• Link to Facebook
  • Link to X
  • Link to Instagram
  • Link to LinkedIn
  • Link to Tumblr
  • Link to Pinterest
  • Link to Youtube
  • Link to TikTok
Kenya Website - Web Design | Web Hosting | Graphic Design | Online Marketing | Call: 0704445999 | Email: info@kenyawebsite.com
  • Shopping Cart Shopping Cart
    0Shopping Cart
Kenya Website
  • Home
  • Web Design
    • Basic Web Design Package
    • Business Web Design Package
    • Corporate Web Design Package
    • Brand Web Design Package
    • Ecommerce Shopping Website Design Package
    • Real Estate Web Design Package
    • Tours & Travel Web Design Package
    • Multivendor Web Design Package
    • Classifieds Website Design Package
    • Real Estate Multivendor Website Design Package
    • Airbnb Web Design Package
    • School / Academic / Education / LMS Web Design Package
    • Blog Web Design Package
  • Web Hosting
    • Shared Hosting
    • VPS Hosting
  • Graphic Design
    • Brochure Design
    • Business Card Design
    • Calendar Design
    • Certificate Design
    • Company Profile Design
    • Delivery Note
    • Email Signature Design
    • Envelope Design
    • Facebook Cover Photo
    • Identity Card Design
    • Invoice Design
    • Letterhead Design
    • Logo Design
    • LPO Design
    • Poster / Flyer Design
    • Prescription Pad Design
    • Price List Design
    • Proforma Invoice Design
    • Product Label
    • Receipt Design
    • Video Intro Design
    • Rollup Banner Design
    • Wedding Card Design
  • Prices
  • Clients
    • Web Design
    • Logo Design
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
Kenya Website

Kenya Website Advanced Security Measures

Restrict access to files and directories

If access permissions for files and directories are not secure enough, these files can be accessed by hackers and used to compromise your website. This security measure sets the permissions for the wp-config file to 600, for other files to 644, and for directories to 755.

Configure security keys

WordPress uses security keys (AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY, and NONCE_KEY) to ensure better encryption of the information stored in the user’s cookies. A good security key should be long (60 characters or longer), random and complex. The security check should verify that the security keys are set up and that they contain at least alphabetic and numeric characters.

Block access to xmlrpc.php

This security measure prevents access to the xmlrpc.php file. It is recommended to apply it to reduce attack surface if XML-RPC is not used. This measure modifies the server configuration file (Apache, nginx). Note that custom directives in the .htaccess files might override this.

Block directory browsing

If directory browsing is turned on, hackers can obtain various information about your website that can potentially compromise its security. If directory browsing is turned on, this security measure can block it. This measure modifies the server configuration file (Apache, nginx). Note that custom directives in the .htaccess file might override this.

Forbid execution of PHP scripts in the wp-includes directory

The wp-includes directory may contain insecure PHP files that can be executed to take over and exploit your website. This security measure prevents the execution of PHP files in the wp-includes directory. This measure modifies the server configuration file (Apache, nginx). Note that custom directives in the .htaccess file might override this.

Forbid execution of PHP scripts in the wp-content/uploads directory

The wp-content/uploads directory may contain insecure PHP files that can be executed to take over and exploit your website. This security measure prevents the execution of PHP files in the wp-content/uploads directory. This measure modifies the server configuration file (Apache, nginx). Note that custom directives in the .htaccess files might override this.

Block access to wp-config.php

The wp-config.php file contains sensitive information like database access credentials, and so on. If, for some reason, processing of PHP files by the web server is turned off, hackers can access the content of the wp-config.php file. This security measure prevents access to the wp-config.php file. This measure modifies the server configuration file (Apache, nginx). Note that custom directives in the .htaccess files might override this.

Disable scripts concatenation for WordPress admin panel

This security measure turns off concatenation of scripts running in the WordPress Administrator panel, preventing your website from being affected by certain DoS attacks. Turning off concatenation of scripts might slightly affect the performance of WordPress Administrator panel, but it should not affect your WordPress website from visitors’ point of view.

Turn off pingbacks

Pingbacks allow other WordPress websites to automatically leave comments under your posts when these websites link to these posts. Pingbacks can be abused to use your website for DDoS attacks on other sites. This security measure turns off XML-RPC pingbacks for your whole website and also disables pingbacks for previously created posts with pingbacks enabled.

Disable PHP execution in cache directories

If a compromised PHP file ends up in one of the cache directories of your website, executing it can lead to compromising the whole website. This security measure disables execution of PHP files in cache directories, preventing such exploits from happening. Note that some plugins or themes might ignore the security recommendations from WordPress Security Team and store valid PHP executables in their cache directory. You might have to disable this security measure if you need to make such plugins or themes work.

Disable file editing in WordPress Dashboard

Disabling file editing in WordPress removes the ability to directly edit the plugin and theme file sources in the WordPress interface. This measure adds an additional layer of protection for the WordPress website in case one of WordPress admin accounts is compromised. In particular, it prevents compromised accounts from easily adding malicious executable code to plugins or themes.

Change default database table prefix

WordPress database tables have the same standard names on all WordPress installations. When the standard wp_ prefix is used for the database table names, the whole WordPress database structure is transparent, making it easy for malicious scripts to obtain any data from it. This security measure changes the database table name prefix to something different than the default wp_ prefix. Note that changing database prefix on a website with production data might be dangerous, so it is strongly advised to back up your website before applying this measure.

Enable bot protection

This measure protects your website from useless, malicious or otherwise harmful bots. It blocks bots that scan your website for vulnerabilities and overload your website with unwanted requests, causing resource overuse. Note that you might want to temporarily disable this measure if you’re planning to use an online service to scan your website for vulnerabilities, since these services might also use such bots.

Block access to sensitive files

This security measure prevents public access to certain files that can contain sensitive information like connection credentials or various information that can be used to determine which known exploits are applicable to your WordPress website.

Block access to potentially sensitive files

This security measure prevents public access to certain files (for example, log files, shell scripts and other executables) that might exist on your WordPress website. Public access to these files could potentially compromise the security of your WordPress website.

Block access to .htaccess and .htpasswd

Gaining access to .htaccess and .htpasswd files allows attackers to subject your website to a variety of exploits and security breaches. This security measure ensures that .htaccess and .htpasswd files cannot be accessed by abusers.

Block author scans

Author scans are looking to find usernames of registered users (especially WordPress admin) and brute-force attack the login page of your website to gain access. This security measure prevents such scans from learning these usernames. Note that depending on the permalink configuration on your website this measure might prevent visitors from accessing pages that list all articles written by a particular author.

Change default administrator’s username

During the installation WordPress creates a user with administrative privileges and the username ‘admin’. Since usernames in WordPress cannot be changed, it is possible to try bruteforcing the password of this user to access WordPress as the administrator. This security measure creates WordPress administrator account with randomized username, and ensures that there is no user with the administrative privileges and ‘admin’ username. If ‘admin’ user is found, all content belonging to this user is reassigned to the new administrator account, and ‘admin’ user account is removed.

 

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
  • Visit us on Yelp
https://kenyawebsite.com/wp-content/uploads/2025/10/website-logo.png 0 0 Kenya Website https://kenyawebsite.com/wp-content/uploads/2025/10/website-logo.png Kenya Website2024-05-19 19:15:462024-05-19 19:15:46Kenya Website Advanced Security Measures
0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular
  • Kenya Website Advanced Security MeasuresMay 19, 2024 - 7:15 pm
Recent
  • Kenya Website Advanced Security MeasuresMay 19, 2024 - 7:15 pm
Popular
  • Kenya Website Advanced Security MeasuresMay 19, 2024 - 7:15 pm

About Kenya Website

Kenya Website are experts in brand development services offering all-inclusive professional web design, graphic design and online marketing services in Nairobi, Kenya.

Get in touch with us to get your professional digital design and digital marketing services.

Web Design Packages

Basic Website Design

Business Website Design

Corporate Website Design

Brand Website Design

Multivendor Website Design Package

Classifieds Website Design Package

Real Estate Marketplace Package

Airbnb Website Design Package

School Website Design Package

Blog Web Design Package

Web Hosting Packages

Shared Hosting

Graphic Design Services

Bill Book Design

Brochure Design

Business Card Design

Calendar Design

Certificate Design

Company Profile Design

Delivery Note Design

Email Signature Design

Envelope Design

Facebook Cover Photo Design

Flier Design

Gift Voucher Design

ID Card Design

Invoice Design

Invitation Card Design

Letterhead Design

Logo Design

Membership Card Design

Notepad Design

Poster Design

Product Label Design

Price List Design

Prescription Pad Design

Proforma Invoice Design

Rollup Banner Design

Video Graphic Design

Wedding Card Design

Online Marketing Services

Search Engine Optimisation (SEO)

Google Ads Marketing & Management Services

Social Media Management Services

Social Media Marketing Services

 

Useful Links

About Us

Payments

Our Guideline on Structuring Your Web Content

Pick Your Brand Colours

Pick Your Brand Fonts

Email Us

Call Us

WhatsApp Us

Leave Your Feedback

Terms & Conditions

Privacy Policy

Copyright © Kenya Website - Web Design | Web Hosting | Graphic Design | Online Marketing
  • Link to Facebook
  • Link to X
  • Link to Instagram
  • Link to LinkedIn
  • Link to Tumblr
  • Link to Pinterest
  • Link to Youtube
  • Link to TikTok
Scroll to top Scroll to top Scroll to top