SlideShare a Scribd company logo
30 Point
Guide To Better
WordPress
Security
wpSecureProtect.com
wpSecureProtect.com
wpSecureProtect.com
wpSecureProtect.com
wpSecureProtect.com
Email Alert
wpSecureProtect.com
What We Do
De Hack
Secure WP
WP Maintenance
& Security
wpSecureProtect.com
7 Steps To Better WP Security
1. Dashboard
2. FTP
3. Plugins
4. Themes
5. Maintenance
6. Computer
7. Action
wpSecureProtect.com
DASHBOARD
wpSecureProtect.com
// One
rhu18g64kd87_
wpSecureProtect.com
admin
Not Author
wpSecureProtect.com
password
Frk%7h#ha)=4
wpSecureProtect.com
wpSecureProtect.com
MySQL
Disable
Remote
Access
wpSecureProtect.com
// Two
FTP
wpSecureProtect.com
Files
Folders
644
755
wpSecureProtect.com
<?php
// Silence is golden.
?>
index.php
wpSecureProtect.com
Config.php
wpSecureProtect.com
# PROTECT install.php
<Files install.php>
Order Allow,Deny
Deny from all
Satisfy all
</Files>
Install.php
wpSecureProtect.com
define('AUTH_KEY', 'Sd-:`R;kj(Ys%mPYq-W#r76UO&G;/z#K4~U8M@cpvGY}anM+x[v(?EDRbet<!%Mp');
define('SECURE_AUTH_KEY', 'ohU%+27`Tx@i`!Mt(o+WpQ/GxAm*IrHu(+4cO$|spk*tE#)W]|y~_CZ/>^d $2!K');
define('LOGGED_IN_KEY', ';b?t?M+jD47~f|`u+-G2.L*k6{4]=q*/F/5Cxe+FEr<A~5sbp*`r{M&.6* xFj|S');
define('NONCE_KEY', 'Wx&L-hLsER+ut2-c%+^t|P+F`)Srf,FP lT.5>wc-AYq8S>X{9McG~:-CdiS.Z1S');
define('AUTH_SALT', 'E?qL2yRRS3&a9{d?C2$ K67}OLIX:;Pe&n16`C%lJ,5)EI0n+~q!Dy6~koRF 16Z');
define('SECURE_AUTH_SALT', 'B)r5%!6{M4D3t/4UC{2M]uB-WGqhc~_:_M|aoQ2^^yF`[9rvwpxV-p&Y-mZz<i3o');
define('LOGGED_IN_SALT', 'MN`Yu[q^WO~-n4*?2QR+/TL#CUl,A,VN|G]Xb9KZWE;JNcKn|xD]:ot=g{@B>Spy');
define('NONCE_SALT', 'f2q&m}q[C+Z{^uRkou+g,RdI$1#MN$b0{:H+-Nh+^WQv0P0LG:OL^7~wH[?-e!q>');
SALT
wpSecureProtect.com
// Three
PLUGINS
wpSecureProtect.com
Akismet
wpSecureProtect.com
WP Hashcash
Extended
wpSecureProtect.com
Wordfence
Security
wpSecureProtect.com
WordPress
Backup To
Dropbox
wpSecureProtect.com
Bulletproof
Security
wpSecureProtect.com
// Four
THEMES
wpSecureProtect.com
Theme
Repository
wpSecureProtect.com
Genesis
Woo
iThemes
Thematic
TwentyThirteen
Theme
Frameworks
wpSecureProtect.com
Unknown
Free
wpSecureProtect.com
FrameworkChild
wpSecureProtect.com
Forum
Tickets
Community
Documentation
Support
wpSecureProtect.com
// Five
MAINTENANCE
wpSecureProtect.com
WP Core
Themes
Plugins
Update
wpSecureProtect.com
Themes
Plugins
Remove
wpSecureProtect.com
Repair
Optimize
wpSecureProtect.com
Database
wp-content
Backup
wpSecureProtect.com
Scan
&
Monitor
wpSecureProtect.com
// Six
COMPUTER
wpSecureProtect.com
Login
Logout
Session
wpSecureProtect.com
Virus
Malware
Firewall
Protect
wpSecureProtect.com
Lastpass
Roboform
1Password
Username
Password
wpSecureProtect.com
FTP
cPanel
Wordpress
Contractors / Outsourcers
Remove
Access
wpSecureProtect.com
Public WiFi
One Time
UID PWD
Log Off!!
wpSecureProtect.com
// Seven
ACTION
wpSecureProtect.com
Not ‘If’
But ‘When’
Implement
wpSecureProtect.com
DOWNLOAD
wpSecureProtect.com
wpSecureProtect.com

More Related Content

PDF
WordPress Meetup Ieper - 15/03/2018 - WordPress Security Best Practices
PPTX
How To Lock Down And Secure Your Wordpress
PDF
Unmasking or De-Anonymizing You
ODP
CMS and security / privacy
PDF
WordPress Security
PPTX
Locking Down Your WordPress Site
PPT
Tips to improve word press security ppt
PDF
Website Security AMA: Best Practices
WordPress Meetup Ieper - 15/03/2018 - WordPress Security Best Practices
How To Lock Down And Secure Your Wordpress
Unmasking or De-Anonymizing You
CMS and security / privacy
WordPress Security
Locking Down Your WordPress Site
Tips to improve word press security ppt
Website Security AMA: Best Practices

What's hot (20)

PDF
How to install and configure lamp (linux,apache mysql mariadb,php) with jooml...
PDF
10 Steps to Optimize Mozilla Firefox for Google Apps Security
PDF
Memcache Injection (Hacktrick'15)
PDF
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
PPTX
Protecting Web App users in today’s hostile environment
PPTX
Sucuri Webinar: Leveraging Sucuri's API
PPTX
Web Uygulama Güvenliği (Akademik Bilişim 2016)
PPT
Is your Wordpress safe enough?
PDF
Securing Your WordPress Website - WordCamp Sydney 2012
PDF
Reversing & malware analysis training part 8 malware memory forensics
PDF
WORDPRESS SECURITY: HOW TO AVOID BEING HACKED
PDF
WordPress Security Essential Tips & Tricks
PDF
URL to HTML
PDF
Bünyamin Demir - Secure YourApp
PDF
Introduction to Backups and Security
PPT
WordPress End-User Security - WordCamp Las Vegas 2011
PPTX
Website security
PPTX
Remove istart.webssearches.com hijacker
PPTX
WordPress Security 101
PDF
ubantu mod security
How to install and configure lamp (linux,apache mysql mariadb,php) with jooml...
10 Steps to Optimize Mozilla Firefox for Google Apps Security
Memcache Injection (Hacktrick'15)
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
Protecting Web App users in today’s hostile environment
Sucuri Webinar: Leveraging Sucuri's API
Web Uygulama Güvenliği (Akademik Bilişim 2016)
Is your Wordpress safe enough?
Securing Your WordPress Website - WordCamp Sydney 2012
Reversing & malware analysis training part 8 malware memory forensics
WORDPRESS SECURITY: HOW TO AVOID BEING HACKED
WordPress Security Essential Tips & Tricks
URL to HTML
Bünyamin Demir - Secure YourApp
Introduction to Backups and Security
WordPress End-User Security - WordCamp Las Vegas 2011
Website security
Remove istart.webssearches.com hijacker
WordPress Security 101
ubantu mod security
Ad

Similar to Wp security presentation (20)

PPTX
WordPress End-User Security
PPTX
Hardening WordPress Security
PPT
WordPress Security - WordCamp NYC 2009
PPT
WordPress Security - WordCamp Boston 2010
PDF
Null bhopal Sep 2016: What it Takes to Secure a Web Application
KEY
Higher Order WordPress Security
PPTX
Locking down word press
PPTX
WordPress Security Updated - NYC Meetup 2009
PDF
Secure wordpress
PDF
Complete Wordpress Security By CHETAN SONI - Cyber Security Expert
PDF
WordPress Security 2018
PDF
WordPress Security Guide
PPT
WordPress Security
PPT
Secure All The Things!
PDF
Securing your WordPress Website - Vlad Lasky - WordCamp Sydney 2012
PPT
Now That's What I Call WordPress Security 2010
PDF
OWASP Thailand 2016 - Joomla Security
PPT
WordPress and the Enterprise
PDF
WordPress Security Presentation
KEY
Optimize wordpress
WordPress End-User Security
Hardening WordPress Security
WordPress Security - WordCamp NYC 2009
WordPress Security - WordCamp Boston 2010
Null bhopal Sep 2016: What it Takes to Secure a Web Application
Higher Order WordPress Security
Locking down word press
WordPress Security Updated - NYC Meetup 2009
Secure wordpress
Complete Wordpress Security By CHETAN SONI - Cyber Security Expert
WordPress Security 2018
WordPress Security Guide
WordPress Security
Secure All The Things!
Securing your WordPress Website - Vlad Lasky - WordCamp Sydney 2012
Now That's What I Call WordPress Security 2010
OWASP Thailand 2016 - Joomla Security
WordPress and the Enterprise
WordPress Security Presentation
Optimize wordpress
Ad

More from Nik Cree (14)

PDF
COURSE OUTLINE - Canva Mastery for Business.pdf
PDF
BOSIO Presentation 20221108 Julie Mason.pdf
PDF
BOSIO Presentation 20221101 John Dwyer.pdf
PDF
BOSIO Presentation 20221025 Steve Brossman.pdf
PDF
BOSIO Presentation 20221017 Karl Schwantes.pdf
PDF
BOSIO Presentation 20220920 Steve Baltzois & David Phillips.pdf
PDF
BOSIO Presentation 20220614 Paul Scheaffe.pdf
PDF
BOSIO Presentation 20220405 Nik Cree.pdf
PDF
BOSIO Presentation 20220906 Nik Cree.pdf
PPTX
Creating Your Own Affiliate or Paid Referral Program And Have Other People Br...
PPTX
Join & Profit With Affiliate Programs
PDF
How To Create Your Entire Website Content Easily And Effortlessly In 7 Days O...
PDF
Create a newsletter in less than 17 minutes without writing a single word
PDF
Mastering Google Adwords In 30 Minutes
COURSE OUTLINE - Canva Mastery for Business.pdf
BOSIO Presentation 20221108 Julie Mason.pdf
BOSIO Presentation 20221101 John Dwyer.pdf
BOSIO Presentation 20221025 Steve Brossman.pdf
BOSIO Presentation 20221017 Karl Schwantes.pdf
BOSIO Presentation 20220920 Steve Baltzois & David Phillips.pdf
BOSIO Presentation 20220614 Paul Scheaffe.pdf
BOSIO Presentation 20220405 Nik Cree.pdf
BOSIO Presentation 20220906 Nik Cree.pdf
Creating Your Own Affiliate or Paid Referral Program And Have Other People Br...
Join & Profit With Affiliate Programs
How To Create Your Entire Website Content Easily And Effortlessly In 7 Days O...
Create a newsletter in less than 17 minutes without writing a single word
Mastering Google Adwords In 30 Minutes

Recently uploaded (20)

PDF
cuic standard and advanced reporting.pdf
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPT
Teaching material agriculture food technology
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Cloud computing and distributed systems.
PDF
Approach and Philosophy of On baking technology
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
Spectroscopy.pptx food analysis technology
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
cuic standard and advanced reporting.pdf
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
MYSQL Presentation for SQL database connectivity
Spectral efficient network and resource selection model in 5G networks
Advanced methodologies resolving dimensionality complications for autism neur...
Teaching material agriculture food technology
Network Security Unit 5.pdf for BCA BBA.
Cloud computing and distributed systems.
Approach and Philosophy of On baking technology
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
20250228 LYD VKU AI Blended-Learning.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Spectroscopy.pptx food analysis technology
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Building Integrated photovoltaic BIPV_UPV.pdf
MIND Revenue Release Quarter 2 2025 Press Release
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx

Wp security presentation

Editor's Notes

  • #11: Change Default Table Name from wp_
  • #12: 1. Create a new Administrative User2. Logout3. Login with the new user details4. Delete the ‘admin’ user5. Attribute all posts to the new administratorN.B. Don’t use the Author Name as the Username
  • #13: Use a secure passwordFrk%7h#ha)=4USNLLastPass, 1PasswordEnforce strong passwords for Contributor+
  • #14: WP Version Number from header
  • #15: Request this from your host:Access only from WordPress and phpMyAdmin
  • #18: wp-includeswp-contentwp-content/pluginswp-content/uploads
  • #20: DeleteModify.htaccess# PROTECT install.php&lt;Files install.php&gt; Order Allow,Deny Deny from all Satisfy all&lt;/Files&gt;
  • #38: DatabaseUploadsTheme
  • #41: BotnetMac too