1. Use strong passwords and usernames 2. Limit the number of administrator accounts 3. Invest in secure WordPress hosting 4. Use the latest recommended PHP version 5. Keep software updated
General WP Security Tips P2
6. Always take regular backups 7. Don’t install shady third party plugins and themes 8. Encrypt sensitive information with an SSL Certificate 9. Keep computers up to date with antivirus software
WP Security with Plugins
10. Enable two-factor authentication 11. Change the default WordPress login URL 12. Limit login attempts 13. Install a security plugin like Sucuri or WordFence 14. Install an anti-spam plugin like Cleantalk 15. Disable author archives with Yoast SEO
WP Security Code Snippets P1
16. Hide WordPress version number in functions.php 17. Password protect staging sites and prevent indexing 18. Disallow wp-config.php in htaccess file 19. Disallow xmlrpc.php in htaccess file 20. Block the include-only files in htaccess file
WP Security Code Snippets P2
21. Disable directory browsing in htaccess file 22. Disable theme editing in wp-config file 23. Disable error logs in wp-config file 24. Change wordpress database prefix in wp-config file 25. Change Unique Keys and Salts in wp-config file
By implementing all of the above security tips your WordPress website will be super secure.
Even if something did happen you’ll have a backup and professionals that will clean the malware for you.
If there is anything you think could be added to this list, please let me know!
• • •
Missing some Tweet in this thread? You can try to
force a refresh