Wordpress site security

Status
Not open for further replies.
A simple google search would have answered your question.
 
i think its secure by default? i mean unless u install nulled plugin/theme
 
If you are afraid of brute force attacks - then make sure you install g recaptcha on your website, and set that captcha requirement for your comment section, as well as the administrator login panel.
The captcha will be able to stop those automated bots from discovering your site, and making your site a potential in their automated routine.
Once the bot notices high failures from your site, or with captcha costs involved, that will lower your site in their potential list, and securing your site in the process.
 
There are 2 plugins you should use to secure your website. After tuning both those plugins your site would be secured.
1) All In One WP Security & Firewall - Using this plugin take care of below things.
- Change your wp-admin login path
- Change the WordPress database prefix ( let the plugin decide the prefix )
- Check database permissions
- Enable firewalls ( there are multiple options ) - My suggestion is to enable all firewall options.
- There is an option to disable PHP file editing, you can enable it so hackers cannot modify your PHP files in future but mind well, you will not be able to edit PHP files too without disabling that option.
- Check other options one by one and enable/disable as per your requirement. ( Don't worry, it's very easy to understand each options )
Plugging would show you your security score. More score is better but some features may not support your coding or theme so make changes accordingly.

2) Wordfence -
This plugin is for checking malware in your files and help to remove them
This plugin is paid plugin but you can find the nulled version from many websites.
- After installing the plugin, go step by step as it guides you.
- After setting up, scan your files. Once Scanning gets completed, it will show you infected files. You can remove the suspicious code from the files or remove file completely ( Take proper decision if you are deleting the file )
- It will show you live traffic/ attacks as well and it will block the attackers as per the rules you have set.
- If you have nulled or purchased addon, it will keep monitor your files and keep scanning files regularly and will mail you the report.

P.S. Use your intelligence to enable/disable options on both of these plugins as per your requirement. but after installing both these plugins with proper tuning, it will make your site very much secure.
 
HEY OP! This answers your question 100%
There are 2 plugins you should use to secure your website. After tuning both those plugins your site would be secured.
1) All In One WP Security & Firewall - Using this plugin take care of below things.
- Change your wp-admin login path
- Change the WordPress database prefix ( let the plugin decide the prefix )
- Check database permissions
- Enable firewalls ( there are multiple options ) - My suggestion is to enable all firewall options.
- There is an option to disable PHP file editing, you can enable it so hackers cannot modify your PHP files in future but mind well, you will not be able to edit PHP files too without disabling that option.
- Check other options one by one and enable/disable as per your requirement. ( Don't worry, it's very easy to understand each options )
Plugging would show you your security score. More score is better but some features may not support your coding or theme so make changes accordingly.

2) Wordfence -
This plugin is for checking malware in your files and help to remove them
This plugin is paid plugin but you can find the nulled version from many websites.
- After installing the plugin, go step by step as it guides you.
- After setting up, scan your files. Once Scanning gets completed, it will show you infected files. You can remove the suspicious code from the files or remove file completely ( Take proper decision if you are deleting the file )
- It will show you live traffic/ attacks as well and it will block the attackers as per the rules you have set.
- If you have nulled or purchased addon, it will keep monitor your files and keep scanning files regularly and will mail you the report.

P.S. Use your intelligence to enable/disable options on both of these plugins as per your requirement. but after installing both these plugins with proper tuning, it will make your site very much secure.
 
Wordpress tips can all be referred to online. Choosing the best Wordpress security plugin would be one.
 
  1. use jetpack plugin
  2. using dedicated server may also protect your wrodpress site
  3. try to get the htaccess hidden in your cpanel
 
How to secure my wordpress website?

Generally, the fewer plugins / themes / etc you install the safer you are. Most people who were hacked lost through some 3rd party item, not through the core software.
 
There are several plugins, install one and the site will be safe for you
 
Generally, the fewer plugins / themes / etc you install the safer you are. Most people who were hacked lost through some 3rd party item, not through the core software.

why do you guys continue to reply to a question asked in 2018
and the person who made this thread hasnt posted on it
since 2018 either.

old inactive thread.

Thread closed.
 
Status
Not open for further replies.
Back
Top