
Comprehensive guide for hardening WordPress installations: covers admin user changes, HTTPS enforcement, plugin security, file permissions, and server configuration for static corporate sites.
This document is written with the aim of being suitable for web applications developed using WordPress that do not interact with users. It is primarily intended for corporate brand pages, various static views, recruitment pages, and similar sites.
For websites where users register and freely use the site, such as open communities, some items in this document may not be applicable. Please keep this in mind as you read.
This document does not include all of the content necessary for securing WordPress.
However, it includes general and detailed information to a level that allows for security risk assessments and vulnerability responses based on the guide.
If you find this helpful, please the "star"🌟 to support further improvements.
When you install WordPress, the default admin username is "admin" unless you change it during the setup process. The "admin" account name is widely known, so it should be changed to a different name. If you continue to use "admin" as your admin username, an attacker could attempt a brute-force attack using "admin" to gain access to your WordPress site.
If an attacker gains access to the WordPress admin account, they will have full control over the website. The default WordPress admin username should be changed to a different name.
Audit:
Remediation:
Note:
By default, WordPress has five user roles - "Administrators", "Editors", "Authors", "Contributors", "Subscribers"
These roles allow you to control what tasks users can perform on your website by assigning appropriate permissions. If user roles and permissions are not properly managed, users might gain unnecessary access to critical functionalities, posing a significant security risk.
Audit:
Remediation: