Membership is FREE – with unlimited access to all features, tools, and discussions. Premium accounts get benefits like banner ads and newsletter exposure. ✅ Signature links are now free for all. 🚫 No AI-generated (LLM) posts allowed. Share your own thoughts and experience — accounts may be terminated for violations.

Wordpress hacked

I use WordFence which is pretty good for the free version. Also really hammer down the folder permissions. I run a server with mod-ruid2 which runs apache/PHP with the users ID instead of the webserver ID. Means the wp-content folder can be run with 755 instead of 775 or 777.

Also as has been mentioned rename the /wp-content folder to something like /assets - there's additional steps & wp-config.php settings needed. Links on the interwebs.

And also move the wp-login page, again interwebs for the code for the functions.php file.

I use my own bespoke skeleton theme https://github.com/ontiuk/iPressRD2 which also pretty much strips all the garbage that WP injects into the header - and telegraphs that it's a WP site - including bloody emojis.

Stephen
 
  • Informative
Reactions: dee
@tifosi

Do you ever get screwed by wordpress updates with the functions file ?

The functions.php file is in the theme, so not applicable to core WP updates. I generally use it to create a standalone theme for personal/client projects - no page-builder garbage.

Stephen
 
  • Informative
Reactions: dee
@tifosi

Do you ever get screwed by wordpress updates with the functions file ?

It is a good idea to a have a standalone functions file so theme updates and such don't have any effect. Just have one as plug-in
 
It is a good idea to a have a standalone functions file so theme updates and such don't have any effect. Just have one as plug-in

For commercial themes e.g bloated multi-option page-builder themeforest offerings, and those in the WordPress repository that have the update theme option in WP admin, then yes, I recommend using the theme as a parent theme always and creating a child theme for development. For bespoke standalone themes, then it's not really required, though I do do it for client projects.
 
I run more than 2000 WP Sites, we had this really often. But since we use Wordfence it became better. You should really try it out.

2000 ! Holy wordpress.That's a lot of sites. I've already installed it on my sites. Seems fab. Securi seems to be the other one that comes up a lot as an option.
 

Rule #1: Be Respectful

Do not insult any other member. Be polite and do business. Thank you!

Premium Members

New Threads

Domain Forum Friends

Lastest Listings

Our Mods' Businesses

*the exceptional businesses of our esteemed moderators
General chit-chat
Help Users
  • No one is chatting at the moment.
      There are no messages in the current room.
      Top Bottom