Membership is FREE – with unlimited access to all features, tools, and discussions. Premium accounts get benefits like banner ads and newsletter exposure. ✅ Signature links are now free for all. 🚫 No AI-generated (LLM) posts allowed. Share your own thoughts and experience — accounts may be terminated for violations.

Wordpress hacked

I use WordFence which is pretty good for the free version. Also really hammer down the folder permissions. I run a server with mod-ruid2 which runs apache/PHP with the users ID instead of the webserver ID. Means the wp-content folder can be run with 755 instead of 775 or 777.

Also as has been mentioned rename the /wp-content folder to something like /assets - there's additional steps & wp-config.php settings needed. Links on the interwebs.

And also move the wp-login page, again interwebs for the code for the functions.php file.

I use my own bespoke skeleton theme https://github.com/ontiuk/iPressRD2 which also pretty much strips all the garbage that WP injects into the header - and telegraphs that it's a WP site - including bloody emojis.

Stephen
 
  • Informative
Reactions: dee
@tifosi

Do you ever get screwed by wordpress updates with the functions file ?

The functions.php file is in the theme, so not applicable to core WP updates. I generally use it to create a standalone theme for personal/client projects - no page-builder garbage.

Stephen
 
  • Informative
Reactions: dee
@tifosi

Do you ever get screwed by wordpress updates with the functions file ?

It is a good idea to a have a standalone functions file so theme updates and such don't have any effect. Just have one as plug-in
 
It is a good idea to a have a standalone functions file so theme updates and such don't have any effect. Just have one as plug-in

For commercial themes e.g bloated multi-option page-builder themeforest offerings, and those in the WordPress repository that have the update theme option in WP admin, then yes, I recommend using the theme as a parent theme always and creating a child theme for development. For bespoke standalone themes, then it's not really required, though I do do it for client projects.
 
I run more than 2000 WP Sites, we had this really often. But since we use Wordfence it became better. You should really try it out.

2000 ! Holy wordpress.That's a lot of sites. I've already installed it on my sites. Seems fab. Securi seems to be the other one that comes up a lot as an option.
 

Rule #1: Be Respectful

Do not insult any other member. Be polite and do business. Thank you!

Members online

No members online now.

Premium Members

New Threads

Domain Forum Friends

Lastest Listings

Our Mods' Businesses

*the exceptional businesses of our esteemed moderators
General chit-chat
Help Users
  • No one is chatting at the moment.
  • Siusaidh AcornBot:
    Siusaidh has left the room.
      Siusaidh AcornBot: Siusaidh has left the room.
      Top Bottom