to be critical enough to get blocked; Low risk - a suspicious event with a feature of a malicious request yet not critical enough to ge - Q: I don’t see data in server resources A: There are two cases why this can happen. Perhaps the module is still processing your site. Or your server configurations do not meet requirements. For this module to work server should give access to read the files: * /proc/meminfo * /proc/cpuinfo * /proc/stat or to run shell_exec. - Q: What is WebTotem? A: The world's friendliest professional-grade security monitoring and protection for websites. - Q: Why doesn’t firewall block the attacks? A: Typically, firewall needs two days to finish training completely. Training is required to analyze your website traffic and thus reduce false positives. If after two days after installation the firewall does not block attacks, please contact support. - Q: Why don’t I see my verification mail? A: Check other sections of your mail service. It is possible that the letter got into spam. If you use gmail, also check the "Promotions" section - Q: What API-keys are used for? A: Typically, the Currently, our API-Keys are used for activating WordPress Plugin. But we are to add more integrations soon, including Zapier, where API-Keys will be required for activation. - Q: How does manual scan work? A: To start scanning you need to click on rescan button in antivirus logs module. In case no changes happened to your filesystem since the last automatic scan the logs will show the same results after manual rescanning. - Q: Why can’t i activate Wordpress plugin with API-Keys? A: It is required to copy API-Key immediately after it has been generated. Since we don't store API-Keys with authentic namings for the sake of security issues. If you did not copy it from generation window, we recommend you to delete it, generate a new one again and copy it with original naming. - Q: What to do if there are problems with the installation? A: * Check the version of your PHP, at the moment, versions below 7.0 are not supported by our agent manager, however we plan to do this. * If you have an old version of PHP, we recommend that you upgrade for your own safety. * Check permissions on your site and users rights. * Give permissions to e - Q: How do I delete an infected file? A: It is impossible to completely delete a file marked as infected by an antivirus using our service. This can be a vital file for your website. You can quarantine this file. To do this, select the site you need in your personal account. Go to the antivirus module, click the "SHOW MORE" button, configu - Q: How does antivirus work? A: Our antivirus scans every 6 hours and scans automatically each time the filesystem changes. In other words, if you upload a new file to your website our antivirus scans it immediately. There is also an option to start manual scanning by clicking the rescan button in the right top of the module. Manu - Q: Issues with installation? A: ##Requirements 64-bit version of PHP only (32-bit version is not supported) ###Minimum requirements for the correct operation of the modules php 7.0 php-json ###Recommended requirements: php 8.1 php-gmp php-json php-sodium php-pdo ###What to check if agent can’t be installed? Check - Q: Does GDN send my data to other Webtotem clients? A: Thanks for the question. You don't have to worry about your personal data. GDN option shares data collected between your websites and does not share it with other WebTotem clients. - Q: Where should I upload the file that I downloaded during manual installation? A: You must upload this file to the root directory of your site where the root files are located (usually in the directory with index.php) - Q: Why is the firewall module empty in the report, although there are results in the cabinet? A: Typically, the firewall only shows blocked attacks in the report. If there are blocked attacks that are shown in your account, but which are not in the report, then there may be problems on our side. ## Search For specific questions, search: https://app.helpshelf.com/help/webtotem/search?q={query} ## AI Agent Access - [Full product context](https://app.helpshelf.com/help/webtotem/llms-full.txt): policy-checked verified documentation, or guarded-access guidance when bulk export is unavailable - MCP endpoint: https://app.helpshelf.com/api/mcp/3e09d594f7a8 (streamable HTTP) with tools: search_docs, ask, get_article, get_product_context Send `Accept: application/json, text/event-stream` — a compliant Streamable HTTP server answers 406 without both media types. - [MCP server card](https://app.helpshelf.com/help/webtotem/.well-known/mcp/server-card.json): machine-readable description of the endpoint above - [Agent skills](https://app.helpshelf.com/help/webtotem/.well-known/agent-skills/index.json): how to use this documentation, as an Agent Skill - Markdown: any article URL returns Markdown when requested with `Accept: text/markdown` AI agents have read-only access to published documentation. This MCP endpoint never creates tickets, notifications, or other account mutations.