I take my blog security VERY seriously. Your blog is an extension of yourself – the next closest thing to DNA and diapers. It only makes sense if you’re pouring that much time into something you protect it.
With every new installation, I start with the same three plugins:
- Limit Log-In Attempts – Limits the amount of times someone can enter incorrect log-in information before that IP address is restricted from logging in. It has a bigger, meaner, older brother: Login Lockdown – which bans all IP addresses in that RANGE.
- WP Spam-Free – If you’re not non-profit or using your blog for personal use, you won’t be able to use Akismet (you know, unless you’re dishonest) – bummer, but there’s some really good spam guards in existence beside Akismet. One of the best – WP Spam-Free.
- WP SuperCache – No matter what kind of traffic your blog gets, if someone wants to take you down, a DDOS attack is really only a click away. I use SuperCache on all my blogs. It makes your site much more resilient against massive amounts of Diggs or if some punk decides to DDOS you.
Those plugins will protect you from most threats. If you’re really concerned about your blog’s security, here’s four more tips you can pick up on:
- Pick a good password (at least one upper-case letter, one lower-case letter, one number and one symbol),
- Change the default display for your username to your nickname,
- Remove the Admin username (through the database), and
- Change the default database prefix from ‘WP_’ to something else
What are your must-have plug-ins or security tips? Let us know by leaving a comment!
{ 2 comments… read them below or add one }
Good thoughts on security Nick. Also a good practice is to keep your WordPress version upgraded. I’m not saying upgrade the day a new version of WP comes out, as this could break some plugins that have not updated yet. Upgrading your themes & not staying in older WP versions makes it harder for your site to be hacked
.
Haha, Matt – I would have to agree.
I tell my clients wait 24-48 hours, most good plugins will be upgraded by then (and of course, the random, blog-destroying errors that sometimes happen in the first 24 hours can be avoided).
Thanks for your comment! It irritates me to no end when users don’t upgrade their WP blogs for fear of angering the WP gods or something. Yuck.
-Nick