{"id":4945,"date":"2018-10-10T18:43:41","date_gmt":"2018-10-10T17:43:41","guid":{"rendered":"https:\/\/blog.fabianpiau.com\/?p=4945"},"modified":"2021-01-14T16:35:19","modified_gmt":"2021-01-14T16:35:19","slug":"tips-to-make-your-wordpress-website-secure","status":"publish","type":"post","link":"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/","title":{"rendered":"Tips to make your WordPress website secure"},"content":{"rendered":"<p><a class=\"lang\" href=\"https:\/\/blog.fabianpiau.com\/fr\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/\" title=\"Lire en fran\u00e7ais\"><strong class=\"labellang\"><span class=\"fr\">&nbsp;<\/span>Version fran\u00e7aise disponible<\/strong><\/a><\/p>\n<div class=\"info\"><strong class=\"label\">Update<\/strong><br \/>\n<strong>January, 14th, 2021 : <\/strong> Update security headers, replaced &#8220;Feature-policy&#8221; with &#8220;Permissions-policy&#8221;.\n<\/div>\n<p>WordPress is one of the most popular CMS (Content Management System). That popularity also means that it is a target of choice for hackers.<br \/>\nIn this article, I will give you some tips to keep your website secure and avoid being attacked.<\/p>\n<p><br clear=\"none\" \/><\/p>\n<h4>1. Use latest versions<\/h4>\n<p>This is true for WordPress itself but also for all your extensions. There are new versions available regularly. If a plugin has not been updated for a while, it is probably not maintained anymore and you might need to remove or replace it. This is also applicable for your theme.<br \/>\nThe version of PHP is also important, check with your hosting provider that you are running the latest version of PHP (7.X), especially <a href=\"https:\/\/www.php.net\/supported-versions.php\" target=\"_blank\" title=\"PHP supported versions\" rel=\"noopener noreferrer\">the versions 5.X won&#8217;t be supported by the end of the year<\/a>.<br \/>\nAlso, note that the more extensions you have installed, the more risk you are taking, as your WordPress configuration will rely on more 3rd party code. You should only keep the plugins that you really need. If a plugin is disabled, don&#8217;t keep its source code and remove all its associated files.<\/p>\n<p><br clear=\"none\" \/><\/p>\n<h4>2. Use secure login details<\/h4>\n<p>Never use the default admin user. If you do, disable this account and create your own account with a personalized username.<br \/>\nChoose a <a href=\"https:\/\/blog.fabianpiau.com\/en\/2013\/11\/01\/some-basic-rules-to-prevent-your-accounts-from-getting-hacked\/\" target=\"_blank\" title=\"Some basic rules to prevent your accounts from getting hacked\" rel=\"noopener noreferrer\">strong password<\/a>. If several users are managing your website, make sure the permissions are valid and avoid giving the admin permission to everyone.<\/p>\n<p><br clear=\"none\" \/><\/p>\n<h4>3. Scan your website<\/h4>\n<p>This is an easy and quick  way to find vulnerabilities and see if one of your plugins is vulnerable or not. You can use these 2 online tools:<\/p>\n<ul>\n<li><a href=\"https:\/\/hackertarget.com\/wordpress-security-scan\/\" target=\"_blank\" title=\"WordPress Security Scan\" rel=\"noopener noreferrer\">WordPress Security Scan<\/a> (my favourite with a detailed report)<\/li>\n<li><a href=\"https:\/\/wpsec.com\/\" target=\"_blank\" title=\"WPScans\" rel=\"noopener noreferrer\">WPSec<\/a><\/li>\n<\/ul>\n<p><br clear=\"none\" \/><\/p>\n<h4>4. Use .htaccess files to protect your directories<\/h4>\n<p>The <code>.htaccess<\/code> file is a server configuration file. It allows you to define rules for your server to follow. <\/p>\n<p>For example, in <code>\/wp-content\/uploads<\/code>, I have created the following <code>.htaccess<\/code>:<\/p>\n<pre class=\"brush: xml; title: ; notranslate\" title=\"\">\r\n# Deny access to everything by default\r\nOrder deny,allow\r\nDeny from all\r\n\r\n# Allow access to media files\r\n&lt;FilesMatch '\\.(jpg|jpeg|png|gif|bmp|zip|rar|pdf)$'&gt;\r\n    Allow from all\r\n&lt;\/FilesMatch&gt;\r\n<\/pre>\n<p>This config ensures only media files are accessible from the browser, any JavaScript, PHP files will be discarded. It is not 100% bulletproof as only the extension is checked, but it is better than nothing.<\/p>\n<p>To avoid execution of malicious PHP in some folder (e.g. in <code>\/wp-includes<\/code>), you can create another <code>.htaccess<\/code> file with the following content:<\/p>\n<pre class=\"brush: xml; title: ; notranslate\" title=\"\">\r\n&lt;Files *.php&gt;\r\nOrder allow,deny\r\nDeny from all\r\n&lt;\/Files&gt;\r\n<\/pre>\n<p><br clear=\"none\" \/><\/p>\n<h4>5. Review file and directory permission<\/h4>\n<p>Make sure the critical files (<code>wp-config.php<\/code>, <code>php.ini<\/code>&#8230;) are not writable publicly, only readable. Only owners should be able to write.<\/p>\n<p><br clear=\"none\" \/><\/p>\n<h4>6. Use security headers<\/h4>\n<p>You can check <a href=\"https:\/\/securityheaders.com\/\" target=\"_blank\" title=\"Security Headers Online Tool\" rel=\"noopener noreferrer\">which security headers you currently use with this online tool<\/a>.<\/p>\n<p>At the root folder, update the <code>.htaccess<\/code> file and add:<\/p>\n<pre class=\"brush: xml; title: ; notranslate\" title=\"\">\r\n# Extra Security Headers\r\n&lt;IfModule mod_headers.c&gt;\r\n\tHeader set Strict-Transport-Security 'max-age=31536000; includeSubDomains'\r\n\tHeader set X-XSS-Protection '1; mode=block'\r\n\tHeader set X-Frame-Options 'sameorigin'\r\n\tHeader set X-Content-Type-Options 'nosniff'\r\n\tHeader unset Server\r\n\tHeader always unset X-Powered-By\r\n\tHeader unset X-Powered-By\r\n\tHeader unset X-CF-Powered-By\r\n\tHeader unset X-Mod-Pagespeed\r\n\tHeader unset X-Pingback\r\n&lt;\/IfModule&gt;\r\n<\/pre>\n<p>In <code>wp-config.php<\/code>, add:<\/p>\n<pre class=\"brush: xml; title: ; notranslate\" title=\"\">\r\n\/** Extra Security *\/\r\nheader('X-Frame-Options: SAMEORIGIN');\r\nheader('X-XSS-Protection: 1; mode=block');\r\nheader('X-Content-Type-Options: nosniff');\r\nheader('Strict-Transport-Security:max-age=31536000; includeSubdomains; preload');\r\nheader('Referrer-Policy: no-referrer-when-downgrade');\r\nheader('Content-Security-Policy: upgrade-insecure-requests');\r\nheader('Permissions-Policy: autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), microphone=(), midi=(), payment=()');\r\nheader_remove('X-Powered-By');\r\nheader_remove('Server');\r\nheader_remove('X-CF-Powered-By');\r\nheader_remove('X-Mod-Pagespeed');\r\nheader_remove('X-Pingback');\r\n@ini_set('session.cookie_httponly', true);\r\n@ini_set('session.cookie_secure', true);\r\n@ini_set('session.use_only_cookies', true);\r\n<\/pre>\n<p><br clear=\"none\" \/><\/p>\n<h4>7. Do not expose too much information<\/h4>\n<p>At the root folder of your website, in <code>php.ini<\/code>, add the line:<\/p>\n<pre class=\"brush: xml; light: true; title: ; notranslate\" title=\"\">\r\nexpose_php = Off\r\n<\/pre>\n<p>Your current version of PHP will not be exposed.<\/p>\n<p><br clear=\"none\" \/><\/p>\n<h4>8. Backup your website regularly<\/h4>\n<p>Last but not least! You don&#8217;t need a particular software or extra plugin to achieve this.<\/p>\n<ul>\n<li>With your favourite FTP tool (e.g. <a href=\"https:\/\/filezilla-project.org\/\" target=\"_blank\" title=\"Filezilla\" rel=\"noopener noreferrer\">Filezilla<\/a>), save all the files available on your server.<\/li>\n<li>For the database, use the available MySQL backup feature. Many hosting companies provide access to phpMyAdmin, an online tool.<\/li>\n<\/ul>\n<p>I recommend doing a backup every month, and keep the history of the last 6 backups somewhere safe. Of course, it depends on the volume of articles you are writing and how critical is your data.<\/p>\n<p><br clear=\"none\" \/><\/p>\n<p>That&#8217;s it! If you have done all the above, your website should be more resilient to attacks. In the worst case, you should be able to recover easily.<\/p>\n<p>Happy safe blogging!<\/p>","protected":false},"excerpt":{"rendered":"<p>&nbsp;Version fran\u00e7aise disponible Update January, 14th, 2021 : Update security headers, replaced &#8220;Feature-policy&#8221; with &#8220;Permissions-policy&#8221;. WordPress is one of the most popular CMS (Content Management System). That popularity also means that it is a target of choice for hackers. In this article, I will give you some tips to keep your website secure and avoid [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4953,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[4],"tags":[231,228,230,109],"class_list":["post-4945","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-hacking","tag-hacker","tag-security","tag-wordpress"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Tips to make your WordPress website secure | CarmaBlog<\/title>\n<meta name=\"description\" content=\"&nbsp;English version available Mise \u00e0 jour 14 Janvier 2021 : Mise \u00e0 jour des security headers, remplacement de &quot;Feature-policy&quot; par &quot;Permissions-policy&quot;.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Tips to make your WordPress website secure | CarmaBlog\" \/>\n<meta property=\"og:description\" content=\"&nbsp;English version available Mise \u00e0 jour 14 Janvier 2021 : Mise \u00e0 jour des security headers, remplacement de &quot;Feature-policy&quot; par &quot;Permissions-policy&quot;.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/\" \/>\n<meta property=\"og:site_name\" content=\"CarmaBlog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/fabian.piau\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/fabian.piau\" \/>\n<meta property=\"article:published_time\" content=\"2018-10-10T17:43:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-01-14T16:35:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i1.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2018\/10\/wordpress-hacker.png?fit=300%2C300&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Fabian Piau\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@fabianpiau\" \/>\n<meta name=\"twitter:site\" content=\"@fabianpiau\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fabian Piau\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/fr\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/fr\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/\"},\"author\":{\"name\":\"Fabian Piau\",\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/#\\\/schema\\\/person\\\/c5cbffd7cf0b10117877f5dfd1b35f14\"},\"headline\":\"Tips to make your WordPress website secure\",\"datePublished\":\"2018-10-10T17:43:41+00:00\",\"dateModified\":\"2021-01-14T16:35:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/fr\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/\"},\"wordCount\":1667,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/#\\\/schema\\\/person\\\/c5cbffd7cf0b10117877f5dfd1b35f14\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/fr\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/blog.fabianpiau.com\\\/wp-content\\\/uploads\\\/2018\\\/10\\\/wordpress-hacker.png?fit=300%2C300&ssl=1\",\"keywords\":[\"hacking\",\"hacker\",\"security\",\"wordpress\"],\"articleSection\":[\"Technology\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/blog.fabianpiau.com\\\/fr\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/\",\"url\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/\",\"name\":\"Tips to make your WordPress website secure | CarmaBlog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/fr\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/blog.fabianpiau.com\\\/wp-content\\\/uploads\\\/2018\\\/10\\\/wordpress-hacker.png?fit=300%2C300&ssl=1\",\"datePublished\":\"2018-10-10T17:43:41+00:00\",\"dateModified\":\"2021-01-14T16:35:19+00:00\",\"description\":\"&nbsp;English version available Mise \u00e0 jour 14 Janvier 2021 : Mise \u00e0 jour des security headers, remplacement de \\\"Feature-policy\\\" par \\\"Permissions-policy\\\".\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[[\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/\"]]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/blog.fabianpiau.com\\\/wp-content\\\/uploads\\\/2018\\\/10\\\/wordpress-hacker.png?fit=300%2C300&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/blog.fabianpiau.com\\\/wp-content\\\/uploads\\\/2018\\\/10\\\/wordpress-hacker.png?fit=300%2C300&ssl=1\",\"width\":300,\"height\":300,\"caption\":\"wordpress-hacker\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/2018\\\/10\\\/10\\\/tips-to-make-your-wordpress-website-secure\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Homepage\",\"item\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Technologie\",\"item\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/category\\\/technology\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Conseils pour s\u00e9curiser votre site WordPress\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/\",\"name\":\"CarmaBlog\",\"description\":\"Agility, Java programming, New technologies and more...\",\"publisher\":{\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/#\\\/schema\\\/person\\\/c5cbffd7cf0b10117877f5dfd1b35f14\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/blog.fabianpiau.com\\\/en\\\/#\\\/schema\\\/person\\\/c5cbffd7cf0b10117877f5dfd1b35f14\",\"name\":\"Fabian Piau\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/i0.wp.com\\\/blog.fabianpiau.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/fabian-pro-small.jpg?fit=567%2C667&ssl=1\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/blog.fabianpiau.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/fabian-pro-small.jpg?fit=567%2C667&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/blog.fabianpiau.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/fabian-pro-small.jpg?fit=567%2C667&ssl=1\",\"width\":567,\"height\":667,\"caption\":\"Fabian Piau\"},\"logo\":{\"@id\":\"https:\\\/\\\/i0.wp.com\\\/blog.fabianpiau.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/fabian-pro-small.jpg?fit=567%2C667&ssl=1\"},\"description\":\"Java developer, Fabian is interested in new technologies and their use within an Agile environment.\",\"sameAs\":[\"https:\\\/\\\/blog.fabianpiau.com\",\"https:\\\/\\\/www.facebook.com\\\/fabian.piau\",\"https:\\\/\\\/www.instagram.com\\\/fabianpiau\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/fabianpiau\\\/\",\"https:\\\/\\\/x.com\\\/fabianpiau\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Tips to make your WordPress website secure | CarmaBlog","description":"&nbsp;English version available Mise \u00e0 jour 14 Janvier 2021 : Mise \u00e0 jour des security headers, remplacement de \"Feature-policy\" par \"Permissions-policy\".","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/","og_locale":"en_US","og_type":"article","og_title":"Tips to make your WordPress website secure | CarmaBlog","og_description":"&nbsp;English version available Mise \u00e0 jour 14 Janvier 2021 : Mise \u00e0 jour des security headers, remplacement de \"Feature-policy\" par \"Permissions-policy\".","og_url":"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/","og_site_name":"CarmaBlog","article_publisher":"https:\/\/www.facebook.com\/fabian.piau","article_author":"https:\/\/www.facebook.com\/fabian.piau","article_published_time":"2018-10-10T17:43:41+00:00","article_modified_time":"2021-01-14T16:35:19+00:00","og_image":[{"width":300,"height":300,"url":"https:\/\/i1.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2018\/10\/wordpress-hacker.png?fit=300%2C300&ssl=1","type":"image\/png"}],"author":"Fabian Piau","twitter_card":"summary_large_image","twitter_creator":"@fabianpiau","twitter_site":"@fabianpiau","twitter_misc":{"Written by":"Fabian Piau","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.fabianpiau.com\/fr\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/#article","isPartOf":{"@id":"https:\/\/blog.fabianpiau.com\/fr\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/"},"author":{"name":"Fabian Piau","@id":"https:\/\/blog.fabianpiau.com\/#\/schema\/person\/c5cbffd7cf0b10117877f5dfd1b35f14"},"headline":"Tips to make your WordPress website secure","datePublished":"2018-10-10T17:43:41+00:00","dateModified":"2021-01-14T16:35:19+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.fabianpiau.com\/fr\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/"},"wordCount":1667,"commentCount":0,"publisher":{"@id":"https:\/\/blog.fabianpiau.com\/#\/schema\/person\/c5cbffd7cf0b10117877f5dfd1b35f14"},"image":{"@id":"https:\/\/blog.fabianpiau.com\/fr\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2018\/10\/wordpress-hacker.png?fit=300%2C300&ssl=1","keywords":["hacking","hacker","security","wordpress"],"articleSection":["Technology"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/blog.fabianpiau.com\/fr\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/","url":"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/","name":"Tips to make your WordPress website secure | CarmaBlog","isPartOf":{"@id":"https:\/\/blog.fabianpiau.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/#primaryimage"},"image":{"@id":"https:\/\/blog.fabianpiau.com\/fr\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2018\/10\/wordpress-hacker.png?fit=300%2C300&ssl=1","datePublished":"2018-10-10T17:43:41+00:00","dateModified":"2021-01-14T16:35:19+00:00","description":"&nbsp;English version available Mise \u00e0 jour 14 Janvier 2021 : Mise \u00e0 jour des security headers, remplacement de \"Feature-policy\" par \"Permissions-policy\".","breadcrumb":{"@id":"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":[["https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/"]]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/#primaryimage","url":"https:\/\/i0.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2018\/10\/wordpress-hacker.png?fit=300%2C300&ssl=1","contentUrl":"https:\/\/i0.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2018\/10\/wordpress-hacker.png?fit=300%2C300&ssl=1","width":300,"height":300,"caption":"wordpress-hacker"},{"@type":"BreadcrumbList","@id":"https:\/\/blog.fabianpiau.com\/en\/2018\/10\/10\/tips-to-make-your-wordpress-website-secure\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Homepage","item":"https:\/\/blog.fabianpiau.com\/en\/"},{"@type":"ListItem","position":2,"name":"Technologie","item":"https:\/\/blog.fabianpiau.com\/en\/category\/technology\/"},{"@type":"ListItem","position":3,"name":"Conseils pour s\u00e9curiser votre site WordPress"}]},{"@type":"WebSite","@id":"https:\/\/blog.fabianpiau.com\/en\/#website","url":"https:\/\/blog.fabianpiau.com\/en\/","name":"CarmaBlog","description":"Agility, Java programming, New technologies and more...","publisher":{"@id":"https:\/\/blog.fabianpiau.com\/en\/#\/schema\/person\/c5cbffd7cf0b10117877f5dfd1b35f14"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.fabianpiau.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/blog.fabianpiau.com\/en\/#\/schema\/person\/c5cbffd7cf0b10117877f5dfd1b35f14","name":"Fabian Piau","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/i0.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2022\/08\/fabian-pro-small.jpg?fit=567%2C667&ssl=1","url":"https:\/\/i0.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2022\/08\/fabian-pro-small.jpg?fit=567%2C667&ssl=1","contentUrl":"https:\/\/i0.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2022\/08\/fabian-pro-small.jpg?fit=567%2C667&ssl=1","width":567,"height":667,"caption":"Fabian Piau"},"logo":{"@id":"https:\/\/i0.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2022\/08\/fabian-pro-small.jpg?fit=567%2C667&ssl=1"},"description":"Java developer, Fabian is interested in new technologies and their use within an Agile environment.","sameAs":["https:\/\/blog.fabianpiau.com","https:\/\/www.facebook.com\/fabian.piau","https:\/\/www.instagram.com\/fabianpiau\/","https:\/\/www.linkedin.com\/in\/fabianpiau\/","https:\/\/x.com\/fabianpiau"]}]}},"views":2053,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blog.fabianpiau.com\/wp-content\/uploads\/2018\/10\/wordpress-hacker.png?fit=300%2C300&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbSHyl-1hL","_links":{"self":[{"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/posts\/4945","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/comments?post=4945"}],"version-history":[{"count":0,"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/posts\/4945\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/media\/4953"}],"wp:attachment":[{"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/media?parent=4945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/categories?post=4945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.fabianpiau.com\/en\/wp-json\/wp\/v2\/tags?post=4945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}