{"id":287,"date":"2014-01-13T21:07:10","date_gmt":"2014-01-13T21:07:10","guid":{"rendered":"https:\/\/ahorseforonebin.co.uk\/?p=287"},"modified":"2014-01-16T06:16:35","modified_gmt":"2014-01-16T06:16:35","slug":"wordpress-points-of-security","status":"publish","type":"post","link":"https:\/\/ahorseforonebin.co.uk\/?p=287","title":{"rendered":"wordpress points of security"},"content":{"rendered":"<p>I may be preaching to the converted on this but&#8230;<\/p>\n<p>I like WordPress (in fact I like most .php-based products).<\/p>\n<p>I&#8217;ve tried Ghost and thought it was meh. I&#8217;ve worked with Drupal and thought it was alright (if slightly over-engineered).<\/p>\n<p>But I *like* WordPress.<\/p>\n<p>However, the more time I spend with it, the more I realise that WordPress has shortcomings, here and there.<\/p>\n<p>It&#8217;s a pros and cons argument.<\/p>\n<p>Yes, there is a very large user community developing features and facilities for the (functional and non-functional portions of the) application.<\/p>\n<p>And this is good. This huge, hardcore team of developers are continually turning the WordPress product in to a much more sophisticated tool.<\/p>\n<p>But there are also some naughty people out there, attempting to bugger up some people&#8217;s WordPress installations.<\/p>\n<p>Just for a laugh.<\/p>\n<p>When I was in LA three years ago, one of my WordPress-based websites was hacked.<\/p>\n<p>It was a relatively straightforward task to get in to the back-end and fix the website. It was just frustrating that it had happened.<\/p>\n<p>Though, interestingly, I believe I would fix the problem in a much simpler way these days.<\/p>\n<p>But here are a couple of simple golden rules that everyone should undertake to protect their WordPress environment:<\/p>\n<ul>\n<li>log in as administrator<\/li>\n<li>create a new user (with a non-obvious name)<\/li>\n<li>promote that user to administrator<\/li>\n<li>log out as administrator<\/li>\n<li>log in as the new administrator user you have just created<\/li>\n<li>delete the old administrator account<\/li>\n<\/ul>\n<p>And while I&#8217;m on the patronising subject of the blindingly obvious:<\/p>\n<ul>\n<li>never publish content from an admin account &#8211; use an author\/editor role<\/li>\n<li>change your passwords \u00a0frequently (and use a random password generator for security)<\/li>\n<\/ul>\n<p>But don&#8217;t worry about deleting your admin user if you have been posting from content from it &#8211; you can just assign your new author\/contributor user as owner of the legacy content, and then you don&#8217;t lose anything.<\/p>\n<p>Maybe you already know these things.<\/p>\n<p>But we&#8217;re never to old to learn, are we?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I may be preaching to the converted on this but&#8230; I like WordPress (in fact I like most .php-based products). I&#8217;ve tried Ghost and thought it was meh. I&#8217;ve worked with Drupal and thought it was alright (if slightly over-engineered). But I *like* WordPress. However, the more time I spend \u2026 <a class=\"continue-reading-link\" href=\"https:\/\/ahorseforonebin.co.uk\/?p=287\"> Continue reading <span class=\"meta-nav\">&rarr; <\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-287","post","type-post","status-publish","format-standard","hentry","category-admin"],"_links":{"self":[{"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=287"}],"version-history":[{"count":5,"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/287\/revisions"}],"predecessor-version":[{"id":293,"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/287\/revisions\/293"}],"wp:attachment":[{"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ahorseforonebin.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}