How to Secure WordPress |
|
WordPress is so widespread that more and more developers are creating ready-made themes and plugins for it. While most of these make your site easier to use and expand its functionality, some can harbor viruses or open the door to hackers. This article will help you minimize the risk of your site being hacked and teach you how to be prepared for any situation. Rule 1: The web server, not WordPress, should be running. What do I mean by the statement: the web server should be running, not the WordPress engine? All user requests that the web server can handle should be handled by it, not WordPress. Every request to your site puts a load on it. The greater the load, the worse your site performs. In general, my recommendation will help relieve the load on caching and security plugins, meaning not only speeding up your site but also making it more secure. So, the web server should be optimized for WordPress, not the other way around. WordPress is a powerful platform, but it can be resource-intensive. If your web server isn't optimized for WordPress, it can lead to performance and availability issues. Let's look at my recommendation using a simple example to understand how your WordPress or other CMS site can become more secure and faster. The readme.html and license.txt files are located in the root folder of any WordPress installation. These are simply text files that don't affect WordPress in any way, and it's recommended to delete them immediately after installation. You don't need these files, but they help hackers determine your current WordPress version and much more, which can be useful for hacking your website. As we can see, the recommendation is correct and seemingly simple to implement. However, the same .txt files are also found in plugin directories, so they need to be deleted there as well. They will reappear after a plugin update. Furthermore, the load of hacker requests on your site can significantly slow it down. This problem can be elegantly solved in any web server, for example in Nginx, the code prohibits access to files with the extensions log, txt, sql in any directory of your site. location ~ \.(log|txt|sql)$ { deny all; access_log off; log_not_found off;} We've secured your site with this line of code. The next line of code will also speed up your site by disabling access to the xmlrpc.php file, which is used for remote access to your site: location = /xmlrpc.php { deny all; access_log off; log_not_found off;} Rule 2: Enable automatic updates for your engine, plugins, and themes Starting with version 5.5, WordPress has a built-in automatic update feature for themes and plugins. To enable automatic theme updates: Go to "Appearance" -> "Themes," hover over the desired theme, and click "Theme Info" -> Enable automatic updates. Rule 3: Don't use nulled templates for WordPress In short, you'll end up paying the developer more to clean your site of malicious code than you'll save by installing a nulled template or plugin. Rule 4: Back up your data as often as possible Not all attacks can be prevented, but just one successful attack can destroy all the work you've put into building your website. We recommend making regular website backups. Attention There are several ways to create backups. You can manually download your website files and export the database, or, as I mentioned above, use the tools offered by your hosting plan (I used the word "plan" for a reason—hello, marketers). Another option is to use WordPress plugins, for example: BulletProof Security is a very interesting plugin for both website protection and backups. WordPress Website Security Recommendations For example, you installed plugins to test and choose the one you want to use. After choosing, be sure to delete all unnecessary ones. Delete unused plugins. <meta name="generator" content="WordPress 5.7.1" /> It's quite common to fail to keep your WordPress version up to date, which can become a weakness in your website. Knowing your WordPress version can be a huge source of damage for a hacker. To prevent WordPress version information from being displayed, add the following line to your functions.php file: remove_action('wp_head', 'wp_generator'); I use the Clearfy Pro plugin, which has settings for: Removes the meta tag from the head section. This allows attackers to find out the WordPress version installed on the site. This meta tag doesn't provide any useful functionality. After you enter your password on the site, you are sent a request for a new one-time password, which you receive via your phone number or email (or by clicking a link in the email). Therefore, even if your primary password is compromised, a hacker will not be able to access your account without access to your phone or email. Popular two-factor verification plugins for WordPress: Keyy Two-Factor Authentication allows you to log in by scanning a QR code instead of remembering your password. Google Authenticator provides two-factor authentication using the Google Authenticator app for Android, iPhone, and Blackberry. Use non-default login credentials The easiest way to set a username is when installing WordPress. However, if you already have it installed, create a new administrator account with different credentials. Log in to your WordPress dashboard Additionally, you can disable the error message about the entered username and password in the functions.php file, located in your website's current theme folder (wp-content/themes/current_theme_WordPress). However, I removed the code because it varies for different WordPress versions. To disable the error message, use the Clearfy Pro plugin or the WP Cerber Security plugin. Disable WP JSON and other features Search engines often index /wp-json/ as a subsection of a website. From an SEO perspective, the index should only include pages that drive traffic, not technical (junk) /wp-json/ pages. When disabling the WordPress REST API, keep in mind that some popular plugins use it, such as Contact Form 7. Therefore, if your contact form suddenly stops working, check to see if the REST API is disabled. There are at least two reasons to disable wp-json: security and SEO. I use the Clearfy Pro plugin to disable wp-json. Using .htaccess in Apache to improve WordPress security .htaccess is a file required for WordPress links to function correctly when using the Apache or LiteSpeed web server (Nginx does not use the .htaccess file). Without the correct entries in the .htaccess file, you will receive many 404 errors. All .htaccess settings are correct immediately after installing WordPress! You may only need to configure redirects from www and http to https. The classic way to configure these redirects is by editing the .htaccess file, but before doing so, consult your hosting provider's documentation; hosting providers often offer their own solutions for setting up redirects. # BEGIN WordPress RewriteEngine On # END WordPress List of WordPress Security Plugins I caution against using security plugins thoughtlessly! Be sure to test them on your website. They can ruin your website's layout (and I'm not confusing this with caching plugins) or block visitor access. Wordfence Security – antivirus, firewall, and malware scanner. Wordfence offers a user guide and automatic scanning options, along with a bunch of other settings. Changing Default WordPress Database Prefixes to Prevent SQL Injection Key Point: A SQL injection attack can be possible due to improper handling of input data used in SQL queries. Simply put, a plugin or theme incorrectly (insecurely) handles data entered by visitors to your site. If you're a seasoned experimenter, find a guide to changing the prefix on another website. Good luck! Go back |
| 18-09-2025, 04:53 |