Security for Wordpress Websites

ksigmtsu

Guru
1000 Post Club
2,024
Since there have been a lot of attacks on wordpress sites as of late, I figured I could give people a couple recommendations on plugins that actually help secure the site.

Bulletproof Security: This plugin secures your .htaccess files, and gives recommendations as to what you can do with file permissions on your server, along with a ton of other info.

Silence is Golden Guard: Allows you to press 1 button that will delete readme files, screenshot files, etc from all your plugins and themes. It also creates an index.php file in every directory that shows a page not found 404 error anytime someone tries to directly access any of the wordpress theme or plugin or source directories.

Use those 3, and you'll immediately increase the security of your site, and be blocked from most types of attacks.

--------------------------------------------------------------------
Since when I wrote this, bulletproof has added brute force protection, so Limit Login Attempts is no longer necessary for that purpose.
 
Last edited:
BPS is fine, but I prefer Wordfence. If your site is hacked and you have installed BPS it might be more difficult to put it back together.

Hackers troll for username Admin and then it is often easy to guess the password by trying information they pick up from your site. Phone numbers, zip codes and combinations of your name are easy targets.
 
Last edited:
I highly recommend Wordfence as well!
And Val's recommendation of it makes me feel a lot better about it since I always hear about BS.

In the past 14 days sc-lifeinsurance.com has had 52 hack attempts by either true brute force log-in attacks or some type of log-in attempt that wasnt me.
Those 52 attacks came from 20 different IPs, and if I had to guess by timing and country of origin, 17 different users.

Most all of the attempts used the Username "Admin" or "Administrator" or "Admin1".
Other user names attempted were "manager" "root" "support".

So dont use some generic username. And dont issue any generic usernames for web designers or seo guys.

Also, post on you blog/site under a different name than your username. This way they cant figure out your username from your site.


Also, WF has a live traffic tracker. It usually shows the source of each visit and which pages they go to. Obviously, it isnt google analytics, but its a quick and easy way to keep track of traffic. It even separates (or tries) the humans from the bots & spiders.

Now I am going to look at wordfence to see if it covers #3 on the OPs list!
 
Last edited:
Get the premium version.

After a few days of using the free version I upgraded to get country block. Absolutely worth the price.

You can still get hacked from a US based IP, but much more difficult with WF.
 
Get the premium version.

After a few days of using the free version I upgraded to get country block. Absolutely worth the price.

You can still get hacked from a US based IP, but much more difficult with WF.


Good advice. I think I will do that today.

I also added Silence is Golden Guard since WF doesnt protect your plugins like it does.
- - - - - - - - - - - - - - - - - -
WARNING!!!!!!!!!!!!

If you install Silence is Golden Guard be VERY careful and backup everything before you do.

It has totally wrecked sc-lifeinsurance plus my other site that is on the same host plan.....

I would not recommend it based on what I am currently going through.

I have even totally deleted the plugin from my server files... its better, but its still f#cked...

:mad::mad::mad::mad:
 
Last edited:
Back
Top