are these some good security steps?
-
I’m running on a small budget, and I want to get rid of my paid security plugin. I’m on an Apache server on Dreamhost. I asked Gemini how to harden my site, and it suggested the following.
Note that my site works fine, these are just proactive measures.
I’d like to know if these suggestions are reasonable. I’m not afraid to get my hands dirty with code. I don’t if there are any members of this forum expert in code, but I thought I would give it a shot.
Some changes to
wp-config.php:define( 'DISALLOW_FILE_EDIT', true ); // Gemini suggestion
define('FORCE_SSL_ADMIN', true); // Gemini suggestionI changed file permissions on wp-config.php to 600 to prevent other users from editing it.
I installed a lightweight, free 2FA plugin.
I use Cloudflare and added a security WAF rule creating a challenge on wp-login.php.
I made some
.htaccesschanges:First, to disallow directory browsing:
Options -IndexesThen, to disallow viewing or changing
wp-config.php, to disable access toxml-rpc.php, and to prevent certain injection tricks:<FilesMatch "^(wp-config\.php|readme\.html|license\.txt)">
Order allow,deny
Deny from all
</FilesMatch>
<Files xml-rpc.php>
Order allow,deny
Deny from all
</Files>
RewriteEngine On
RewriteCond %{QUERY_STRING} (<|%3C).*script.*(>|%3E) [NC,OR]
RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
RewriteRule ^(.*)$ index.php [F]Finally I added an
.htaccessto the uploads directory to disallow php:<Files *.php>
deny from all
</Files>The page I need help with: [log in to see the link]
You must be logged in to reply to this topic.