WordPress.org

Ready to get started?Download WordPress

Forums

Wordfence Security
wp-admin htpasswd login field home page (5 posts)

  1. iivvvii
    Member
    Posted 1 year ago #

    For extra security I have set a htaccess pasword for the wp-admin folder. But now I get a login box on the homepage and I think this is because wordfence is loading te following file:

    <script type="text/javascript">var src="http://***.nl/wp-admin/admin-ajax.php?action=wordfence_logHuman&hid=F******************************B"; if(window.location.protocol == "https:"){ src = src.replace("http:", "https:"); } var wfHTImg = new Image(); wfHTImg.src=src;</script>

    What can I do about this?

    http://wordpress.org/extend/plugins/wordfence/

  2. RobinInTexas
    Member
    Posted 1 year ago #

    I have the same problem, I disabled wordfence.

  3. RobinInTexas
    Member
    Posted 1 year ago #

    And I turned Wordfence back on.

    For anybody else that wants to restore Basic Auth to the admin area, here's my workaround that seems to work:

    <FilesMatch "^(admin|dashboard|index|admin-header|admin-footer|edit|edit-tags|options-reading|site-new|user-new|users|sites|tools|post|upload|themes|post-new|widgets|nav-menus).php$">
    AuthName "WrodPress"
    AuthType Basic
    AuthUserFile /var/www/vhosts/mysite.com/htpass
    Require valid-user
    </FilesMatch>

    For those who miss the significance, the password file is outside the
    AuthUserFile /var/www/vhosts/mysite.com/htpass
    web hierarchy,
    AuthUserFile /var/www/vhosts/mysite.com/httpdocs/
    This is a second .htaccess file located in the wp-admin directory, the

    <files ~ "^.*\.([Hh][Tt][Aa])">
    order allow,deny
    deny from all
    </files>

    is located in the primary .htaccess in the web root

  4. iivvvii
    Member
    Posted 1 year ago #

    I fixed it by adding this code after the normal password protection htaccess:

    <FilesMatch "admin-ajax.php">
      Satisfy Any
      Allow from all
    </FilesMatch>
  5. RobinInTexas
    Member
    Posted 1 year ago #

    I like yours better, but I don't think I need to change mine again. I imagine as time goes on, there will be another library needed.

Topic Closed

This topic has been closed to new replies.

About this Plugin

About this Topic