SlideShare a Scribd company logo
WordPress Security BasicsEast Bay WordPress Meetup 6/20/10Sallie Goetsch
Wait! Isn’t WordPress Secure?
Secure HostDedicated ServerVPSReliable Shared Hosting (NOT Network Solutions). “A properly configured web server will not allow users to access the files of another user, regardless of file permissions. The web server is the responsibility of the hosting provider. The methods for doing this (suexec, et al) have been around for 5+ years.” Matt Mullenweg
BasicsBack Up!Update WordPressUpdate Plugins
Check Your File Permissions
Move wp-config.phpUp one directory (WP will look for it there automatically)Best when you can move wp-config.php out of the public_html (or analagous) directoryDon’t do this with nested WP installs!
wp-config.php: Unique Keys
Username & PasswordNever use “admin” for your admin accountUse a strong password
Database Table NameChange from wp_ to something-else_ (or just choose something else to start with)
Bonus: .htaccess(Only works for static IP addresses)AuthUserFile /dev/nullAuthGroupFile /dev/nullAuthName "Access Control"AuthType Basicorder deny,allowdeny from all#IP address to Whitelistallow from xxx.xxx.xxx.xxx
PluginsAntiVirus for WPAutomatic WordPress BackupSecure WordPressServerBuddyTheme  Authenticity CheckerWordPress DB BackupWP Exploit ScannerWordPress File Monitor WordPress FirewallWP Security Scan
AntiVirushttp://wpantivirus.com/
Automatic WordPress Backuphttp://www.webdesigncompany.net/automatic-wordpress-backup/
Secure WordPresshttp://wordpress.org/extend/plugins/secure-wordpress/
ServerBuddyhttp://pluginbuddy.com/free-wordpress-plugins/serverbuddy/
Theme Authenticity Checkerhttp://builtbackwards.com/projects/tac/
WordPress Database Backuphttp://austinmatzko.com/wordpress-plugins/wp-db-backup/
WordPress Exploit Scannerhttp://ocaoimh.ie/exploit-scanner/
WordPress File Monitorhttp://mattwalters.net/projects/wordpress-file-monitor/
WordPress Firewallhttp://www.seoegghead.com/software/wordpress-firewall.seo
WordPress Firewall Notification
WordPress Security Scanhttp://semperfiwebdesign.com/plugins/wp-security-scan/
http://www.meetup.com/Eastbay-WordPress-Meetup/

More Related Content

PDF
Word press security checklist
PPTX
Ignite - selfhosting WordPress - tips and tricks
PPTX
Managing WordPress
ODP
WordPress Security
PPT
Web Security Programming I I
PDF
Javascript issues and tools in production for developers
PPTX
WordPress.org & Optimizing Security for your WordPress sites
PPT
WebHosting Performance / WordPress - Pubcon Vegas - Hendison
Word press security checklist
Ignite - selfhosting WordPress - tips and tricks
Managing WordPress
WordPress Security
Web Security Programming I I
Javascript issues and tools in production for developers
WordPress.org & Optimizing Security for your WordPress sites
WebHosting Performance / WordPress - Pubcon Vegas - Hendison

What's hot (18)

PPT
WordPress Setup and Security (Please look for the newer version!)
PPTX
WordPress Plugins and Security
PDF
WordPress Security Basics - Melbourne WordPress User Meetup
PDF
8 Ways to Hack a WordPress website
ODP
Installing WordPress in 5-Steps
PDF
WordPress Setup and Security - WordCamp, Charleston 2014
PPTX
My v mware solutions home lab
PPT
Security 101
PDF
Page speed optimization
PPTX
Presentation to SAIT Students - Dec 2013
PDF
Securing your WordPress site in 5 easy pieces
PPTX
Demystfying secure certs
PDF
10 tips to improve your website security
KEY
WordPress Security
PPTX
Speeding Up WordPress sites
PDF
WordPress Server Security
PDF
WordPress security & performance a beginners guide
WordPress Setup and Security (Please look for the newer version!)
WordPress Plugins and Security
WordPress Security Basics - Melbourne WordPress User Meetup
8 Ways to Hack a WordPress website
Installing WordPress in 5-Steps
WordPress Setup and Security - WordCamp, Charleston 2014
My v mware solutions home lab
Security 101
Page speed optimization
Presentation to SAIT Students - Dec 2013
Securing your WordPress site in 5 easy pieces
Demystfying secure certs
10 tips to improve your website security
WordPress Security
Speeding Up WordPress sites
WordPress Server Security
WordPress security & performance a beginners guide
Ad

Viewers also liked (6)

PDF
WordPress Multisite deep dive
PDF
Sallie Goetsch: Making the Events Calendar Sit Up and Beg
PDF
Is Your (Client's) Website Ready for 2017?
PDF
Making WordPress Easier to Use
PDF
WordPress Comments (November Meetup)
PDF
Git Version Control for the Complete N00b by Adam LaBarge
WordPress Multisite deep dive
Sallie Goetsch: Making the Events Calendar Sit Up and Beg
Is Your (Client's) Website Ready for 2017?
Making WordPress Easier to Use
WordPress Comments (November Meetup)
Git Version Control for the Complete N00b by Adam LaBarge
Ad

Similar to Word press security basics (20)

PDF
PPTX
WordPress End-User Security
PPTX
WordPress Security - WordPress Meetup Copenhagen 2013
PDF
WordPress Security - 12 WordPress Security Fundamentals
PPTX
WordPress Security Presentation from South Florida WordPress Meetup
PDF
Word press beirut 9th meetup march
PPT
WordPress Security
PDF
WordPress Hardening: Strategies to Secure & Protect Your Website
PDF
Security handout
PPTX
Wordpress security issues
ODP
WordPress Security - Kulpreet Singh
PPTX
WordPress Security Best Practices
PPTX
WordPress Security Updated - NYC Meetup 2009
PPT
Securing Your WordPress Website by Vlad Lasky
PPT
Securing Your WordPress Website - WordCamp GC 2011
PDF
WordPress Security 101
PDF
WordPress Security is like a HHAM Sandwich
PPT
Now That's What I Call WordPress Security 2010
KEY
Higher Order WordPress Security
PPTX
Word camp pune 2013 security
WordPress End-User Security
WordPress Security - WordPress Meetup Copenhagen 2013
WordPress Security - 12 WordPress Security Fundamentals
WordPress Security Presentation from South Florida WordPress Meetup
Word press beirut 9th meetup march
WordPress Security
WordPress Hardening: Strategies to Secure & Protect Your Website
Security handout
Wordpress security issues
WordPress Security - Kulpreet Singh
WordPress Security Best Practices
WordPress Security Updated - NYC Meetup 2009
Securing Your WordPress Website by Vlad Lasky
Securing Your WordPress Website - WordCamp GC 2011
WordPress Security 101
WordPress Security is like a HHAM Sandwich
Now That's What I Call WordPress Security 2010
Higher Order WordPress Security
Word camp pune 2013 security

More from East Bay WordPress Meetup (20)

PDF
How to Conduct an SEO Audit
PPTX
WordPress Membership Plugins: WP-Members
PPTX
WordPress Membership Plugins: MemberPress
PDF
How to Develop a Color Palette for Your Website with Amanada McCoy
PDF
Event Management Plugins for WordPress
PDF
Beyond Gravity Forms: Form Plugins for WordPress
PDF
Rob La Gatta; Making the Events Calendar Sit Up and Beg
PDF
Advanced Custom Fields: Amazing Possibilities and Irritating Limitations
PDF
March 2015: Plugins Worth Paying For
PDF
Google Webmaster Tools for WordPress
PDF
Introduction to Google Analytics by Katherine Mancuso
PDF
iThemes Exchange: the New Kid on the WordPress E-Commerce Block
PDF
Running a WordPress Business--Some Numbers
PPTX
What Developers Need Designers to Know about WordPress
PDF
Making WordPress Fly
PDF
Drag-and-drop WordPress Themes, featuring Themify Builder
PDF
Drag and-Drop WordPress Themes
PDF
Fun with WooCommerce
PDF
Managed WordPress Hosting
PDF
Having Fun with Local WordPress Development
How to Conduct an SEO Audit
WordPress Membership Plugins: WP-Members
WordPress Membership Plugins: MemberPress
How to Develop a Color Palette for Your Website with Amanada McCoy
Event Management Plugins for WordPress
Beyond Gravity Forms: Form Plugins for WordPress
Rob La Gatta; Making the Events Calendar Sit Up and Beg
Advanced Custom Fields: Amazing Possibilities and Irritating Limitations
March 2015: Plugins Worth Paying For
Google Webmaster Tools for WordPress
Introduction to Google Analytics by Katherine Mancuso
iThemes Exchange: the New Kid on the WordPress E-Commerce Block
Running a WordPress Business--Some Numbers
What Developers Need Designers to Know about WordPress
Making WordPress Fly
Drag-and-drop WordPress Themes, featuring Themify Builder
Drag and-Drop WordPress Themes
Fun with WooCommerce
Managed WordPress Hosting
Having Fun with Local WordPress Development

Recently uploaded (20)

PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPTX
Big Data Technologies - Introduction.pptx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
cuic standard and advanced reporting.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Encapsulation theory and applications.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Dropbox Q2 2025 Financial Results & Investor Presentation
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Mobile App Security Testing_ A Comprehensive Guide.pdf
MYSQL Presentation for SQL database connectivity
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Big Data Technologies - Introduction.pptx
Diabetes mellitus diagnosis method based random forest with bat algorithm
Building Integrated photovoltaic BIPV_UPV.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
cuic standard and advanced reporting.pdf
Electronic commerce courselecture one. Pdf
Network Security Unit 5.pdf for BCA BBA.
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Encapsulation theory and applications.pdf
Spectral efficient network and resource selection model in 5G networks
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Reach Out and Touch Someone: Haptics and Empathic Computing
Build a system with the filesystem maintained by OSTree @ COSCUP 2025

Word press security basics