WordPress Security Hardening That Is Not a Plugin
Security that lives in the server, configuration and process rather than a plugin: file permissions, disabled file editing, user hygiene, edge filtering.
Writing
5 write-ups from production, newest first. Each one is a problem hit on a real project and how it was diagnosed and fixed.
Security that lives in the server, configuration and process rather than a plugin: file permissions, disabled file editing, user hygiene, edge filtering.
What a website security scan actually does, the problems it finds and the ones it misses, why a clean scan is not a secure site, and what else a care plan does.
How daily website backups should work: where they are stored, how often they are tested, how long they are kept, and how a restore actually happens.
What to do in the first 24 hours after your website is hacked, in plain words: contain it, tell people, clean it, and stop it happening again.
What the Not Secure warning in the browser means, why it appears, how it affects visitors and search, and the steps that restore the padlock.