MANAGING YOUR WORDPRESS SECURITY TIPS
A STEP BY STEP GUIDE
BY
MADHAN KUMAR
TABLE OF CONTENTS
INTRODUCTION
Chapter 1: Why and How to Protect Your WordPress website
Number 1: An essential measure: The use of a "strong" password
Number 2: Blocking brute force attacks
Number 3: Never use the WordPress "admin" account.
Number 4: Limit the number of administrator accounts on your site and force users to choose strong passwords.
Number 5: Changing the WordPress back office access URLs (wp-admin and wp-login)
Number 6: Hide the WordPress version you are using
Number 7: Change database prefix
Number 8: Hide the true IP address of your site with CloudFlare
Number 9: Get your site to HTTPS with CloudFlare
Number 10: Disabling the XML-RPC interface
Number 11: Blocking navigation of your WordPress folders
Number 12: Disabling the File Editor
Number 13: Disabling the execution of PHP files in certain WordPress directories
Number 14: The Role of Hosting Your WordPress website
Number 15: Moving your PhpMyAdmin
Number 16: Be careful with the themes and plugins you install
Number 17: Make backups
Chapter 2: How do you recognize a hacked WordPress site?
How to monitor your site?
How do you know if your site has been hacked?
Conclusion
Acknowledgements
ANNEXES
INTRODUCTION
Why this book?
As of late, WordPress has become the most generally utilized Content Management System (or CMS) on the world. Actually, as per the most recent W3Techs indicator, WordPress now controls over 30% of the sites on the world!
WordPress has numerous focal points, it is an open source, free, and the network and distributers have created modules to do everything: informal organization joining, gathering, web based business site, online installment, photograph exhibition, media player, SEO, schedule, overview, inn booking... Its utilization has been very democratized by the numerous books and sites that are prospering and that clarify bit by bit how to introduce it, how to begin and manufacture your first site with WordPress, how to tweak your WordPress site, construct an internet business website, and so forth... It is even conceivable to utilize subjects (free or paid) to get, in a couple of snaps, an expert site deserving of a web office.
To put it plainly, it currently appears to be unthinkable not to consider WordPress with regards to building sites, particularly on the off chance that you are not an expert in the field of web improvement, since you will have the option to put an excellent site online without composing a solitary line of code.
Be that as it may, there is another side to this decoration, once in a while referenced, which persuaded the composition of this book: the PC security of WordPress destinations. Without a doubt, similar to all PC hacking, WordPress has security blemishes. Naturally initiated security refreshes are insufficient to take care of the issue since they don't cover the numerous weaknesses in the modules and subjects that are the duty of their particular distributers. In addition, some security openings are not specialized but rather "human, for example, utilizing the WordPress administrator account with a trifling or effectively crackable password, for example, "admin123".
Since WordPress is broadly conveyed far and wide and regularly utilized by novice website admins, sites that utilization it are legitimately exceptionally presented to assaults by hacker from around the globe. These hacker consistently prevail with regards to doing a great deal of harm in light of the fact that the principles of the exchange and great practices as far as PC security have not been applied. Among the CMS locales hacked a year ago, 90% were WordPress destinations!
Building sites with WordPress for as far back as 10 years, I have regularly seen the absence of information on security issues while "cleaning" and making sure about hacked sites. This genuine absence of information persuaded me to compose this book. I will probably democratize great security rehearses and to propose solid activities, simple to acknowledge on your WordPress webpage to altogether reinforce your site against assaults.
Regardless of whether your site isn't that of a worldwide organization, it is probably going to be assaulted. All things considered, hacker dispatch computerized contents (or hacking robots) that misuse the defects in WordPress or certain modules for:
- Adding inappropriate content to the website (e.g. links to illegal websites)
- Adding spam comments
- Destroying the content of the website
- Crashing the website or slow down the website (this is called a Denial of Service attack or DoS attack)
- Extract information (example: retrieve the list of emails of people who have left a comment)
- Injecting invisible scripts that will infect the browsers of users visiting your site
The instruments and working strategies to complete these vindictive activities are sadly effectively available on the Internet and it is not, at this point important to be an accomplished PC expert to do hacking activities. Somebody can botch your site, for no particular reason, to hurt you, or take data about your clients (I will return to this later).
Who is this book for?
You don't should be a PC wizard to peruse and apply the standards and activities clarified in this book. Like the numerous books on WordPress, I needed this one to be justifiable and appropriate by the best number of individuals. My objective is that however many destinations as could reasonably be expected ought to be safer! The specialized viewpoints are therefore all around clarified and PC per users will discover the chance to reexamine, and possibly some of the time, another perspective regarding a matter definitely known.
What will you find in this book?
I needed this book to be useful and simple to utilize, provided that you read it without actualizing the allots set in it, it will be pointless! That is the reason it has been imagined as a progression of short parts disclosing why and how to shield yourself from a particular proviso. I have set specific significance on clarifying the ideas utilized by the assailants so you comprehend why I am suggesting one measure or the other.
Fixing a few weaknesses requires modules, while for other people, it isn't fundamental. In the event that vital, I will consistently propose to you free modules (or freemium) to ensure your site.
You will see that I have point by point bit by bit the settings or design changes to be made. To support you, when essential, I've incorporated screen captures, however WordPress and its modules advance rapidly and regardless of whether the menus and areas continue as before, you may discover disparities between the screen captures in this book and what you'll see at home.
I send you an email with all the settings to copy/paste
To make things simpler, I propose to send you by email all the settings and connections to the modules that are referenced in this book. You should simply duplicate/glue the settings into your WordPress example and you will stay away from a dull re-composing of the lines in the book. To do this, send an email to bonus4wp@gmx.com with "Reward WP" in the headline, and I will send you a message with all the data.
By the way, who am I?
My name is Thomas Person and I am a PC engineer with 18 years of experience. I am right now taking a shot at IT security issues in an enormous organization. In corresponding to my work, I have been utilizing WordPress since 2010, first to make individual destinations, at that point for loved ones, and now for "genuine" customers with whom I sign agreements.