Forum

Secure WordPress Si...
 
Notifications
Clear all

Secure WordPress Sites by Hiding WP-Includes Files

4 Posts
4 Users
0 Reactions
160 Views
(@softlogic001089am)
Member Admin
Joined: 1 year ago
Posts: 10
Topic starter  

Hello Guys,

I recently discovered a significant security concern on one of my websites: https://sofatinfertility.com/ . It turns out that the WP-includes files are publicly accessible, which poses a serious security risk. Hackers can exploit this vulnerability through SQL injection or other malicious attacks.

To prevent this, I'll add the following code to my .htaccess file.

 

<IfModule mod_rewrite.c>

RewriteEngine On

RewriteBase /

RewriteRule ^wp-includes/ - [F,L]

</IfModule>

 

User-agent: *

Disallow: /wp-includes/

 

Is this the safest method, or do I have to do more things?


   
Quote
(@mahaveer)
New Member
Joined: 4 months ago
Posts: 2
 

The code you have metioned is a good step to prevent wp-includes/ from public accesss. i will suggest you need to block direct HTTP access to the wp-includes directory by RewriteRule ^wp-includes/ - [F,L]. you can also use robots.txt directive to tell search engine not to index these files by using Disallow: /wp-includes/ this code.


   
ReplyQuote
(@flytech_fly)
New Member
Joined: 4 months ago
Posts: 1
 

Locking down the wp-includes directory that you mentioned is a good step to prevent public access. For additional security, use the rule RewriteRule ^wp-includes/ - [F,L] to prevent direct HTTP access to the wp-includes directory. Furthermore, you may now use a robots.txt directive by the way to prevent search engines from indexing these files.


   
ReplyQuote
(@emmamiller)
New Member
Joined: 4 months ago
Posts: 1
 

You’ve made a good start by changing your .htaccess file. To make your website even safer, you should also add rules to block direct access to important files like wp-config.php and the .htaccess file itself. It's also important to keep an eye on your site and update it regularly to keep it safe.


   
ReplyQuote
Share: