• I’m running on a small budget, and I want to get rid of my paid security plugin. I’m on an Apache server on Dreamhost. I asked Gemini how to harden my site, and it suggested the following.

    Note that my site works fine, these are just proactive measures.

    I’d like to know if these suggestions are reasonable. I’m not afraid to get my hands dirty with code. I don’t if there are any members of this forum expert in code, but I thought I would give it a shot.

    Some changes to wp-config.php:

    define( 'DISALLOW_FILE_EDIT', true ); // Gemini suggestion
    define('FORCE_SSL_ADMIN', true); // Gemini suggestion

    I changed file permissions on wp-config.php to 600 to prevent other users from editing it.

    I installed a lightweight, free 2FA plugin.

    I use Cloudflare and added a security WAF rule creating a challenge on wp-login.php.

    I made some .htaccess changes:

    First, to disallow directory browsing:

    Options -Indexes

    Then, to disallow viewing or changing wp-config.php, to disable access to xml-rpc.php, and to prevent certain injection tricks:

    <FilesMatch "^(wp-config\.php|readme\.html|license\.txt)">
    Order allow,deny
    Deny from all
    </FilesMatch>
    <Files xml-rpc.php>
    Order allow,deny
    Deny from all
    </Files>
    RewriteEngine On
    RewriteCond %{QUERY_STRING} (<|%3C).*script.*(>|%3E) [NC,OR]
    RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
    RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
    RewriteRule ^(.*)$ index.php [F]

    Finally I added an .htaccess to the uploads directory to disallow php:

    <Files *.php>
    deny from all
    </Files>

    The page I need help with: [log in to see the link]

Viewing 2 replies - 1 through 2 (of 2 total)
  • Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    I’d like to know if these suggestions are reasonable. 

    Yes.

    See this for a more comprehensive list. Doing all that may make your updating less user friendly but it’s a good doc.

    https://developer.wordpress.org/advanced-administration/security/hardening/

    • This reply was modified 6 days ago by Jan Dembowski. Reason: Had more coffee and added link
    Thread Starter michaelmossey

    (@michaelmossey)

    @jdembowski Thank you! I’ll check that out.

    I realize that updates might require me to change some of this again after the update, but I’m keeping an organized “cheatsheet” of all the changes I made, and can make them again quickly,

    Also I forgot to mention that I use Duplicator Lite to back up after every change to my site. I don’t have users or anything that changes daily. So if I’m hacked, the important thing is that I check my site daily to make sure it’s still up, then if not, I would just restore it from the latest backup (and contact Dreamhost tech support to get help wiping out the attack).

Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.