Results 1 to 18 of 18
  1. #1
    PaulEchere's Avatar
    PaulEchere is online now Private Member
    Join Date
    June 2020
    Posts
    565
    Thanks
    67
    Thanked 177 Times in 136 Posts

    Default How do you keep your WP website safe?

    I have just received a PW reset request email from one of my websites. Now the main thing I'm concerned about is how my username became known, because it isn't the generic "admin", it's pretty random tbh.

    Now I'm wondering whether I should take some additional measures like hiding the login page (I know I should have done that a long time ago), something else?

  2. The Following User Says Thank You to PaulEchere For This Useful Post:

    Geou1991 (26 January 2024)

  3. #2
    dannyx is offline Public Member
    Join Date
    November 2019
    Posts
    658
    Thanks
    129
    Thanked 168 Times in 135 Posts

    Default

    Hiding the login page on large sites can be problematic, sometimes various errors come out when doing so. However, it is obviously worth doing.

    There are also other options. You can, for example, set Google Captcha at login. Or IP blockade after several unsuccessful attempts and monitor login attempts whether your login is actually used by bots and humans or not. There are some less and more radical options. Do you use any security plugins?

  4. #3
    PaulEchere's Avatar
    PaulEchere is online now Private Member
    Join Date
    June 2020
    Posts
    565
    Thanks
    67
    Thanked 177 Times in 136 Posts

    Default

    I do actually use Google captcha one one of my websites (not the one I referred to above). And no, I don't have any security plugins, do you have any you can recommend?

  5. #4
    dannyx is offline Public Member
    Join Date
    November 2019
    Posts
    658
    Thanks
    129
    Thanked 168 Times in 135 Posts

    Default

    I personally use Wordfence.
    There you can see the login attempts and the logins that are used for that. 90% of the attempts are for admin login and domain name.
    It also has a lot of cool features, real-time blocking, you can block entire countries, etc. Besides, it's a popular plugin so rules and threats are updated quite often.

    I personally opted for Wordfence because I previously needed 2-3 security plugins, as one had one function and the other had another. Wordfence has it all in one place.

    I don't know if I remember correctly, but Wordfence probably has the most downloads in its category, or high.

    However, there are other good plugins, and surely someone else will comment on other solutions.

  6. The Following 2 Users Say Thank You to dannyx For This Useful Post:

    CPReport (1 February 2024), NoDepositCasinos (16 February 2024)

  7. #5
    Strider1973's Avatar
    Strider1973 is offline Private Member
    Join Date
    November 2012
    Posts
    416
    Thanks
    298
    Thanked 259 Times in 176 Posts

    Default

    Maybe they did a password reset with your email? Maybe by using [email protected]?

    You can use a simple plugin like "WPS Hide Login" to use another login URL.
    "Semper paratus!"
    My BTC Address: 1F11EJvSAab5vMQgGWGQMASr9T7LCkZjvb

  8. #6
    PaulEchere's Avatar
    PaulEchere is online now Private Member
    Join Date
    June 2020
    Posts
    565
    Thanks
    67
    Thanked 177 Times in 136 Posts

    Default

    Thanks for the recommendations, I will check those out.

    They did request a PW reset, but all that comes to my personal email address, which is likely very difficult to get into without having access to my phone.

  9. #7
    edgarf76's Avatar
    edgarf76 is offline Private Member
    Join Date
    March 2013
    Location
    Montreal
    Posts
    2,175
    Thanks
    798
    Thanked 580 Times in 427 Posts

  10. #8
    chaumi is offline Private Member
    Join Date
    October 2013
    Location
    East Midlands
    Posts
    1,508
    Thanks
    505
    Thanked 784 Times in 573 Posts

    Default

    This one does the trick for me, never yet had a problem and it doesn't appear to slow down the site at all...

    https://wordpress.org/plugins/all-in...-and-firewall/

  11. #9
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    31,789
    Thanks
    3,643
    Thanked 8,676 Times in 5,532 Posts

    Default

    Hiding the login page is often referred to as "security by obscurity". While not 100% effective it will slow down a lot of script kiddies who spend their day scanning for default wp-login pages..

    Some of the better security plugins may also prevent username discovery.

    My preference to security plugins is WP Cerber.

    Rick
    Universal4

  12. #10
    baldidiot is offline Private Member
    Join Date
    January 2010
    Posts
    4,977
    Thanks
    427
    Thanked 2,271 Times in 1,510 Posts

    Default

    Quote Originally Posted by universal4 View Post
    Hiding the login page is often referred to as "security by obscurity".
    You beat me to it... It's basically the equivalent of hiding the front door.

    The problem is that some people think that is sufficient, but it isn't. Even if it's hidden you still need to secure the door properly. Plus that won't stop them getting in through a window (if you want to continue the analogy).

    I would suggest:

    1. Cloudflare
    2. Wordfence - set strict brute force protection, both on failed log ins (eg: set to block at 3 attempts) and an immediate lock out on incorrect usernames
    3. 2 Factor

    Also don't use the same email everywhere. If you're using the same email that you use to message people as the email on your wordpress account, they don't even need to know the username, they can just use the email.
    onlinegamblingwebsites.com - Formally known as goodbonusguide.

    Gambling Domains: Small clear out of some of the domains we've been hoarding on Dan - see the list here. Prices negotiable, and willing to swap for decent links.

  13. The Following User Says Thank You to baldidiot For This Useful Post:

    NoDepositCasinos (16 February 2024)

  14. #11
    newcustomeroffer is offline Public Member
    Join Date
    January 2018
    Location
    United Kingdom
    Posts
    921
    Thanks
    140
    Thanked 406 Times in 313 Posts

    Default

    Defender Pro is a nice WP plugin which allows you to create your own login URL, plus you can monitor and ban IPs that are acting suspiciously.
    For the latest bookmaker new customer offers visit https://www.newcustomeroffer.co.uk/

  15. #12
    NoDepositCasinos's Avatar
    NoDepositCasinos is offline Public Member
    Join Date
    November 2022
    Location
    Colombia
    Posts
    582
    Thanks
    105
    Thanked 186 Times in 158 Posts

    Default

    Is there such a thing as too much security? Besides the possibility of slowing down the pages, are there any disadvantages to consider?

    I use Wordfence, and as I write this, I'm implementing one of the tips shared in this thread. I haven't had any issues so far, but I aim to maintain reasonable security measures on my websites.

  16. #13
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    31,789
    Thanks
    3,643
    Thanked 8,676 Times in 5,532 Posts

    Default

    Quote Originally Posted by NoDepositCasinos View Post
    Is there such a thing as too much security? Besides the possibility of slowing down the pages, are there any disadvantages to consider?
    Good question however, as you design and or implement security changes ask yourself a few questions.

    Is there any reason anyone on the planet other than you and or developers or writers need to know the url of the admin login? If you allow a lot of guest content from unverified sources that changes the answer.

    And if you do block the login page, is there any reason not to block the ip of those who attempt to find it or attempt to hit the default wp-login?

    IMO opinion the answer to both of those is to go ahead and block.

    Since you chose wordfence, you should be fine in most cases. And you can test to make sure it is doing what you want by hitting your site using a vpn to see if it locks you out or reacts the way you want it to.

    Rick
    Universal4

  17. The Following User Says Thank You to universal4 For This Useful Post:

    NoDepositCasinos (18 February 2024)

  18. #14
    bon's Avatar
    bon
    bon is offline Private Member
    Join Date
    June 2023
    Location
    Georgia
    Posts
    12
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    For our sites, we usually limit the number of attempts to log in, make regular backups, and use security plugins (approximately the same ones we wrote about above). We are also now thinking about SSL/TLS Encryption.

    I've already had cases when attackers steal the site and I'm sure it's better to prevent hacking

  19. #15
    DaftDog's Avatar
    DaftDog is offline Private Member
    Join Date
    October 2008
    Location
    Your kitchen.
    Posts
    2,068
    Thanks
    651
    Thanked 741 Times in 441 Posts

    Default

    I found this forum thread about WordPress security plugins quite interesting: https://www.webhostingtalk.com/showthread.php?t=1875698

  20. #16
    NoDepositCasinos's Avatar
    NoDepositCasinos is offline Public Member
    Join Date
    November 2022
    Location
    Colombia
    Posts
    582
    Thanks
    105
    Thanked 186 Times in 158 Posts

    Default

    Quote Originally Posted by universal4 View Post
    Good question however, as you design and or implement security changes ask yourself a few questions.

    Is there any reason anyone on the planet other than you and or developers or writers need to know the url of the admin login? If you allow a lot of guest content from unverified sources that changes the answer.

    And if you do block the login page, is there any reason not to block the ip of those who attempt to find it or attempt to hit the default wp-login?

    IMO opinion the answer to both of those is to go ahead and block.

    Since you chose wordfence, you should be fine in most cases. And you can test to make sure it is doing what you want by hitting your site using a vpn to see if it locks you out or reacts the way you want it to.

    Rick
    Universal4
    Thank you for the tips. I was worried about missing something.

    I just took the test you recommended and everything seems to work properly.

  21. #17
    lapa221Q is offline Public Member
    Join Date
    May 2023
    Posts
    33
    Thanks
    0
    Thanked 4 Times in 3 Posts

    Default

    keep your themes and plugins updated, use strong and unique passwords, limit login attempts, use a security plugin like iThemes Security, enable two-factor authentication, and regularly back up your site.

  22. #18
    baldidiot is offline Private Member
    Join Date
    January 2010
    Posts
    4,977
    Thanks
    427
    Thanked 2,271 Times in 1,510 Posts

    Default

    Quote Originally Posted by NoDepositCasinos View Post
    Is there such a thing as too much security? Besides the possibility of slowing down the pages, are there any disadvantages to consider?
    In theory if your security is too strict you could block legitimate users, so in theory yes there is such a thing as "too much". But it depends on what you're doing to secure the site and what your users are likely to do.

    Eg: Set a flood protection to <10 / 5 minutes and you'll probably end up blocking some users.

    Perhaps "too strict" is a better term to use than "too much security" for what I'm talking about though.
    onlinegamblingwebsites.com - Formally known as goodbonusguide.

    Gambling Domains: Small clear out of some of the domains we've been hoarding on Dan - see the list here. Prices negotiable, and willing to swap for decent links.

  23. The Following User Says Thank You to baldidiot For This Useful Post:

    universal4 (28 February 2024)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •