WordPress Owners: Safer Steps in This Order
The official WordPress hardening guide says the first step after a compromise is to strengthen your logins. Renaming your database prefix does “nothing to secure your website," says Shield Security. The fact is changing the WordPress database prefix is security theater. So most web owners look to a compilation of recommended hardening steps.
A WordPress owner facing a possible compromise heads for a “wordpress security checklist” and finds a jumble of yea and nay. But the treatise on hardening WordPress cites only three steps worth doing first, and 5 that do the rest.
The latest hardening checklist, made by GF.dev, ranks strong passwords plus 2FA as item 1 and login rate limiting with XML-RPC disabled as item 2. GF.dev put changing the database table prefix as 6th. WP Security Ninja lists people and logins as one of its five core pillars.
So why does everyone start with shared admin logins and, lastly, protected backups offsite? The answer lies in how quickly an attacker uses your plugins to do their dirty work.
But before you dive in, consider that when you find a checklist, you may find a warning. For many, most of the items cited as “core” vulnerability sources were simply never installed. "There’s nothing secure about renaming the WordPress prefix," according to a Shield Security Q&A.
Logins: The Biggest Lever You Control
Wordpress owners hit first by would-be attackers are most often the victims of brute force attacks. The offense is aimed at your login, as the official guide says.
Plugin authors harden Wordpress by recommending that you set up strong, unique passwords. And counselors are wiser yet: among the most recommended hardening steps are to enable two-factor authentication. And, experts add, be sure to limit failed logins or lock out accounts after a preset number of tries. And it is best not to share administrator user name and password combinations.
But cant a skilled attacker find their way past 2FA and every strong password? Cant they download your entire mysql database? Shield Security says no. Because the prefixes are public knowledge. The central point at issue, says Shield Security, is that if an attacker has the rights to read a prefix, he probably can get the database data.
Plugins and Themes: Hygiene Against Real-World Exploits
So if hardened logins are the first step, then plugin and theme hygiene are a close second. To begin, the recommendations say, be sure to auto-update for minor WordPress core releases, then review and apply major core releases within a week. Also, enable auto-updates for trusted plugins, and remove any plugins or themes that are not being used. And be sure to stay away from pirated or “nulled” themes and plugins, as they often include malware.
Further strength can be gained by enabling real-time or scheduled backups, housed off the web server for good measure, and test-restored backups to be safe. The more recent wordpress hardening guides all mention file permissions, such as directories set at 755 and files at 644, and restricting wp-config.php access to either 600 or 640, as a practice to deny attackers access if they do get in.
But file permissions are more of a supporting practice, and backups are the only real safety net. So put the backup info in the right place and keep track of the data. WordPress Security Ninja suggests promoting HTTPS on your site and using a web application firewall (WAF) implementation, which filters common exploit attempts.
Beyond the First Three Changes: Host, HTTPS, and WAF
WordPress Security Ninja recommends HTTPS on the host and a web application firewall, known as a WAF, a piece of software which filters out common exploit attempts. Other guidance, meanwhile, cautions that web application firewalls can help but won’t magically fix your website.
That said, a well-chosen hardening checklist is generally regarded as trustworthy guidance. And because compromised plugins are a common cause of trouble, the best policy is to keep password access restricted, close unused plugins, and keep data backups handy.