Nginx config, PHP-FPM, MySQL hardening, Fail2Ban, UFW. Written for people who manage their own infrastructure.
Server hardening, SSH, UFW, Fail2Ban, PHP-FPM isolation
MySQL security, table prefix hardening, database user privileges
SSL configuration, security headers, Nginx rules
“Most WordPress security advice stops at the plugin layer. This book doesn't.”
From Chapter 2: WordPress Core Hardening
location ~* /(wp-config\.php|xmlrpc\.php|readme\.html|license\.txt) {
deny all;
return 404;
}
Stu is a WordPress administrator and hosting specialist with a long background in server management. That means Nginx configs, PHP-FPM pools, MySQL tuning, SSH hardening, firewall rules — the layer underneath WordPress that most WordPress security advice never touches.
The handbook is written for developers and sysadmins who run their own infrastructure and want to secure WordPress from the ground up rather than bolt security on top through plugins. Every chapter is rooted in real production experience, not theory.
Start with Chapter 1, it's free.
Read Chapter 1One payment, lifetime access to the handbook and every future update.
Buy Now — £19Secure payment via Stripe