Can someone tell me.

Cloudflare + WordFence are my choices. Here is a good thread about Cloudflare & WordPress security, thanks to @CyberCommander: https://www.blackhatworld.com/seo/t...min-login-with-cloudflare-zero-trust.1515428/

Other things to implement:

Don't use nulled stuff.
I recommend not to use shared hosting.
Good passwords (a1B@cdE1Fgh&&) & strong username.
Keep the plugins and the theme updated.
Update the salt keys from time to time.

Cheers!
M
many thanks for your recommendation

@mrrankseo check https://cleantalk.org/ they have two very strong Antispam & Firewall plugins. You should use both.


You can use also a webhosting like https://www.mechanicweb.com/ or https://stablepoint.com/ which protect your site with https://www.imunify360.com/
 
Last edited:
Hey, you can use strong password and username and never share details any one.
 
My suggestion would be to secure your WordPress site by updating regularly, using strong credentials, limiting login attempts, and enabling two-factor authentication.
 
Three important things to remember when it comes to securing your WP site. First is to choose a secure host, second is to keep your WP core, themes, and plugins ALWAYS up to date, and lastly, create a secure and strong username and password.
 
many thanks for your recommendation

@mrrankseo check https://cleantalk.org/ they have two very strong Antispam & Firewall plugins. You should use both.


You can use also a webhosting like https://www.mechanicweb.com/ or https://stablepoint.com/ which protect your site with https://www.imunify360.com/

Cleantalk is indeed a great choice. I've been using it since 4+ years ago.

If the WordPress has only one user, I'd like to add Basic Authentication to lock down the wp-admin area as well. You can search Google to find a lot of ways to do this. Or, you could also try this simple plugin. https://wordpress.org/plugins/easy-basic-authentication/
 
Last edited:
you can use a strong password and username so no one should crack it.
and also don't tell anyone about your username and password.
Thank you.
 
Use Cloudflare, don't install sketchy unknown plugins, and don't use nulled themes.

Make sure your password is really good. Hide your WP login page (there is a plugin for this)
 
Asides from those mentioned:
  1. Hide your WP login - lots of plugins to do this or you can look change it in the code.
  2. Use complex passwords - for ftp, hosting login, wordpress login etc
  3. Use 2FA on everything - so that it requires mobile authenthication to access web-facing login panels
  4. Harden your server - if you're hosting your own panel, ensure it's updated, and only necessary ports are open
  5. Use less plugins - the more plugins you use, the more susceptible your site is to vulnerabilities introduced by those plugins.
 
I'm not sure if wordfence does this but it also helps if you change your admin login url so link/comment spammers can't post garbage comments on your site.
Comment spambots using the default url for domains that use WP
 
How can I secure my WordPress site and if so, what plugins can I use?
Secure your wordpress site by using strong passwords, enabling two-factor authentication, keeping themes and plugins updated, and using security plugins like " Wordfence or Sucuri ".
 
Go for Wordfence. That's all you need. Any changes to your WordPress files will be notified to you.
 
Keep your WordPress core, themes and plugins up-to-date, enable automatic updates. Also use a strong password and user access while you secure your login, do regular back ups and put essential security plugins.
 
After using Wordpress/Woocommerce for one shop I would say it's impossible to secure and best to be avoided.
 
you can secure your site on wordpress by create a strong passwords.
 
Back
Top