SlideShare a Scribd company logo
WordPress Security using
iThemes Security
Jason Yingling | Lead Developer
Red8 Interactive | red8interactive.com
@jason_yingling | jasonyingling.me
HHAM
β€’ Hosting
β€’ Hardening
β€’ Access
β€’ Maintenance
WordPress Hosting
β€’ Support for latest software
β€’ Optimized for running
WordPress
β€’ Malware scanning
β€’ Work with WordPress 24/7
β€’ Backups
Hardening
β€’ Protecting your site from common security
risks
– Don’t use the β€˜admin’ username
– Strong passwords
– Hide the login area
– Brute Force Protection
– 404 Protection
– Malware scanning
Access
β€’ Minimize number of administrators
β€’ Remove file editing from dashboard
β€’ Two Factor Authentication
Maintenance
β€’ Keep WordPress up to date
β€’ Keep plugins up to date
β€’ Remove unused themes and plugins
iThemes Security
iThemes Landing Page
β€’ Broken down into high priority, medium
priority, and low priority
Global Settings
β€’ Write to wp-
config.php
β€’ Emails for
lockout
notifications,
file change
warnings, etc.
Global Settings
β€’ Error messages
to display to
locked out
users
Global Settings
β€’ Enables blacklisting repeat offenders
β€’ Good idea to switch these up from the
defaults
Global Settings
β€’ Enables blacklisting repeat offenders
β€’ Good idea to switch these up from the
defaults
404 Detection
β€’ Blocks attacker for scanning for known
vulnerabilities
Away Mode
β€’ Allows for disabling
access to the
dashboard between
certain hours
β€’ Do you really need
to be able to edit
24/7?
β€’ Taking a vacation
Banned Users
β€’ Enable
HackRepair.com’s
blacklist feature
β€’ Enable Ban Users
β€’ Permanently bans
attackers IPs
Brute Force Protection
β€’ Limit the number of
bad login attempts
before temporarily
locking out the
offending host
Brute Force Protection
β€’ Switch it up from the
default
β€’ 4 Max Login Attempts
Per Host
β€’ 9 Max Login Attempts
Per User
β€’ 6 Minutes to
Remember Bad Login
Database Backups
β€’ Sends a database backup via email or stores
on server
β€’ Plugins
– BackupBuddy
– BackWPUp
– WPmudev Snapshot
– VaultPress
File Change Detection
β€’ Allows you to
include and exclude
specific files that
may change often
β€’ Helpful to see what
files were changed if
an attack happens
Hide Login Area
β€’ Change login url
from /wp-admin
β€’ Makes it more
difficult for
attacker to find
login area
β€’ Avoid using
iThemes default
/wplogin
SSL
β€’ Requires SSL setup on server
β€’ Allows you to force SSL for Dashboard
Strong Passwords
β€’ Enables you to force strong passwords for
users for certain user roles
System Tweaks
β€’ Some of this
may be
performed by
your host
β€’ Good idea to
have on unless
you know
something
conflicts on your
site
WordPress Tweaks
WordPress Tweaks
WordPress Tweaks
Advanced Settings
β€’ Change name
of β€˜admin’
user
β€’ Change user
with id of 1
Advanced Settings
β€’ Change WordPress salts
Advanced Settings
β€’ Change name
of wp-content
directory
β€’ Not necessary
on most WP
specific hosts
Advanced Settings
β€’ Change database prefix to make your tables
harder to find
iThemes Security Pro
β€’ Allow you to temporarily bump a users access
iThemes Security Pro
β€’ More password
options
β€’ Password
generator on
user profile
β€’ Password
expiration
β€’ Force password
change
iThemes Security Pro
β€’ Use Google’s
reCAPTCHA for
login,
registration,
and
commenting
iThemes Security Pro
β€’ Allow users to
setup Two Factor
Authentication
using Google
Authenticator
app
iThemes Security Pro
β€’ Log user activities at a certain role such as login,
saving content, and more
Locked yourself out?
β€’ Login to your database via phpMyAdmin or a
program like Sequel Pro
β€’ Navigate to the itsec_lockouts table
β€’ Delete the row with your IP
Locked yourself out?
β€’ Disable plugin via FTP
β€’ Navigate to /wp-content/plugins
β€’ Rename the ithemes-security plugin directory
Questions?
β€’ Jason Yingling | Red8 Interactive
β€’ @jason_yingling
β€’ http://jasonyingling.me

More Related Content

PPTX
Speeding Up WordPress sites
KEY
Exploring WordPress Multisite
PPT
WordPress Multisite
PDF
Launching a WordPress Site 101 (Cincinnati WordPress, August 2015)
KEY
Understanding WordPress Multisite
PPTX
Optimizing WordPress - WordPress SF Meetup April 2012
PPTX
Managing Multisite: Lessons from a Large Network
PPTX
Multisite core concepts final
Speeding Up WordPress sites
Exploring WordPress Multisite
WordPress Multisite
Launching a WordPress Site 101 (Cincinnati WordPress, August 2015)
Understanding WordPress Multisite
Optimizing WordPress - WordPress SF Meetup April 2012
Managing Multisite: Lessons from a Large Network
Multisite core concepts final

What's hot (20)

PDF
WordPress Server Security
PPTX
Presentation to SAIT Students - Dec 2013
PPTX
Piecing Together the WordPress Puzzle
PPTX
I Can Haz More Performanz?
PPTX
Wordpress For Begineer
PDF
WordPress Website Creation Training Course Slides
PDF
Speeding up your WordPress Site - WordCamp Toronto 2015
PDF
The WordPress Way
PPTX
Optimizing WordPress (WordCamp Philly 2011)
PDF
Best Friend || Worst Enemy: WordPress Multisite
PPT
WordPress Fav Plugins & Security
PPTX
WordCamp Boston WordPress plugins-8-2014
PDF
WordPress Intermediate Workshop
PPTX
Squeeze Maximum Performance From Your Joomla Website
PDF
Wp maintenance and Security
KEY
WordPress Security
PPTX
WordPress Resources Nov 2014
PPTX
WordPress(The Big Picture)
PPTX
The Power of a Video Library - WordCamp Raleigh
PPTX
HyperDB, MySQL Performance, & Flavors of MySQL
WordPress Server Security
Presentation to SAIT Students - Dec 2013
Piecing Together the WordPress Puzzle
I Can Haz More Performanz?
Wordpress For Begineer
WordPress Website Creation Training Course Slides
Speeding up your WordPress Site - WordCamp Toronto 2015
The WordPress Way
Optimizing WordPress (WordCamp Philly 2011)
Best Friend || Worst Enemy: WordPress Multisite
WordPress Fav Plugins & Security
WordCamp Boston WordPress plugins-8-2014
WordPress Intermediate Workshop
Squeeze Maximum Performance From Your Joomla Website
Wp maintenance and Security
WordPress Security
WordPress Resources Nov 2014
WordPress(The Big Picture)
The Power of a Video Library - WordCamp Raleigh
HyperDB, MySQL Performance, & Flavors of MySQL
Ad

Viewers also liked (14)

PDF
WordPress Custom Post Types
PPTX
Creating Dynamic Sidebars & Widgets in WordPress
KEY
Doing Things the WordPress Way
PDF
Managing_WordPress_Projects_wcstl 2015_Lucas_Lima
PDF
Wordpress as a Backend
PPTX
Getting to Know Underscores
PPTX
Teresa Lane - Content Modeling - WordCamp St. Louis 2016
PPTX
Building a Simple Project Plan for WordPress Projects
PDF
Passwords, Attakcks, and Security, oh my!
PDF
Ryan Markel - WordCamp StL 2016 - Code Review
PDF
How to Make the Most out of Yoast SEO
PPTX
(( Lucas lima )) Managing WordPress Projects - STL Meetup August 2015
PPTX
Automating WordPress Plugin Development with Gulp
PDF
How to Become a Thought Leader in Your Niche
WordPress Custom Post Types
Creating Dynamic Sidebars & Widgets in WordPress
Doing Things the WordPress Way
Managing_WordPress_Projects_wcstl 2015_Lucas_Lima
Wordpress as a Backend
Getting to Know Underscores
Teresa Lane - Content Modeling - WordCamp St. Louis 2016
Building a Simple Project Plan for WordPress Projects
Passwords, Attakcks, and Security, oh my!
Ryan Markel - WordCamp StL 2016 - Code Review
How to Make the Most out of Yoast SEO
(( Lucas lima )) Managing WordPress Projects - STL Meetup August 2015
Automating WordPress Plugin Development with Gulp
How to Become a Thought Leader in Your Niche
Ad

Similar to Ithemes presentation (20)

PDF
Protect Your WordPress Website - Setting Up IThemes Security
PDF
WordPress Security is like a HHAM Sandwich
PPTX
WordPress Security Updated - NYC Meetup 2009
PPT
WordPress Security - WordCamp Boston 2010
PPT
WordPress Security - WordCamp NYC 2009
PPTX
WordPress Security - WordPress Meetup Copenhagen 2013
PDF
Types of Security Threats WordPress Websites Face: Part-1
PPTX
WordPress Plugins and Security
PPT
WordPress Security
PDF
WordPress Security - 12 WordPress Security Fundamentals
PDF
Word camp2011 introwordpresssecurity
KEY
Securing WordPress by Jeff Hoffman
PPTX
WordPress Security
PPT
Now That's What I Call WordPress Security 2010
PPTX
WordPress Security Fundamentals - WordCamp Biratnagar 2018
PDF
ResellerClub Ctrl+F5 - WordPress Security session
PDF
WordPress Security 101: Practical Techniques & Best Practices
PPTX
Security Function
PPT
Securing Word Press Blog
PDF
Word press beirut 9th meetup march
Protect Your WordPress Website - Setting Up IThemes Security
WordPress Security is like a HHAM Sandwich
WordPress Security Updated - NYC Meetup 2009
WordPress Security - WordCamp Boston 2010
WordPress Security - WordCamp NYC 2009
WordPress Security - WordPress Meetup Copenhagen 2013
Types of Security Threats WordPress Websites Face: Part-1
WordPress Plugins and Security
WordPress Security
WordPress Security - 12 WordPress Security Fundamentals
Word camp2011 introwordpresssecurity
Securing WordPress by Jeff Hoffman
WordPress Security
Now That's What I Call WordPress Security 2010
WordPress Security Fundamentals - WordCamp Biratnagar 2018
ResellerClub Ctrl+F5 - WordPress Security session
WordPress Security 101: Practical Techniques & Best Practices
Security Function
Securing Word Press Blog
Word press beirut 9th meetup march

More from Jason Yingling (11)

PDF
WordPress Security Best Practices
PPTX
Installing WP-CLI locally
PPTX
Getting Started with Gutenberg Development
PPTX
Plugin development
PPTX
Introducing CSS Grid
PPTX
Customizing the WordPress Customizer
PDF
Battling Google PageSpeed Insights
PPTX
Putting the Develop in Development
PPTX
WordPress Template hierarchy
PPTX
Design todevelop
PPTX
Building Flexible Sites with Advanced Custom Fields
WordPress Security Best Practices
Installing WP-CLI locally
Getting Started with Gutenberg Development
Plugin development
Introducing CSS Grid
Customizing the WordPress Customizer
Battling Google PageSpeed Insights
Putting the Develop in Development
WordPress Template hierarchy
Design todevelop
Building Flexible Sites with Advanced Custom Fields

Recently uploaded (20)

PPTX
presentation_pfe-universite-molay-seltan.pptx
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
DOCX
Unit-3 cyber security network security of internet system
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PDF
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
PDF
Triggering QUIC, presented by Geoff Huston at IETF 123
Β 
PDF
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
PDF
The Internet -By the Numbers, Sri Lanka Edition
Β 
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
PPTX
introduction about ICD -10 & ICD-11 ppt.pptx
PDF
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
Β 
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PPTX
Slides PPTX World Game (s) Eco Economic Epochs.pptx
PPTX
international classification of diseases ICD-10 review PPT.pptx
PPTX
INTERNET------BASICS-------UPDATED PPT PRESENTATION
PPTX
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PDF
Unit-1 introduction to cyber security discuss about how to secure a system
PPTX
innovation process that make everything different.pptx
PPTX
artificial intelligence overview of it and more
presentation_pfe-universite-molay-seltan.pptx
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
Unit-3 cyber security network security of internet system
Job_Card_System_Styled_lorem_ipsum_.pptx
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
Triggering QUIC, presented by Geoff Huston at IETF 123
Β 
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
The Internet -By the Numbers, Sri Lanka Edition
Β 
Introuction about ICD -10 and ICD-11 PPT.pptx
introduction about ICD -10 & ICD-11 ppt.pptx
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
Β 
SASE Traffic Flow - ZTNA Connector-1.pdf
Slides PPTX World Game (s) Eco Economic Epochs.pptx
international classification of diseases ICD-10 review PPT.pptx
INTERNET------BASICS-------UPDATED PPT PRESENTATION
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
The New Creative Director: How AI Tools for Social Media Content Creation Are...
Unit-1 introduction to cyber security discuss about how to secure a system
innovation process that make everything different.pptx
artificial intelligence overview of it and more

Ithemes presentation

Editor's Notes

  • #3: 4 key components to WP security
  • #4: We use WP Engine. They keep daily backups for 30 days and have a partnership with Sucuri for scanning havked sites and fixing issues
  • #6: This gives attackers less avenues for gaining access.
  • #8: - Formerly BetterWPSecurity (believe the free version shows up as that still in the file directory) - Upon activating iThemes Security you’ll get the important first steps screen
  • #9: Good idea to take care of high priority items
  • #10: Need to allow for iThemes to write to wp-config.php file
  • #11: - Error messages to display to users / hosts for different lockout reasons
  • #12: - Allows users / hosts to be banned for hitting a certain limit of lockouts within a certain time period
  • #13: If you’re forgetful you may want to white list your IP. - Use this sparingly
  • #14: Detects hosts that are hitting an unusually high number of 404 pages This can occur when an attacker is scanning for known vulnerabilities in plugins and themes on your site if those files don’t exist
  • #15: Let’s you completely block access to the backend during certain periods Can set up daily or one-time limits
  • #16: -Allows you to use hackrepair.coms list of known bad hosts / bots -Enabling ban users let’s you permanently ban bad hosts
  • #17: - Brute Force Protection let’s you limit the number of bad login attempts before temporarily locking out the offending host
  • #18: Good idea to avoid the iThemes defaults because as it becomes more commonly used attackers will learn the defaults (not a big thing)
  • #19: Let’s you get a copy of the database emailed or stored on the server I’d suggest using other backup software that let’s you store backups at an external source such as Dropbox or Google Drive
  • #20: Can detect if files were changed and show which files Can be annoying with plugin / theme updates
  • #21: Makes it harder for an attacker to find your login area
  • #22: -Allows you to force SSL if you have it set up on your server -
  • #23: Allows you to force users at or above a certain role to use a strong password
  • #24: Probably good to have these on for most simple WordPress sites
  • #25: Removing the generator meta tag and displaying a random version make it more difficult for an attacker to zero in on known vulnerabilities with past versions Who doesn’t want to reduce comment spam?
  • #26: -Disable the file editor hides the edit function from plugins and the Apperance menu. If you edit your theme directly form the WP-Admin you’ll want to leave the file editor on. I always edit my code from a separate program as it is more secure to have the file editor hidden.
  • #27: -I don’t mess with replacing the jQuery version as it could cause issues with themes functionality if they were built for a specific version I generally leave the login error message enabled Forcing a unique nickname helps prevent users from displaying their username within a post.
  • #28: Allows you to change the admin username if β€˜admin’ exists and change the user id if there is a user with id of 1. Both are good to do as an attacker usually knows that account has the most access
  • #29: -Salts are secret keys used by WordPress in the wp-config.php files to increase security. These can be updated from iThemes. -I generally don’t mess with this as I generate salts during the initial WordPress install
  • #30: - This one can be tricky. It’s probably unneccesary on WP specific hosts as they’ll have measures in to protect wp-content and may not even allow you to change the name of this directory
  • #31: -changing the database prefix to something other than wp_ is good to make it harder for an attacker to find your database tables
  • #32: -These are some of the pro features for the paid version - Privilege escalation let’s you temporarily increase a users privileges, say if you have a developer that needs admin access for a week
  • #33: Pro also gives you more password options such as: - adding a password generator to user profiles - setting password expirations - and forcing users to change their password on their next login
  • #34: You can also add a Google reCAPTCHA field to your login screen that will help to prevent people from brute forcing your site
  • #35: Pro also allows you to give users the option for Two Factor Authentication through the Google Authenticator app. This requires users to enter a specially generated 6 digit code from their phone when logging into the site A huge increase of security
  • #36: -User logging let’s you track actions of users at or above a certain role -Actions like logging in and saving content