{"id":19031195,"date":"2026-09-28T11:48:21","date_gmt":"2026-09-28T11:48:21","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/are-these-some-good-security-steps\/"},"modified":"2026-09-28T13:33:16","modified_gmt":"2026-09-28T13:33:16","slug":"are-these-some-good-security-steps","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/are-these-some-good-security-steps\/","title":{"rendered":"are these some good security steps?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I&#8217;m running on a small budget, and I want to get rid of my paid security plugin. I&#8217;m on an Apache server on Dreamhost. I asked Gemini how to harden my site, and it suggested the following. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Note that my site works fine, these are just proactive measures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;d like to know if these suggestions are reasonable. I&#8217;m not afraid to get my hands dirty with code. I don&#8217;t if there are any members of this forum expert in code, but I thought I would give it a shot.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some changes to <code>wp-config.php<\/code>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>define( 'DISALLOW_FILE_EDIT', true ); \/\/ Gemini suggestion<br \/>define('FORCE_SSL_ADMIN', true); \/\/ Gemini suggestion<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">I changed file permissions on wp-config.php to 600 to prevent other users from editing it. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I installed a lightweight, free 2FA plugin.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I use Cloudflare and added a security WAF rule creating a challenge on wp-login.php.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I made some <code>.htaccess<\/code> changes:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, to disallow directory browsing:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><code>Options -Indexes<\/code><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then, to disallow viewing or changing <code>wp-config.php<\/code>, to disable access to <code>xml-rpc.php<\/code>, and to prevent certain injection tricks:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;FilesMatch \"^(wp-config\\.php|readme\\.html|license\\.txt)\"&gt;<br \/>  Order allow,deny<br \/>  Deny from all<br \/>&lt;\/FilesMatch&gt;<br \/>&lt;Files xml-rpc.php&gt;<br \/>  Order allow,deny<br \/>  Deny from all<br \/>&lt;\/Files&gt;<br \/>RewriteEngine On<br \/>RewriteCond %{QUERY_STRING} (&lt;|%3C).*script.*(&gt;|%3E) &#091;NC,OR]<br \/>RewriteCond %{QUERY_STRING} GLOBALS(=|\\&#091;|\\%&#091;0-9A-Z]{0,2}) &#091;OR]<br \/>RewriteCond %{QUERY_STRING} _REQUEST(=|\\&#091;|\\%&#091;0-9A-Z]{0,2})<br \/>RewriteRule ^(.*)$ index.php &#091;F]<br \/><\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Finally I added an <code>.htaccess<\/code> to the uploads directory to disallow php:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;Files *.php&gt;<br \/>  deny from all<br \/>&lt;\/Files&gt;<br \/><\/code><\/pre>\n","protected":false},"template":"","class_list":["post-19031195","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19031195","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19031195\/revisions"}],"predecessor-version":[{"id":19031292,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19031195\/revisions\/19031292"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19031195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}