Results 1 to 18 of 18
  1. #1
    PaulEchere's Avatar
    PaulEchere is offline Private Member
    Join Date
    June 2020
    Posts
    730
    Thanks
    70
    Thanked 228 Times in 177 Posts

    Default How do you keep your WP website safe?

    I have just received a PW reset request email from one of my websites. Now the main thing I'm concerned about is how my username became known, because it isn't the generic "admin", it's pretty random tbh.

    Now I'm wondering whether I should take some additional measures like hiding the login page (I know I should have done that a long time ago), something else?

  2. The Following User Says Thank You to PaulEchere For This Useful Post:

    Geou1991 (26 January 2024)

  3. #2
    dannyx is offline Public Member
    Join Date
    November 2019
    Posts
    733
    Thanks
    143
    Thanked 185 Times in 147 Posts

    Default

    Hiding the login page on large sites can be problematic, sometimes various errors come out when doing so. However, it is obviously worth doing.

    There are also other options. You can, for example, set Google Captcha at login. Or IP blockade after several unsuccessful attempts and monitor login attempts whether your login is actually used by bots and humans or not. There are some less and more radical options. Do you use any security plugins?

  4. #3
    PaulEchere's Avatar
    PaulEchere is offline Private Member
    Join Date
    June 2020
    Posts
    730
    Thanks
    70
    Thanked 228 Times in 177 Posts

    Default

    I do actually use Google captcha one one of my websites (not the one I referred to above). And no, I don't have any security plugins, do you have any you can recommend?

  5. #4
    dannyx is offline Public Member
    Join Date
    November 2019
    Posts
    733
    Thanks
    143
    Thanked 185 Times in 147 Posts

    Default

    I personally use Wordfence.
    There you can see the login attempts and the logins that are used for that. 90% of the attempts are for admin login and domain name.
    It also has a lot of cool features, real-time blocking, you can block entire countries, etc. Besides, it's a popular plugin so rules and threats are updated quite often.

    I personally opted for Wordfence because I previously needed 2-3 security plugins, as one had one function and the other had another. Wordfence has it all in one place.

    I don't know if I remember correctly, but Wordfence probably has the most downloads in its category, or high.

    However, there are other good plugins, and surely someone else will comment on other solutions.

  6. The Following 2 Users Say Thank You to dannyx For This Useful Post:

    CPReport (1 February 2024), NoDepositCasinos (16 February 2024)

  7. #5
    Strider1973's Avatar
    Strider1973 is offline Private Member
    Join Date
    November 2012
    Posts
    449
    Thanks
    337
    Thanked 268 Times in 182 Posts

    Default

    Maybe they did a password reset with your email? Maybe by using info@yourdomain.com?

    You can use a simple plugin like "WPS Hide Login" to use another login URL.
    "Semper paratus!"
    My BTC Address: 1F11EJvSAab5vMQgGWGQMASr9T7LCkZjvb

  8. #6
    PaulEchere's Avatar
    PaulEchere is offline Private Member
    Join Date
    June 2020
    Posts
    730
    Thanks
    70
    Thanked 228 Times in 177 Posts

    Default

    Thanks for the recommendations, I will check those out.

    They did request a PW reset, but all that comes to my personal email address, which is likely very difficult to get into without having access to my phone.

  9. #7
    edgarf76's Avatar
    edgarf76 is offline Private Member
    Join Date
    March 2013
    Location
    Montreal
    Posts
    2,196
    Thanks
    804
    Thanked 582 Times in 429 Posts

    Default

    You may want to try sucuri.
    Visit Play Slots 4 Real Money and Casino Slots Money for trusted recommendations and tips on the best casinos.

  10. #8
    chaumi is offline Private Member
    Join Date
    October 2013
    Location
    East Midlands
    Posts
    1,640
    Thanks
    570
    Thanked 839 Times in 617 Posts

    Default

    This one does the trick for me, never yet had a problem and it doesn't appear to slow down the site at all...

    https://wordpress.org/plugins/all-in...-and-firewall/

  11. #9
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,832
    Thanks
    4,492
    Thanked 9,254 Times in 5,948 Posts

    Default

    Hiding the login page is often referred to as "security by obscurity". While not 100% effective it will slow down a lot of script kiddies who spend their day scanning for default wp-login pages..

    Some of the better security plugins may also prevent username discovery.

    My preference to security plugins is WP Cerber.

    Rick
    Universal4

  12. #10
    baldidiot is offline Private Member
    Join Date
    January 2010
    Posts
    5,094
    Thanks
    432
    Thanked 2,333 Times in 1,555 Posts

    Default

    Quote Originally Posted by universal4 View Post
    Hiding the login page is often referred to as "security by obscurity".
    You beat me to it... It's basically the equivalent of hiding the front door.

    The problem is that some people think that is sufficient, but it isn't. Even if it's hidden you still need to secure the door properly. Plus that won't stop them getting in through a window (if you want to continue the analogy).

    I would suggest:

    1. Cloudflare
    2. Wordfence - set strict brute force protection, both on failed log ins (eg: set to block at 3 attempts) and an immediate lock out on incorrect usernames
    3. 2 Factor

    Also don't use the same email everywhere. If you're using the same email that you use to message people as the email on your wordpress account, they don't even need to know the username, they can just use the email.
    onlinegamblingwebsites.com - Formally known as goodbonusguide.

    Gambling Domains: Small clear out of some of the domains we've been hoarding - see the spreadsheet here.

  13. The Following User Says Thank You to baldidiot For This Useful Post:

    NoDepositCasinos (16 February 2024)

  14. #11
    newcustomeroffer is offline Public Member
    Join Date
    January 2018
    Location
    United Kingdom
    Posts
    1,340
    Thanks
    232
    Thanked 588 Times in 461 Posts

    Default

    Defender Pro is a nice WP plugin which allows you to create your own login URL, plus you can monitor and ban IPs that are acting suspiciously.
    For the latest bookmaker new customer offers visit https://www.newcustomeroffer.co.uk/

  15. #12
    NoDepositCasinos's Avatar
    NoDepositCasinos is offline Public Member
    Join Date
    November 2022
    Location
    Colombia
    Posts
    1,195
    Thanks
    344
    Thanked 461 Times in 379 Posts

    Default

    Is there such a thing as too much security? Besides the possibility of slowing down the pages, are there any disadvantages to consider?

    I use Wordfence, and as I write this, I'm implementing one of the tips shared in this thread. I haven't had any issues so far, but I aim to maintain reasonable security measures on my websites.
    casinobonusnewsletter.com - AMs contact me for deals

    revenueoptimization.io - DM me if you want to be featured in our blog

  16. #13
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,832
    Thanks
    4,492
    Thanked 9,254 Times in 5,948 Posts

    Default

    Quote Originally Posted by NoDepositCasinos View Post
    Is there such a thing as too much security? Besides the possibility of slowing down the pages, are there any disadvantages to consider?
    Good question however, as you design and or implement security changes ask yourself a few questions.

    Is there any reason anyone on the planet other than you and or developers or writers need to know the url of the admin login? If you allow a lot of guest content from unverified sources that changes the answer.

    And if you do block the login page, is there any reason not to block the ip of those who attempt to find it or attempt to hit the default wp-login?

    IMO opinion the answer to both of those is to go ahead and block.

    Since you chose wordfence, you should be fine in most cases. And you can test to make sure it is doing what you want by hitting your site using a vpn to see if it locks you out or reacts the way you want it to.

    Rick
    Universal4

  17. The Following User Says Thank You to universal4 For This Useful Post:

    NoDepositCasinos (18 February 2024)

  18. #14
    bon's Avatar
    bon
    bon is offline Private Member
    Join Date
    June 2023
    Location
    Georgia
    Posts
    12
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    For our sites, we usually limit the number of attempts to log in, make regular backups, and use security plugins (approximately the same ones we wrote about above). We are also now thinking about SSL/TLS Encryption.

    I've already had cases when attackers steal the site and I'm sure it's better to prevent hacking

  19. #15
    DaftDog's Avatar
    DaftDog is offline Private Member
    Join Date
    October 2008
    Location
    South Africa
    Posts
    2,151
    Thanks
    687
    Thanked 773 Times in 463 Posts

    Default

    I found this forum thread about WordPress security plugins quite interesting: https://www.webhostingtalk.com/showthread.php?t=1875698

  20. #16
    NoDepositCasinos's Avatar
    NoDepositCasinos is offline Public Member
    Join Date
    November 2022
    Location
    Colombia
    Posts
    1,195
    Thanks
    344
    Thanked 461 Times in 379 Posts

    Default

    Quote Originally Posted by universal4 View Post
    Good question however, as you design and or implement security changes ask yourself a few questions.

    Is there any reason anyone on the planet other than you and or developers or writers need to know the url of the admin login? If you allow a lot of guest content from unverified sources that changes the answer.

    And if you do block the login page, is there any reason not to block the ip of those who attempt to find it or attempt to hit the default wp-login?

    IMO opinion the answer to both of those is to go ahead and block.

    Since you chose wordfence, you should be fine in most cases. And you can test to make sure it is doing what you want by hitting your site using a vpn to see if it locks you out or reacts the way you want it to.

    Rick
    Universal4
    Thank you for the tips. I was worried about missing something.

    I just took the test you recommended and everything seems to work properly.
    casinobonusnewsletter.com - AMs contact me for deals

    revenueoptimization.io - DM me if you want to be featured in our blog

  21. #17
    lapa221Q is offline Public Member
    Join Date
    May 2023
    Posts
    76
    Thanks
    0
    Thanked 11 Times in 9 Posts

    Default

    keep your themes and plugins updated, use strong and unique passwords, limit login attempts, use a security plugin like iThemes Security, enable two-factor authentication, and regularly back up your site.

  22. #18
    baldidiot is offline Private Member
    Join Date
    January 2010
    Posts
    5,094
    Thanks
    432
    Thanked 2,333 Times in 1,555 Posts

    Default

    Quote Originally Posted by NoDepositCasinos View Post
    Is there such a thing as too much security? Besides the possibility of slowing down the pages, are there any disadvantages to consider?
    In theory if your security is too strict you could block legitimate users, so in theory yes there is such a thing as "too much". But it depends on what you're doing to secure the site and what your users are likely to do.

    Eg: Set a flood protection to <10 / 5 minutes and you'll probably end up blocking some users.

    Perhaps "too strict" is a better term to use than "too much security" for what I'm talking about though.
    onlinegamblingwebsites.com - Formally known as goodbonusguide.

    Gambling Domains: Small clear out of some of the domains we've been hoarding - see the spreadsheet here.

  23. The Following User Says Thank You to baldidiot For This Useful Post:

    universal4 (28 February 2024)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •