Replies: 0
I’m hosting a few WordPress sites and my approach to security thus far is to make sure the core and all plug-ins and themes are kept up-to-date, and I run Configserver Firewall (CSF) / LFD on my VPS.
There’s a number of WordPress Security plug-ins out there including ones that attempt to “hide” the fact you are running WordPress. I’ve got one site owner that is interested in doing this hiding. I’ve read some articles in the past on the subject that concluded essentially these hide plugins are in effective as you can’t 100% hide you have a WordPress site from any knowledgable hacker.
I really have two questions regarding WordPress Security:
(1) For those that are already familiary with BOTH CSF/LFD AND the most popular WordPress Security Plug-Ins, are there any plug-ins worth installing that increase security but don’t unecessarily duplicate security functions that CSF/LFD is already performing, AND, don’t add bells & whistles that are unecessary and just overcomplicate the WordPress setup and potentially effect performance.
(2) Disregarding the “hide” WordPress plugins from a security standpoint, what would be the best one to use taking into considerating the first question?
Essentially, I’m looking for someone that has experience running CSF/LFD hosting WordPress sites that has experimented with various WordPress Security Plug-Ins. They seem hard to come by as it seems the vast majority (not all) WordPress users aren’t running on a VPS or Dedicated Server running CSF/LFD, or, the vast majority of Sys Admins knowledgable about CSF/LFD, aren’t WordPress Security Experts. There’s got to be a few “Unicorns” out there though?