Looking for recommendations on ways to secure WordPress sites since they seem to be prime targets of low life cybercriminals.
At least few of these could be the default WP settings.Here's my base security I do to all our WordPress sites:
Not fully agree on this. If it's a complex WP site, updating can ruin everything. I usually check them manually and update only if there are any vulnerability fixes. In some cases just change appropriate lines of code manually. It's an overkill, I know, but better safe than sorry.Upgrade plugins as they come out (some can be auto-updated if you trust them)
And yet, they're not. They must be manually done.At least few of these could be the default WP settings.
Oh, definitely agree. If you don't trust the source, you shouldn't have any auto-update enabled. And you can restrict your auto-updates to only update sub versions too. For example, we will auto-update Wordfence subversions as they generate new rules and updates nightly and keep the site extra secure. But something like Contact Form 7, usually their updates are cosmetic.Not fully agree on this. If it's a complex WP site, updating can ruin everything. I usually check them manually and update only if there are any vulnerability fixes. In some cases just change appropriate lines of code manually. It's an overkill, I know, but better safe than sorry.