Safety measurements, anything else I can do?
-
I helped someone cleaning their hacked WordPress site. It was outdated and poorly configured. Below a list of things I’ve did to cure and prevent.
In the next couple of weeks, I am planning to release a new site for a big international client. They chose WordPress and I want to keep it as safe as possible. Is there, next to the list below, anything important that I should do as well?
Thanks in advance!
- Reinstall WordPress completely
- Reinstall all plugins
- Reinstall themes
- Update everything
- Install Wordfence
- Made some adjustments in the server settings. E.g. no more CHMOD 777 (don’t even bother to ask). Most files changed to 644 and uploads to 755
Made adjustments in the htaccess, so no PHP files are allowed in the uploads map. - Scanned all files with maleware scanners
- Deleted all user accounts including the mainadmin account. Created a new admin account with a strong login / pass combo.
- Deleted all unnecessairy plugins and content.
- Reset FTP account with strong login / pass
- Reset MySQL account with strong login / pass
- Anti spam plugin and server measurement for sendmail files.
- IP-block for certain countries.
- Etc. Etc.
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
- The topic ‘Safety measurements, anything else I can do?’ is closed to new replies.