Core Security Hardening Steps#
- 1Protect
wp-login.php: Limit login attempts using plugins like Wordfence or LiteSpeed Cache reCAPTCHA. - 2Disable XML-RPC: If you do not use the WordPress mobile app, block XML-RPC in
.htaccessto prevent DDoS amplification:
apache
<Files xmlrpc.php>
Order Allow,Deny
Deny from all
</Files>- 1Correct File Permissions: Folders must be
0755and files0644. Sensitive files likewp-config.phpshould be0600or0640. - 2Virus Scanner: Run periodic scans in cPanel -> Virus Scanner to inspect
public_htmlfor known webshells and malware.