WordPress Security BasicsEast Bay WordPress Meetup 6/20/10Sallie Goetsch
Wait! Isn’t WordPress Secure?
Secure HostDedicated ServerVPSReliable Shared Hosting (NOT Network Solutions). “A properly configured web server will not allow users to access the files of another user, regardless of file permissions. The web server is the responsibility of the hosting provider. The methods for doing this (suexec, et al) have been around for 5+ years.” Matt Mullenweg
BasicsBack Up!Update WordPressUpdate Plugins
Check Your File Permissions
Move wp-config.phpUp one directory (WP will look for it there automatically)Best when you can move wp-config.php out of the public_html (or analagous) directoryDon’t do this with nested WP installs!
wp-config.php: Unique Keys
Username & PasswordNever use “admin” for your admin accountUse a strong password
Database Table NameChange from wp_ to something-else_ (or just choose something else to start with)
Bonus: .htaccess(Only works for static IP addresses)AuthUserFile /dev/nullAuthGroupFile /dev/nullAuthName "Access Control"AuthType Basicorder deny,allowdeny from all#IP address to Whitelistallow from xxx.xxx.xxx.xxx
PluginsAntiVirus for WPAutomatic WordPress BackupSecure WordPressServerBuddyTheme  Authenticity CheckerWordPress DB BackupWP Exploit ScannerWordPress File Monitor WordPress FirewallWP Security Scan
AntiVirushttp://wpantivirus.com/
Automatic WordPress Backuphttp://www.webdesigncompany.net/automatic-wordpress-backup/
Secure WordPresshttp://wordpress.org/extend/plugins/secure-wordpress/
ServerBuddyhttp://pluginbuddy.com/free-wordpress-plugins/serverbuddy/
Theme Authenticity Checkerhttp://builtbackwards.com/projects/tac/
WordPress Database Backuphttp://austinmatzko.com/wordpress-plugins/wp-db-backup/
WordPress Exploit Scannerhttp://ocaoimh.ie/exploit-scanner/
WordPress File Monitorhttp://mattwalters.net/projects/wordpress-file-monitor/
WordPress Firewallhttp://www.seoegghead.com/software/wordpress-firewall.seo
WordPress Firewall Notification
WordPress Security Scanhttp://semperfiwebdesign.com/plugins/wp-security-scan/
http://www.meetup.com/Eastbay-WordPress-Meetup/

Word press security basics