Securing WordPress

  • Install WordFence Security Plugin
  • Protect wpconfig.php by adding this block in .htaccess

    # BEGIN protect wpconfig.php
    <files wp-config.php>
    order allow,deny
    deny from all
    </files>
    # END protect wpconfig.php
  • Proteect xmlrpc.php by adding this block in .htaccess

    # BEGIN protect xmlrpc.php
    <files xmlrpc.php>
    order allow,deny
    deny from all
    </files>
    # END protect xmlrpc.php