Wiser WebsitesWiser Websites

01582 931340

  • News
  • About
  • Home
  • Website Design
  • Services
  • Hosting
  • Work
  • Contact
Wednesday, 17 July 2019 / Published in WordPress

WordPress Security: 10 Advanced Tips Part 1

Following up from my last post offering some advice for WordPress security, there are another 10 ways to help keep your website stay safe I would like to share with you- 5 here and another 5 in my next post.

1. Remove your WordPress version number

Your current WordPress version number can be found very easily. It’s basically sitting right there in your site’s source view.

Here’s the thing: if hackers know which version of WordPress you use, it’s easier for them to tailor-build the perfect attack.

You can hide your version number with many WordPress security plugins however for a more manual approach (and to also remove the version number from RSS feeds,) consider adding the following function to your functions.php file:

function wpbeginner_remove_version() {
return '';
}
add_filter('the_generator', 'wpbeginner_remove_version');

2. Disable directory listing with .htaccess

If you create a new directory as part of your website and do not put an index.html file in it, you may be surprised to find that your visitors can get a full directory listing of everything that’s in that directory.

For example, if you create a directory called “data”, you can see everything in that directory simply by typing http://www.example.com/data/ in your browser. No password or anything is needed.

You can prevent this by adding the following line of code in your .htaccess file:

Options All -Indexes

3. Disallow file editing

If a user has admin access to your WordPress dashboard, they can edit any files that are part of your WordPress installation. This includes all plugins and themes.

If you disallow file editing, no one will be able to modify any of the files – even if a hacker obtains admin access to your WordPress dashboard.

To make this work, add the following to the wp-config.php file (at the very end):

define('DISALLOW_FILE_EDIT', true);

4. Change the WordPress database table prefix

If you have ever installed WordPress then you are familiar with the wp- table prefix that is used by the WordPress database. I recommend you change it to something unique.

Using the default prefix makes your site database prone to SQL injection attacks. Such attacks can be prevented by changing wp- to some other term. For instance, you can make it mywp- or wpnew-.

5. Monitor your audit logs

When you’re running WordPress multisite, or handling a multi-author website, it’s essential to understand what type of user activity is going on.

Your writers and contributors might be changing passwords, but there are other things you might not want to happen.

For instance, theme and widget changes are obviously only reserved for the admins. Make sure your super admin or site host is checking the audit logs of your site to make sure that your admins and contributors are not trying to change something on your site without approval.

What you can read next

WordPress Security: 10 Advanced Tips Part 2
WordPress Security: Myths and Realities
8 WordPress Security Tips for 2019

Recent Posts

  • The History of YouTube

    The rise and rise of YouTube continues, it has ...
  • National womens equality day – Women in tech

    International Women’s Day 2025 – Women in Tech:...
  • 6 Positive Impacts of Technology on Daily Life in 2025

    6 Positive Impacts of Technology on Daily Life ...
  • Spanish ‘beach body’ ad gets complaints over image used.

    A Spanish body confidence ad was published in J...
  • 7760

    What Is YouTube and How Can You Leverage Its Po...

Get updates and SEO advice

COMPANY

  • Frequently Asked Questions
  • Why Choose Wiser Websites
  • Why Choose WordPress
  • Website Consultancy
  • Charity Work

WEB DESIGN & OPTIMSATION

  • Search Engine Optimisation
  • Best Local Listing Sites
  • Business Listings & Maps
  • Website Analysis
  • Website Features

HOSTING & SECURITY

  • Hosting Platform Technologies
  • Frequently Asked Questions
  • SSL Certificates

FOLLOW US

SUBSCRIBE

Add your email to join our newsletter

TOP