Confirmed. WPEngine will not be allowing local install nginx configurations.
Hi Kevin,
You may be interested in reading What Rules are Enforced by the .htaccess File in iThemes Security (Pro)?
The article is a bit outdated (and missing 1 entry) so below an updated list for the current iTSec release:
Security> Settings> Features> Lockouts> Ban Users> Default Ban List
Security> Settings> Advanced> System Tweaks> Protect System Files
Security> Settings> Advanced> System Tweaks> Disable Directory Browsing
Security> Settings> Advanced> System Tweaks> Disable PHP in Uploads
Security> Settings> Advanced> System Tweaks> Disable PHP in Plugins
Security> Settings> Advanced> System Tweaks> Disable PHP in Themes
Security> Settings> Advanced> WordPress Tweaks> XML-RPC (Disable XML-RPC)
As you can see WPEngine’s decision has little impact on the iTSec plugin’s features.(Even less after the iTSec plugin 8.0 release since many System/WordPress Tweaks settings, which all added rules to the .htaccess file, have been removed.)
Also note that the iTSec plugin most important features (like strong passwords, two-factor authentication and Brute Force Protection) are unaffected.
Personally, the only one I would really hate to miss is disabling XML-RPC. But that setting not only adds rules to the .htaccess file but hooks into the WordPress core xmlrpc_enabled filter as well (possibly as a fallback mechanism).
+++++ To prevent any confusion, I’m not iThemes +++++
Thanks @nlpro
Aye, I’m aware of those. Honestly those Ban List rules make up the bulk of the protections for our sites.
It’s always better to have the server software itself do the blocking than it is to have WordPress or even any php do the processing. Cuts down on PHP processes overloading the servers.
I’m hopeful with 8.0, that there are indeed items put in place to circumvent, or the iThemes team is in talks with WPEngine, however, I may be removing this off of 2000+ websites (40% of those are Pro plugins… hate to have to drop that much business from iThemes…)
-
This reply was modified 4 years, 9 months ago by
Kevin Pirnie.
I would be ok with the plugin even generating those rules in a copy/paste text area. At least then we would be able to send that off to WPE to have implemented. However, the way the WPE system is now, you either import the rules through them, or you enter them yourself 1 by 1, and that’s just not feasible.
I would be ok with the plugin even generating those rules in a copy/paste text area.
The iTSec plugin has got you covered.
Security > Settings > Tools -> Server Config Rules