- Protecting your admin suite by restricting access to I.P. addresses specified in the .htaccess file.
- Including an empty index.html file in your /plugins/ directory to prevent anyone from browsing the otherwise wide-open directory (although attempting to access the plugins directory here seems to generate a 404 error instead…)
- Removing the WP version information metadata from your header.php file to avoid giving easy clues to potential hackers.
Needless to say, I’ll be acting on all three of those across my client sites (as applicable, it could be difficult perhaps to get accurate I.P. address information from all my clients) in my next WP-admin session.






















Be The First To Comment
Related Post
Please Leave Your Comments Below