WordPress Hardening

[ad_1]

Hi WordPressians, I need help with WordPress security.

I have a really simple landing page portfolio website, which I don't log into very often. Today, after almost 5 months, I logged into my WordPress dashboard and was shocked to find 201 blog posts. I was literally stunned.

I installed Bit File Manager but couldn't access the root directory due to a 307 error related to the backend. I then checked the htaccess file from cPanel for any unusual code but found nothing suspicious. I also checked the users in the WordPress dashboard, and there was no one listed except for me. I'm unsure how someone gained access to my dashboard.

The theme and plugins I’m using are:

  1. Bricks
  2. SEO Framework
  3. Site Kit by Google
  4. BBQ Firewall
  5. LiteSpeed Cache
  6. WP Vivid for backups

While writing this post, another blog post was added to my site, seemingly from someone in Brazil.

Note: I'm using a very strong password with 40 characters.

[ad_2]
3 Comments
  1. Install and activate wordfence. If you can go into the database and delete all users except yourself. Enable 2fa for admin in wordfence.

    Also make sure on your account you dont have any “application passwords” or whatever they are called in the admin user page.

  2. Are these Posts appearing in your list of Posts, rather than comments listed on your dashboard that bots are posting (perhaps even if not visible on-page) to you page?

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer