New Posts
Live Radio
Welcome guest, is this your first visit?
  • Login:
Gr88.com Affiliate Program
+ Reply to Thread
Results 1 to 5 of 5
Like Tree2Likes
  • 2 Post By Matt Geer

Thread: Add security to your Wordpress website.

  1. #1
    Writer-Photoshop Newbie
    My Status
     

    Add as a friend
    Join Date
    Feb 2009
    Location
    Vancouver, Wa
    Posts
    639
    Blog Entries
    1
    Feedback Score
    21 (100%)

    Default Add security to your Wordpress website.

    I've been doing some research on how to make my sites that use Wordpress more secure. I thought I'd share something that I came across today.

    You can read it here.

    #2 is what stood out the most to me. Take the code that they give you ^, place it in a .htaccess file and drop it into your /wp-admin/ folder. When you go to: xhttp://www.yoursite.com/wp-admin/ and the IP address is wrong (or not there), it takes you straight to a 404 page. Correct the IP address and you'll be taken to the standard /wp-admin/ login page.

    Since I'm still doing research I'm not sure if this is the most optimal method (I think you should use more than one anyway), but at first glance it looks like it can be a good addition to your overall security efforts.
    PokerFelts and yeahfree2 like this.

  2. #2
    Senior Member
    My Status
     

    Add as a friend
    Join Date
    Apr 2009
    Location
    England
    Posts
    545
    Blog Entries
    3
    Feedback Score
    25 (100%)

    Default

    Great share Matt, think i might implement this in the morning.

  3. #3
    Senior Member
    My Status
     

    Add as a friend
    Join Date
    Nov 2008
    Location
    USA
    Posts
    426
    Feedback Score
    8 (100%)

    Default

    Keep in mind that doing this pretty much kills your ability to work on your site from "anywhere". Unless you have a VPN setup, such that your IP address never changes no matter where you are.

    It certainly adds security, but there is a downside.

  4. #4
    Writer-Photoshop Newbie
    My Status
     

    Add as a friend
    Join Date
    Feb 2009
    Location
    Vancouver, Wa
    Posts
    639
    Blog Entries
    1
    Feedback Score
    21 (100%)

    Default

    Yeah, that's a good point. But how hard is that to take care of?

    - Go to What is My IP
    - Open your FTP, edit your .htaccess
    - Login

    Less than 5 minutes?

    Granted, it won't be the perfect solution for everyone, but assuming you're not mobile it's far from inconvenient IMO. Especially given the upsides and that you could probably avoid using plugins such as Limit Login Attempts or something similar.

  5. #5
    Senior Member
    Rebmem Roines
     

    Add as a friend
    Join Date
    Nov 2008
    Location
    US
    Posts
    959
    Feedback Score
    23 (100%)

    Default

    Good thread from OP. I personally don't want to go through that (I am mobile) every time I want to log in to one of dozens of WP sites I work on, but that's just me.

    I think WP has a pretty good guide:

    Hardening WordPress « WordPress Codex

    Changing the admin user name and locking down the uploads folder are the first things I'd do if I were worried.

    I think using as few plugins as possible and trying to write your own when you need some functionality is also key. But really, if you just update everything religiously and choose secure admin names / passwords, you should be fine.


 

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
Powered by vBulletin® Version 4.1.5
Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.
SEO by vBSEO 3.6.0
Affiliate Program Consultant