Increased Security

At the moment, there is a huge attack going on against blogs using WordPress.

It’s primarily attacking the blogs who’ve kept a lot of the default settings – particularly keeping the primary user as “admin” with weak/known passwords – but still, it’s better to make sure that things are secure.

D4D™ has always been on an altered install of WordPress – mainly because I’m really bad at leaving things alone – so I’m less concerned about it, but all the same, I’ve added in a couple of security plugins just to reinforce things.  I’m also making use of Cloudflare to add another level of security.

It’s going to make things interesting for a lot of Blog Owners on the WordPress platform, though.  Basically, if you’re on WP you need to :

  1. Make sure you’re not relying on the “admin” user
    1. Add a new user to WP , give it admin rights (and a strong password)
    2. Set “admin” to have the lowest possible permissions (contributor), or delete it completely.
  2. If possible, make sure your database isn’t using the wp_ prefix for all wordpress tables.
  3. Use Cloudflare or similar
  4. Install the Limit Logins plugin
  5. If you know what you’re doing, also install the Extend WP Security plugin
  6. Take backups!

There’s other stuff along the way, but those really are the key points.


One Comment on “Increased Security”

  1. Adam says:

    Good tips! WordPress seems to be constantly under attack, which has made me a bit of a blogspot fan – even if it does invite scything criticism from my peers 🙁


Leave a Reply

Your email address will not be published. Required fields are marked *