Uncategorised

Essential WordPress Apache Security Hardening

A complete, step-by-step guide to hardening your WordPress website at the server level. Learn how to secure core files, restrict dangerous script execution, enforce browser HTTP security headers on Apache web servers, and implement essential application safeguards.

1. Uploads Hardening: PHP Script Execution Prevention

To prevent PHP execution in uploads folder add this code in uploads/.htaccess:

<Files *.php>
  <IfModule mod_authz_core.c>
    # Apache 2.4+
    Require all denied
  </IfModule>
  <IfModule !mod_authz_core.c>
    # Apache 2.2 (Legacy)
    Order Deny,Allow
    Deny from all
  </IfModule>
</Files>

2. ​XML-RPC Hardening: Remote Request & Pingback Protection

Older WordPress protocol for remote publishing and pingbacks, protecting from brute-force login attacks and automated DDoS attempts.

To disable XML-RPC add this code in root .htaccess:

<Files xmlrpc.php>
  <IfModule mod_authz_core.c>
    # Apache 2.4+
    Require all denied
  </IfModule>
  <IfModule !mod_authz_core.c>
    # Apache 2.2 (Legacy)
    Order Deny,Allow
    Deny from all
  </IfModule>
</Files>

Or in your theme functions.php add this code (althought it is better to do the .htaccess way because it blocks requests at the server level before loading WordPress or PHP):

add_filter( 'xmlrpc_enabled', '__return_false' );

> Then Verify if it is Disabled: https://yourdomain.com/xmlrpc.php

3. Configuration Security: Core System File Access Restrictions

To protect your wp-config.php file, which contains your database credentials and secret keys add this code in root .htaccess:

<Files wp-config.php>
  <IfModule mod_authz_core.c>
    # Apache 2.4+
    Require all denied
  </IfModule>
  <IfModule !mod_authz_core.c>
    # Apache 2.2 (Legacy)
    Order Deny,Allow
    Deny from all
  </IfModule>
</Files>

> Then Verify if it is Disabled: https://yourdomain.com/wp-config.php

4. Directory Security: Directory Index & Browsing Protection

To block viewing the raw list of files and folders when there is no default index page add this code in root .htaccess file:

Options -Indexes

5. Browser Security: HTTP Security Headers Hardening

​Enforce strict safety policies: preventing browsers from sniffing mismatched file types, stopping your site from being embedded in malicious clickjacking iframes, controlling referrer data when users leave, forcing permanent HTTPS connections, and restricting the misuse of browser device sensors.

Add this code in root .htaccess:

<IfModule mod_headers.c>
# 1. X-Content-Type-Options (Prevents MIME-sniffing)
Header set X-Content-Type-Options "nosniff"
# 2. X-Frame-Options (Prevents clickjacking)
Header set X-Frame-Options "SAMEORIGIN"
# 3. Referrer-Policy (Controls navigation data leakage)
Header set Referrer-Policy "strict-origin-when-cross-origin"
# 4. Strict-Transport-Security (Forces permanent HTTPS)
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" env=HTTPS
# 5. Permissions-Policy (Blocks misuse of device sensors like camera/mic)
Header set Permissions-Policy "geolocation=(), microphone=(), camera=()"
</IfModule>

> Check headers in Security Headers: https://securityheaders.com/


Application Security: Core Safeguards & Plugin Defenses

​Malware & File Integrity Scanning

An automated process that compares every file on your server against official WordPress core files and virus signature databases to detect backdoors or malicious code injections.

​Brute-Force & IP Locking

A security control that tracks failed login attempts and automatically bans aggressive IP addresses or bots from accessing your site.

​Two-Factor Authentication (2FA)

A login security layer that requires both a standard password and a temporary passcode generated by an authenticator app (e.g., Google Authenticator, Authy) on a mobile device.

Login CAPTCHA Protection

An automated verification check (such as Google reCAPTCHA) added specifically to your login screen to block automated bots and brute-force scripts from submitting fake credentials.

> These 4 issues can be done with free plugin Wordfence: https://www.wordfence.com/


Contact me about: Essential WordPress Apache Security Hardening, by:

  Email »  WhatsApp »