Quick Online Tips byline Home | About | Guestblog | Advertise | Themes | Jobs | Shop | Contact
14/08/2007
Bookmark and Share
ADVERTISEMENTS

Matt Cutts, the Google engineer gave some amazing tips at WordCamp 2007. I discussed some lessons learnt and new WordPress updates, that were revealed at WordPress camp. Now Matt Cutt has released the powerpoint presentation that he talked of at the conference and some new wordpress security tips were known.

Posting an article about Whitehat SEO tips for bloggers, Matt Cutts released the PowerPoint deck (.ppt) that he presented after the Google’s PR team okayed the release. I learnt 3 new WordPress security tips from his presentation.

1. Drop version string in header.php
The tag in your header.php that displays your current version of wordpress.
<meta name="generator" content="WordPress <?php bloginfo('version'); ?>" />

Since everyone knows your wordpress version this way, your blog is prone to hackers if you have not upgraded to the new version.
Hide your wordpress version by deleting it or simply changing it to
<meta name="generator" content="WordPress" />

2. Put a blank index.html in /plugins/ directory.
In a normal wordpress installation, anyone can access your WordPress plugin folder to see which plugins you have installed. The path is
http://www.yourdomain.com/wp-content/plugins/

Try it for your blog and your entire directory structure is revealed. Just create a blank file in notepad and name it index.html and drop it in your plugins folder and the folder details will no longer be visible to the public and prevent hackers from cracking a plugin security hole.

3. Put .htaccess in /wp-admin/
He points to this article of Protecting the WordPress wp-admin folder. This will limit access to this folder by IP address and attempts at accessing any file within this folder will be greeted with a Forbidden error message.

He warns that you need to place this file in the /wp-admin folder and not replace or delete the .htaccess file in the root folder of your blog. Though he says the security issue was fixed in recent wordpress version, this is a security idea which can help you further protect your wp-admin folder.

Tip: It is easy to block search engines from crawling your wp-admin folder by blocking access via robots.txt file. I added this line
Disallow: /wp-admin/

See Also

Tags: #Blogging   #SEO   #Security   #WordPress

Free subscription: Subscribe RSS feed or get daily tips in your email
* Click confirmation link sent in email * Don't see the email, check spam folder

18 Responses

  1. ram says:

    2nd one can be avoided by adding a line
    Options -Indexes
    in your .htaccess file. This way you dont have to manually add index.html files to folders like plugins.

  2. Michael says:

    Those are awesome tips, especially the one about changing the meta information in your header, I will surely do that as soon as I can

  3. pearl says:

    I am so glad I came across this article because just a few days ago I saw all of my plug-in files were visible, I thought I might have done something wrong! great tips!! thanks for pointing them out… will be working on these soon

  4. thanks for the tips , i have implemented it immediately

  5. Craig says:

    Regarding the robots.txt suggestion — if I understand correctly, search engines do not necessarily honour the instructions in the file, so you may only be blocking access to “legitimate” crawlers.
    I am not 100% sure on this, but if I am, then it is a good thing to do, but not as effective as one might wish it to be.

  6. iwebie says:

    Nice tips. I used to use WordPress, but I got sick of all the security holes and switched back to MovableType.

  7. Cebu says:

    This is truly amazing. Keep it up your post!

  8. Cebu Seo says:

    Great tips and I will definitely try this one on my WP-based blogs. I don’t know if Wp.com is using this tips, any idea coz some of my blogs are hosted on their site?

  9. renan says:

    nice blog it is very informative more people appreciate this kind of blog..thanks for the tips i learn in this blog.

  10. Teenburg says:

    I’m use security key!
    What is Security Key?
    It is a hashing salt that is not readable through the database or in more easy words the WordPress Security Key is a unique phrase which causes better encryption of information stored in the user’s cookies.

  11. cebu seo says:

    While you are learning a few tip or two from the Google engineer, I am here struggling to learn basics like upgrading a template… All my 6 blogs in wordpress are having a hard time getting updates because I don’t know how to access through ftp.

  12. km says:

    Nice tips specially for the tips 2 and tips 3 to avoid others to view your wp structure

  13. robots.txt does not provide any security at all. A malicious bot can simply choose to ignore it.

    Make sure you password protect all the sensitive information.

  14. I have to add my voice to the others in respect to the robots.txt file advice, malicious bots dont follow the rules of robots.txt, and since you can easily check robots.txt going to http://www.domain.com/robots.txt an attacker will find out what are the folders you want to protect easily.

    The other two tips are really good.

  15. vivi says:

    “Put .htaccess in /wp-admin/ “will limit access to this folder by IP address and attempts at accessing any file within this folder will be greeted with a Forbidden error message.

    But, I wanna limit access to any folder by Ip add. and attempts at accessing any file within my blog will be greeted with a forbidden error message….

    How can i do …?
    I need your help…..

  16. Great content, very helpfull. The web needs more great sites like this.

  17. Eav says:

    Great tips, especially modifiled about the meta tag in the header, cool suggestion.

  18. Praveen says:

    Wow!!! Nice Stuff buddy…..
    Recently there is a attack over WordPress Blogs by Hackers.The saddest part is exploited security Hole not yet Identified,

    Dirty Attack Over Hundreds Of WordPress Blogs
    http://www.techpraveen.com/2010/04/dirty-attack-over-hundreds-of-wordpress.html

Leave a Reply to “3 New WordPress Security Tips I Learnt from Matt Cutts”

Free Subscription
* Click confirmation link sent in email
writeWrite a guest article - Get free links, SEO, traffic, readers for your site. Read 300 guest bloggers cant be wrong! Stars: Srikanth, Eric, Hans, Jo, Paul and Indu
Job Search 
job title, keywords, company, location jobs by job search
Find Jobs in India | Jobs in US