Here are some great tips from Ken Dawes’ presentation “How to Improve Wordpress Security“. Ken was a guest speaker in Rebecca Holman’s class More WordPress-Tweaks, Tricks and Marketing Ideas.
Check out Ken’s website for more about his service offerings.
- Delete user “admin” – create a new admin account first
- change first and last name and nickname
- Choose a secure password – don’t use the word “password”
- Login LockDown plugin
- Check your Theme for the tinthumb update
- AntiVirus plugin
- WordPress Firewall 2 plugin – you’ll have to add your own ip address to edit your site
- Block Bad Queries (BBQ) plugin
- Update Unique Keys plugin – logout and log back in again
- Growmap Anti Spambot Plugin – alternative for Akismet
- BulletProof Security plugin
Other non security
- permalinks -custom /%post_id%/%postname%/
- use a 404 redirect plugin if you already had a lot of links
- Core Tweaks WordPress Setup – cleanup first installations (sitemap etc.)
- WP-DBManager plugin – alternative to WP-DB-Backup
- Filezilla - ftp (file transfer protocol) manager – to backup all your media files such as images and pdf’s
Another Security Plugin that is widely used:
- WP Security Scan plugin – set and forget
Share on Facebook
