ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

WordPress Security Tips

By Vladan SEGET | Last Updated: January 11, 2019

Shares

I wanted to share some WordPress security tips. Usually, after you first install WordPress, you configure your WP installation and installs some plugins. You should also make sure that your WP blog is secure enough otherwise you might expose yourself for being hacked.

1. Use Simple Login Lockdown

This plugin allows you to get protected against brute force attacks. If it's you that forgot your password, and so you make a failed login attempt, the lockdown count gets cleared on successful login.

How it works:

  1. An attacker attempts to login and fails
  2. Simple Login Lockdown record that failed login
  3. After a certain number of failed attemps (defaults to five), further attemps to access the wp-login.php page are blocked for a time (defaults to one hour)

Login Lockdown WordPress Plugin

Get the Simple Login Lockdown plugin here.

2. Hide your plugins

Usually a WordPress Installation is extended by plugins. There are millions of free plugins which enhances WP isntallations. While you can't possibly use hundreds, you might use 10-20 plugins. Plugins are often source of troubles, because of bugs and vulnerabilities that can be exploited to damage your website. You certainly do not want the hacker to spoil your hard maintained blog, do you?

If you visit the folder /wp-content/plugins/ on some blogs, you might be able to see all the plugins that are used. To avoid that, you just need to create an empty index.html file and drop it there.

3. WordPress Security Plugins

You can go even further with this plugin called Better WP Security (I haven't tested personaly) which can:

  • Remove the meta “Generator” tag (you're hiding to hackers important informations on which platform your website runs)
  • Change the urls for WordPress dashboard including login, admin, and more..

But also:

  • Rename “admin” account
  • Change the ID on the user with ID 1
  • Change the WordPress database table prefix
  • Change wp-content path

I would recommend to test this plugin on a blog which is not your principal blog, as it does quite a lot of stuff…

In addition, I'm using WordFence Security Plugin for WordPress, which provides you with life traffic view, scans for week passwords, and much more…

4. WordPress Folders and files permissions

Directories should have, at most, permissions of 755, where files should be should be, at most, 664. You must never ever have ANY file at permissions greater than 666 unless you are directed specifically to do so. At some shared hosts they directs you to have 777 on wp upload images directory. I would recommend checking with them directly, and if they don't want to change their policy about that, I would seek another hosting provider as having 755 on folders is really necessity.

5. Backup, Backup, Backup

You never know, better safe than sorry… If you're serious to blogging, starting to have some traffic, you would want to make sure that your work is safe. Set it and forget it are the best solutions, no? Eat your own dog food – get free account at Codeguard at least. Yes they have free accounts (on the page there is a link down there…), but they also target professionals with plans that starts at $5/months. That's what I'm using. Whenever I create new post, upload new image, update plugin – every single change is detected an it allows me to  go back in time – like Time Machine…

The free accounts don't have a support. But what's $5/month … two cup of coffee?..-:) You're serious on blogging? You blog often? You'll be backed up automatically, and get your blog's data safe, with granular restore possibilities.

Also good read:

  • 5 Tips for WordPress Beginners – some new tips for new version of WordPress (3.5)!
  • Top 5 things to do after installing WordPress – essential things to configure after WordPress Installation
  • WordFence Security Plugin for WordPress
  • WordPress Backup Cloud Service – a Time Machine for your blog
Shares
Vote !

| Filed Under: Backup Tagged With: Wordpress Security Tips

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Comments

  1. Salah says

    February 25, 2013 at 12:15 pm

    I have tried Better WP Security it work pretty good.

  2. Ravi Kumar says

    February 20, 2014 at 5:09 am

    Hi Vladan,

    Thank you for this very useful post, appreciate your time and effort on this blog post. Please could you advise what plugin do you use for picture to pop-up like a slide show with a close button on it, when we click on any picture in your blog.

    Thanks again, I am one of your regular visitor….

    -Ravi

    • Vladan SEGET says

      February 20, 2014 at 2:49 pm

      If I remember right, it’s called “pretty photo”. Just FYI, you can see which plugins are used if you look at the source code of a blog post… -:) Cheers.

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco
  • VMware ESXi FREE is FREE again!

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in