Could you suggest a great wordpress hardening tutorial?

MadVlad

Junior Member
Joined
Oct 13, 2011
Messages
165
Reaction score
34
Hi all,
for weeks I am strugling to keep my wordpress websites from being hacked.
Could anyone suggest a good tutorial on how to make a wordpress hack proof and secure it 100%.
The one that would include database scan and finding a possible malicious strings in a database.
 
Hacked is a strong word. What actually is happening, are you not able to find your content once hacked (and replaced by other content) or are you getting lots of spam comments or brute force attacks
 
Well, it started to eat up the CPU on the shared hosting (Hostgator) and I got the warning from the host and they've taken all the websites down. Then I started investigating and found kind of folders full of junk html files... Then I started to do some security and installed Wordfence and some other plugins, did the manual hardening of the wordpress sites. Change the salt keys, did the .htaccess files on all. Clean the sites manually. Changed all the passwords including cPanel one and Ftp one. Did much more reading but it still gets warning from wordfence plugin scan that the new files are being infected every day. Now I have a feeling that the infections come from database. But I am not sure how to check the datavbase fro the malicious code...
 
Have you reinstalled the core files from a fresh installation?
 
@cocoholo yes I bought the themes from themeforest. Well since last post I was a quite busy with figuring out things. I did update on all Wp websites plus I after that replaced wp-admin and wp-includes folders. I am using Wordfence for scanning, Sucuri for hardening, Gauntlet (for hardening), TAC to check if the code is being inserted into theme...
It seems that I am doing it right for now. In Sucuri dashboard you can see (and get a email notofication) if the file has been modified. Thats great. Around 15 websites I've done in the past week are still okay and I hope it will stay that way. But man, I went end read a hundreds of pages on the security for WP and it wasn't a quick thing. It took me well more than a month and still there is a fear that I missed some malicious code somewhere...
 
Back
Top