Nginx config, PHP-FPM, MySQL hardening, Fail2Ban, UFW. Written for people who manage their own infrastructure.
Server hardening, SSH, UFW, Fail2Ban, PHP-FPM isolation
MySQL security, table prefix hardening, database user privileges
SSL configuration, security headers, Nginx rules
“Most WordPress security advice stops at the plugin layer. The interesting problems are underneath.”
From Chapter 2: WordPress Core Hardening
location ~* /(wp-config\.php|xmlrpc\.php|readme\.html|license\.txt) {
deny all;
return 404;
}
I've spent a long time managing the infrastructure underneath WordPress sites as well as the WordPress itself. Nginx configs, PHP-FPM pools, MySQL tuning, SSH and firewall rules, the layer most WordPress security advice never reaches.
The handbook is written for developers and sysadmins who run their own infrastructure and want to secure WordPress from the ground up. Every chapter is grounded in production setups I have actually run.
The security checks I'd run through on any WordPress site, delivered straight to your inbox.
All 13 chapters, kept up to date. Single payment, access for life.
Buy Protect My WP for £19Pay once. Keep access permanently, including all future updates.
Buy Now for £19Secure payment via Stripe