{"id":24114,"date":"2022-01-05T06:22:42","date_gmt":"2022-01-05T06:22:42","guid":{"rendered":"https:\/\/www.designbombs.com\/?p=24114"},"modified":"2022-08-23T05:46:29","modified_gmt":"2022-08-23T05:46:29","slug":"wordpress-security","status":"publish","type":"post","link":"https:\/\/www.designbombs.com\/wordpress-security\/","title":{"rendered":"14 Ways to Secure Your WordPress Site &#8211; Step by Step"},"content":{"rendered":"<p>WordPress security should be a top priority for site owners. Why? Because there are up to 90,000 attacks on WordPress sites every minute.<\/p>\n<p>If that\u2019s not concerning enough, each week <a href=\"https:\/\/sucuri.net\/website-security\/website-hacked-report\">Google blacklists around 20,000 websites<\/a> for malware and 50,000 for phishing. And when a website is blacklisted \u2013 and users forced to agree to the risks \u2013 it results in a loss of around 95% of traffic.<\/p>\n<p>While the latest version of WordPress is always the most secure release available, there\u2019s more you can do to your site to ensure it\u2019s impenetrable to hackers and bots.<\/p>\n<p>Here are some best practice tips to help you secure your site.<\/p>\n<ol>\n<li><a href=\"#use-good-web-host\">Use a Good Web Host<\/a><\/li>\n<li><a href=\"#use-quality-themes-plugins\">Only Use Quality Themes and Plugins<\/a><\/li>\n<li><a href=\"#keep-core-up-to-date\">Keep WordPress Core, Themes, and Plugins Up-to-Date<\/a><\/li>\n<li><a href=\"#dont-use-admin-username\">Don&#8217;t Use &#8220;Admin&#8221; As a Username<\/a><\/li>\n<li><a href=\"#use-strong-password\">Use a Strong Password<\/a><\/li>\n<li><a href=\"#two-factor-authentication\">Use Two-Factor Authentication<\/a><\/li>\n<li><a href=\"#limit-login-attempts\">Limit Login Attempts<\/a><\/li>\n<li><a href=\"#install-ssl-certificate\">Install an SSL certificate<\/a><\/li>\n<li><a href=\"#change-database-prefix\">Change Database Prefix<\/a><\/li>\n<li><a href=\"#protecting-wpconfig\">Protecting wp-config.php and .htaccess Files<\/a><\/li>\n<li><a href=\"#add-security-keys\">Add Security Keys<\/a><\/li>\n<li><a href=\"#disable-file-editing\">Disable File Editing<\/a><\/li>\n<li><a href=\"#prevent-php-files-from-being-executed\">Prevent PHP Files from Being Executed<\/a><\/li>\n<li><a href=\"#disable-xml-rpc\">Disable XML-RPC Selectively<\/a><\/li>\n<\/ol>\n<h2 id=\"use-good-web-host\">1. Use a Good Web Host<\/h2>\n<p>A good web host is your first line of defense against attacks on your site. So don\u2019t automatically opt for cheap shared hosting. Instead, <a href=\"https:\/\/www.designbombs.com\/best-wordpress-hosting\/\">do your homework<\/a>.<\/p>\n<p>Go with a reputable host that supports the latest versions of basic web technologies, such as PHP and MySQL. Be sure to check your host supports PHP 7 \u2013 it is the<a href=\"https:\/\/wordpress.org\/about\/requirements\/\"> official recommended PHP version for WordPress<\/a>.<\/p>\n<p>Consider choosing a <a href=\"https:\/\/www.designbombs.com\/managed-wordpress-hosting\/\">managed WordPress host<\/a>. These services are set up specifically for WordPress and look after all the important technical aspects of hosting, including security, backups, uptime, and performance.<\/p>\n<h2 id=\"use-quality-themes-plugins\">2. Only Use Quality Themes and Plugins<\/h2>\n<p><a href=\"http:\/\/wpscan.org\/\">According to WPScan<\/a>, 52% of website vulnerabilities are caused by plugins while 11% are caused by themes. Combine, that\u2019s more than 60% of WordPress security<\/p>\n<p>The easiest way to ensure your <a href=\"https:\/\/www.designbombs.com\/best-wordpress-plugins\/\">plugins<\/a> and <a href=\"https:\/\/www.designbombs.com\/best-multi-purpose-wordpress-themes\/\">themes<\/a> can stand up to attacks is to only download them from reputable sources. This includes <a href=\"http:\/\/wordpress.org\">WordPress.org<\/a> and premium providers. Downloading from dodgy developers who hide malicious code in their themes and plugins could compromise your site.<\/p>\n<p>If you\u2019re not sure if a website you want to download from is safe, look for testimonials and reviews to ensure the product you want is of sound quality.<\/p>\n<p>Also, ensure any plugins and themes you use are also well-supported and regularly updated. If a plugin or theme hasn\u2019t been updated in a long time, chances are it contains security holes that are unpatched or even bad code that could leave you vulnerable to hacks.<\/p>\n<p>Lastly, only keep plugins and themes that you actually need and use. The more you have, the higher the risk of being hacked. So regularly review your list of plugins and themes and deactivate and delete any that you don\u2019t need.<\/p>\n<h2 id=\"keep-core-up-to-date\">3. Keep WordPress Core, Themes, and Plugins Up-to-Date<\/h2>\n<p>WordPress is open source software and developed and maintained by a worldwide community of volunteers. With each new release, any security vulnerabilities are patched.<\/p>\n<p>By default, WordPress automatically installs minor updates (i.e. WordPress 4.9.4). But for major releases (i.e. WordPress 4.9), the onus is on you to manually update to the latest version.<\/p>\n<div id=\"attachment_24116\" style=\"width: 810px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordpress-updates.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-24116\" class=\"wp-image-24116 size-full\" src=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordpress-updates.png\" alt=\"\" width=\"800\" height=\"280\" srcset=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordpress-updates.png 800w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordpress-updates-300x105.png 300w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordpress-updates-768x269.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><p id=\"caption-attachment-24116\" class=\"wp-caption-text\">Ensure your site is always running the latest version of WordPress.<\/p><\/div>\n<p>These core updates are critical for the security and performance of your site. So be sure to backup your site and apply any core updates when they become available.<\/p>\n<p>Likewise, it\u2019s also important to regularly update any plugins and themes so you\u2019re always using the most up-to-date and secure versions of software.<\/p>\n<h2 id=\"dont-use-admin-username\">4. Don&#8217;t Use &#8220;Admin&#8221; As a Username<\/h2>\n<p>Don\u2019t use \u201cadmin\u201d as the username for your site. Earlier versions of WordPress used \u201cadmin\u201d as the default username, making it easier for hackers \u2013 one less piece of the puzzle to guess during a brute force attack.<\/p>\n<p>But recent releases of WordPress changed this, giving users the opportunity to enter their own username during installation. However, some people still opt to use \u201cadmin\u201d rather than come up with an original username. Just don\u2019t.<\/p>\n<p>You want to make it harder for malicious attackers to penetrate your site, so attacks take longer and you or your hosting provider can identify any attacks before they are successful and stop them.<\/p>\n<h2 id=\"&quot;use-strong-password\">5. Use a Strong Password<\/h2>\n<p>Always create strong and unique passwords for your WordPress admin account, database, hosting account, email address and any FTP accounts. Like usernames, passwords are another piece of the puzzle for hackers to guess, and the stronger your password, the more difficult you make it for hackers to successfully login to your site.<\/p>\n<p>During installation, WordPress will try to force a strong password on you and ask you to check a box if you enter a weak one. While you might want to come up with your own password, tools like <a href=\"https:\/\/passwordsgenerator.net\/\">Secure Password Generator<\/a> can create a strong password for you.<\/p>\n<div id=\"attachment_24117\" style=\"width: 810px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-password-generator.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-24117\" class=\"wp-image-24117 size-full\" src=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-password-generator.png\" alt=\"\" width=\"800\" height=\"567\" srcset=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-password-generator.png 800w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-password-generator-300x213.png 300w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-password-generator-768x544.png 768w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-password-generator-84x60.png 84w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><p id=\"caption-attachment-24117\" class=\"wp-caption-text\">The Secure Password Generator lets you create unique and random passwords.<\/p><\/div>\n<h2 id=\"two-factor-authentication\">6. Use Two-Factor Authentication<\/h2>\n<p>Even with a strong username and password, brute force attacks are still a problem for many websites. This is where two-factor authentication can help.<\/p>\n<p>Two-factor authentication adds another step in the login process, forcing users to enter a code sent to their mobile phone in addition to entering their usual login credentials. This can thwart automatic attacks and ensure your site doesn\u2019t fall victim to hackers.<\/p>\n<p>Plugins like <a href=\"https:\/\/www.designbombs.com\/go\/ithemes-security\">iThemes Security<\/a> can implement two-factor authentication. There are also free plugins like <a href=\"https:\/\/wordpress.org\/plugins\/two-factor-authentication\/\">Two Factor Authentication<\/a> that can add this extra layer of security to your site.<\/p>\n<div id=\"attachment_24118\" style=\"width: 810px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/two-factor-authentication.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-24118\" class=\"wp-image-24118 size-full\" src=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/two-factor-authentication.png\" alt=\"\" width=\"800\" height=\"369\" srcset=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/two-factor-authentication.png 800w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/two-factor-authentication-300x138.png 300w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/two-factor-authentication-768x354.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><p id=\"caption-attachment-24118\" class=\"wp-caption-text\">The free Two Factor Authentication plugin lets you easily add another layer of protection when logging in to your site.<\/p><\/div>\n<h2 id=\"limit-login-attempts\">7. Limit Login Attempts<\/h2>\n<p>By default, you can attempt to login to your WordPress account as many times are you want. While this might be convenient for you if you\u2019re forgetful and don\u2019t always get your password right on the first or even third go, it\u2019s also convenient for hackers carrying out brute force attackers \u2013 it gives them an unlimited number of attempts to crack your username and password combination.<\/p>\n<p>This can be easily fixed by limiting the number of failed login attempts a user can make on your site. Free plugins like<a href=\"https:\/\/wordpress.org\/plugins\/wp-limit-login-attempts\/\"> WP Limit Login Attempts<\/a> let you limit login attempts and block IP addresses temporarily.<\/p>\n<h2 id=\"install-ssl-certificate\">8. Install an SSL Certificate<\/h2>\n<p>Installing an SSL certificate on your site is a must, especially if you have an eCommerce store. Not only because it will make it difficult for hackers to intercept sensitive information between user browsers and your server, but because Google now insists that all sites should have one.<\/p>\n<p>Starting in July 2018 with the release of Chrome 68, web pages that load without HTTPS will be marked as \u201cnot secure.\u201d This means that users who try to access sites that don\u2019t have an SSL certificate will get a warning that the site is untrustworthy.<\/p>\n<p>This announcement is a big deal because, according to Cloudflare, more than half of web visitors will see these warnings.<\/p>\n<div id=\"attachment_24119\" style=\"width: 810px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/lets-encrypt.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-24119\" class=\"wp-image-24119 size-full\" src=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/lets-encrypt.png\" alt=\"\" width=\"800\" height=\"586\" srcset=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/lets-encrypt.png 800w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/lets-encrypt-300x220.png 300w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/lets-encrypt-768x563.png 768w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/lets-encrypt-363x265.png 363w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><p id=\"caption-attachment-24119\" class=\"wp-caption-text\">Let&#8217;s Encrypt is a free certificate authority providing SSL certificates for site owners.<\/p><\/div>\n<p>Getting an SSL certificate is becoming more and more easier to do. <a href=\"https:\/\/www.wpkube.com\/lets-encrypt-free-ssl-wordpress\/\">Let\u2019s Encrypt offers free open source certificates<\/a> while hosting companies will generally provide one for a free (and sometimes even for free).<\/p>\n<h2 id=\"change-database-prefix\">9. Change Database Prefix<\/h2>\n<p>By default, WordPress uses wp_ as the prefix for all tables in your site\u2019s database. This means that if you\u2019re using the default \u2013 which is common WordPress knowledge \u2013 hackers can easily guess what your table name is, making it vulnerable for SQL injections.<\/p>\n<p>A simple way to fix this it to change the prefix to something random, like <code>5jiqtu69dg_<\/code> using a <a href=\"https:\/\/www.random.org\/\">random string generator<\/a>. In order to update your table\u2019s prefix, open the wp-config.php file in the root of your site\u2019s file directory and find this line:<\/p>\n<pre>$table_prefix \u00a0= 'wp_';<\/pre>\n<p>Using my example, you would replace the line like so:<\/p>\n<pre>$table_prefix \u00a0= '5jiqtu69dg_';<\/pre>\n<p>Next, you\u2019ll need to update the prefix used in your database. While security plugins like iThemes Security can help you do it quickly and easily, you can <a href=\"http:\/\/www.developerdrive.com\/2018\/03\/how-to-change-the-wordpress-database-prefix-to-improve-security\/\">learn how to do it manually via phpMyAdmin here<\/a>.<\/p>\n<h2 id=\"protecting-wpconfig\">10. Protecting wp-config.php and .htaccess Files<\/h2>\n<p>Your site\u2019s wp-config.php file, which is usually located in the root folder of your website, contains critical information about your WordPress installation, including the name, host, username and password for your database. Meanwhile, .htaccess is a hidden file that sets directory level server configuration, enables pretty permalinks, and allows for redirects.<\/p>\n<p>Preventing access to these critical files is easy. Simply add the following to your .htaccess file to protect wp-config.php:<\/p>\n<pre>&lt;Files wp-config.php&gt;\r\norder allow,deny\r\ndeny from all\r\n&lt;\/Files&gt;<\/pre>\n<p>Alternatively, you could simply move your wp-config.php file on directory higher as WordPress will <a href=\"https:\/\/wordpress.stackexchange.com\/questions\/58391\/is-moving-wp-config-outside-the-web-root-really-beneficial\">automatically look for it there<\/a>.<\/p>\n<p>To stop unwanted access to .htaccess, all you need to do is change the file name in the code:<\/p>\n<pre>&lt;Files .htaccess&gt;\r\norder\u00a0allow,deny\r\ndeny\u00a0from all\r\n&lt;\/Files&gt;<\/pre>\n<h2 id=\"add-security-keys\">11. Add Security Keys<\/h2>\n<p>WordPress security keys and salts encrypt information stored in browser cookies, protecting passwords and other sensitive information. There are four security keys in total: <code>AUTH_KEY<\/code>, <code>SECURE_AUTH_KEY<\/code>, <code>LOGGED_IN_KEY<\/code>, and <code>NONCE_KEY<\/code>.<\/p>\n<p>These authentication keys are basically a set of random variables and make it harder to crack your passwords. A non-encrypted password like \u201cwordpress\u201d doesn\u2019t take much effort for attackers to break. But a long and random password like \u201cL2(Bpw 6#:S.}tjSKYnrR~.Dys5c&gt;+&gt;2l2YMMSVWno4`!%wz^GOBf};uj*&gt;-tkye\u201d is much more difficult to crack.<\/p>\n<p>Adding security keys and salts is a manual process and easy to do. Here\u2019s how to do it:<\/p>\n<ol>\n<li>Get a new set of security keys and salts. You can randomly<a href=\"https:\/\/api.wordpress.org\/secret-key\/1.1\/salt\/\"> generate them here<\/a>.<\/li>\n<li>Next, update your wp-config.php file. Open your file and scroll down until you find the section below and replace the old values with your\u00a0new keys and salts:<\/li>\n<\/ol>\n<pre>\/**#@+\r\n * Authentication Unique Keys and Salts.\r\n *\r\n * Change these to different unique phrases!\r\n * You can generate these using the {@link https:\/\/api.wordpress.org\/secret-key\/1.1\/salt\/ WordPress.org secret-key service}\r\n * You can change these at any point in time to invalidate all existing cookies. This will force all users to have to log in again.\r\n *\r\n * @since 2.6.0\r\n *\/\r\ndefine('AUTH_KEY', 'add unique variables here');\r\ndefine('SECURE_AUTH_KEY', 'add unique variables here');\r\ndefine('LOGGED_IN_KEY', 'add unique variables here');\r\ndefine('NONCE_KEY', 'add unique variables here');\r\ndefine('AUTH_SALT', 'add unique variables here');\r\ndefine('SECURE_AUTH_SALT', 'add unique variables here');\r\ndefine('LOGGED_IN_SALT', 'add unique variables here');\r\ndefine('NONCE_SALT', 'add unique variables here');\r\n\r\n\/**#@-*\/<\/pre>\n<ol start=\"3\">\n<li>Save your wp-config.php file. You\u2019ll be automatically logged out of your WordPress site and will need to log in again.<\/li>\n<\/ol>\n<h2 id=\"disable-file-editing\">12. Disable File Editing<\/h2>\n<p>WordPress features an internal code editor for plugin and theme files. While this is useful for admins who want to make quick changes to files, it also means hackers and high-level users can also make file changes. You can find this feature by going to <b>Appearance &gt; Editor<\/b> in your WordPress admin.<\/p>\n<p>You can disable file editing in your wp-config.php file. Just open your file and add this line of code:<\/p>\n<pre>define('DISALLOW_FILE_EDIT', true);<\/pre>\n<p>You\u2019ll still be able to edit your plugins and themes via <a href=\"https:\/\/www.designbombs.com\/best-ftp-clients-for-mac-windows\/\">FTP<\/a> or <a href=\"https:\/\/www.designbombs.com\/beginners-guide-cpanel\/\">cPanel<\/a>, just not in the WordPress admin.<\/p>\n<h2 id=\"prevent-php-files-from-being-executed\">13. Prevent PHP Files from Being Executed<\/h2>\n<p>A common folder for hackers to upload malware in WordPress is <i>wp-content\/uploads, <\/i>but also <i>wp-includes\/<\/i>. To prevent files from being executed in these folders, create a new text file in a text editor and paste in this code:<\/p>\n<pre>&lt;Files *.php&gt;\r\ndeny\u00a0from all\r\n&lt;\/Files&gt;<\/pre>\n<p>Next, save this file as .htaccess and upload it to both your <i>\/wp-content\/uploads<\/i> and <i>wp-includes\/<\/i> folders via FTP or cPanel.<\/p>\n<h2 id=\"disable-xml-rpc\">14. Disable XML-RPC Selectively<\/h2>\n<p>XML-RPC, or XML Remote Procedure Call, is an API that helps connect web and mobile apps with your WordPress site. It was enabled by default in WordPress 3.5 but has since been found to<a href=\"https:\/\/blog.cloudflare.com\/a-look-at-the-new-wordpress-brute-force-amplification-attack\/\"> significantly amplify brute force attacks<\/a>.<\/p>\n<p>For example, if a hacker wanted to try 500 different passwords on your site, usually they would have to make 500 separate login attempts. But with XML-RPC, the hacker could use the <code>system.multicall<\/code> function to try a large number of username and passwords combinations in a single HTTP request.<\/p>\n<p>While it would be easy to simply disable this feature altogether for your site, it would mean losing functionality for plugins like Jetpack. Instead, it\u2019s best to selective in the way you implement and disable XML-RPC using <a href=\"https:\/\/wordpress.org\/plugins\/search\/disable+xml-rpc\">specially designed plugins<\/a>.<\/p>\n<h2>Bonus: How to Check for Vulnerabilities<\/h2>\n<p>There are a couple of different ways you can check your site for vulnerabilities: with an online site scanner or with a plugin.<\/p>\n<p>With these free online tools, all you need to do it enter your site\u2019s URL and they will start scanning your site for known vulnerabilities:<\/p>\n<p><a href=\"https:\/\/hackertarget.com\/wordpress-security-scan\/\"><b>WordPress Security Scan<\/b><\/a> \u2013 This tool passively checks for basic security issues. You\u2019ll need to upgrade to a premium plan for advanced testing.<\/p>\n<p><a href=\"https:\/\/sitecheck.sucuri.net\/\"><b>Sucuri SiteCheck<\/b><\/a> \u2013 Check your website for known malware, blacklisting status, website errors, and out-of-date software. With a premium upgrade, this tool will do malware cleanup, DDoS\/brute force protection, blacklist removal and security monitoring.<\/p>\n<p><a href=\"https:\/\/wpscan.org\/\"><b>WPScan<\/b><\/a> \u2013 This black box WordPress vulnerability scanner hosted at GitHub lets you scan your site for known vulnerabilities with core, plugins and themes. You\u2019ll need to use the Terminal to run this application. It\u2019s free for personal use and sponsored by Sucuri.<\/p>\n<h2>Bonus: Best WordPress Security Plugins<\/h2>\n<p>Installing a <a href=\"https:\/\/www.designbombs.com\/wordpress-security-plugins\/\">security plugin<\/a> on your WordPress site adds another line of defense against possible attacks. They offer a wide range of features to help secure your site \u2013\u00a0including site scans \u2013\u00a0and can notify you when your site has been compromised.<\/p>\n<p>Here are the top 3 plugins:<\/p>\n<h3><a href=\"https:\/\/wordpress.org\/plugins\/wordfence\/\">Wordfence<\/a><\/h3>\n<div id=\"attachment_24125\" style=\"width: 810px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordfence.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-24125\" class=\"wp-image-24125 size-full\" src=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordfence.png\" alt=\"\" width=\"800\" height=\"586\" srcset=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordfence.png 800w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordfence-300x220.png 300w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordfence-768x563.png 768w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/wordfence-363x265.png 363w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><p id=\"caption-attachment-24125\" class=\"wp-caption-text\">Wordfence security plugin.<\/p><\/div>\n<p>WordFence is a hugely popular free security plugin with 2+ million active installations and a premium option available. It features a \u201cThreat Defense Feed\u201d that pulls in the newest firewall rules, malware signatures and malicious IP addresses, keeping your website site.<\/p>\n<p>A web application firewall identifies and blocks malicious traffic, while a real-time IP blacklist blocks all requests from malicious IPs, protecting your site while reducing load.<\/p>\n<p>This plugin protects against brute force attacks by limiting login attempts, enforcing strong passwords, and other login security measures. If it finds any kind of infection in your site, it will notify you by email. You can also monitor the traffic to your site in real-time to check if it\u2019s under attack.<\/p>\n<h3><a href=\"https:\/\/wordpress.org\/plugins\/sucuri-scanner\/\">Sucuri<\/a><\/h3>\n<div id=\"attachment_24126\" style=\"width: 810px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/sucuri.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-24126\" class=\"wp-image-24126 size-full\" src=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/sucuri.png\" alt=\"\" width=\"800\" height=\"586\" srcset=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/sucuri.png 800w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/sucuri-300x220.png 300w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/sucuri-768x563.png 768w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/sucuri-363x265.png 363w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><p id=\"caption-attachment-24126\" class=\"wp-caption-text\">Sucuri security plugin.<\/p><\/div>\n<p>For a free security plugin, Sucuri\u2019s security plugin provides a comprehensive set of features, including security activity auditing so you can keep an eye on any changes made to your site, file integrity monitoring, remote malware scanning, blacklist monitoring, and security hardening measures.<\/p>\n<p>A \u201cpost-hack security actions\u201d section of the plugin walks you through the three key things you should do after a compromise. You can also enable security notifications so when an infection is found on your site or it\u2019s compromised, you\u2019ll be immediately alerted.<\/p>\n<p>When you upgrade to the premium version, you get access to a website firewall for added protection.<\/p>\n<h3><a href=\"https:\/\/wordpress.org\/plugins\/better-wp-security\/\">iThemes Security<\/a><\/h3>\n<div id=\"attachment_24127\" style=\"width: 810px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/ithemes.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-24127\" class=\"wp-image-24127 size-full\" src=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/ithemes.png\" alt=\"\" width=\"800\" height=\"578\" srcset=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/ithemes.png 800w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/ithemes-300x217.png 300w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/ithemes-768x555.png 768w, https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/ithemes-84x60.png 84w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><p id=\"caption-attachment-24127\" class=\"wp-caption-text\">iThemes Security plugin.<\/p><\/div>\n<p>While the free version of iThemes Security helps lock down WordPress, fix common holes and strengthen user credentials, the pro version features just about every security measure you could need.<\/p>\n<p>There\u2019s two-factor authentication, malware scan scheduling, and user action logging so you can track when users editor content, login or logout. You can update security keys and salts, set password expiration and add Google reCAPTCHA to your site.<\/p>\n<p>Other features include online file comparison, WP-CLI integration, and temporary privilege escalation so you can grant temporary admin or editor access to your site.<\/p>\n<h2>Conclusion<\/h2>\n<p>There\u2019s no right way to protect your WordPress site against security threats. The best you can do is keep WordPress core, themes and plugins up-to-date and implement a number of different solutions that patch vulnerabilities, protect critical files, and force users to strengthen their credentials.<\/p>\n<p><a href=\"https:\/\/www.designbombs.com\/best-backup-plugins-wordpress\/\">Scheduling regular backups<\/a> is also a must. You never know when your site might succumb to an attack, so it\u2019s important you\u2019re ready and have a plan in place for quickly restoring your site in case of an emergency.<\/p>\n<p>Investing in a solid security plugin that lets you scan your site for vulnerabilities, monitor actions, and alert you when something isn\u2019t right will also help harden your site and ensure it\u2019s well-protected against threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress security should be a top priority for site owners. Why? Because there are up to 90,000 attacks on WordPress&#8230;<\/p>\n","protected":false},"author":42,"featured_media":24166,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[157],"tags":[],"class_list":{"0":"post-24114","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-wordpress-tutorials","8":"entry"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v18.1 (Yoast SEO v26.4) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>WordPress Security (2020) - 14 Ways to Secure Your Website<\/title>\n<meta name=\"description\" content=\"WordPress security should be a top priority for site owners. Why? Because there are up to 90,000 attacks on WordPress sites every minute. Learn how to harden your site and prevent attacks in this comprehensive guide.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.designbombs.com\/wordpress-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"14 Ways to Secure Your WordPress Site - Step by Step\" \/>\n<meta property=\"og:description\" content=\"WordPress security should be a top priority for site owners. Why? Because there are up to 90,000 attacks on WordPress sites every minute. If that\u2019s not\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.designbombs.com\/wordpress-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Design Bombs\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/designbombs\/\" \/>\n<meta property=\"article:published_time\" content=\"2022-01-05T06:22:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-08-23T05:46:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"722\" \/>\n\t<meta property=\"og:image:height\" content=\"265\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Raelene Morey\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@designbombs\" \/>\n<meta name=\"twitter:site\" content=\"@designbombs\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Raelene Morey\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/\"},\"author\":{\"name\":\"Raelene Morey\",\"@id\":\"https:\/\/www.designbombs.com\/#\/schema\/person\/a9265b06816921c5aafbc1b46077ece8\"},\"headline\":\"14 Ways to Secure Your WordPress Site &#8211; Step by Step\",\"datePublished\":\"2022-01-05T06:22:42+00:00\",\"dateModified\":\"2022-08-23T05:46:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/\"},\"wordCount\":2654,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\/\/www.designbombs.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg\",\"articleSection\":[\"WordPress Tutorials\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.designbombs.com\/wordpress-security\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/\",\"url\":\"https:\/\/www.designbombs.com\/wordpress-security\/\",\"name\":\"WordPress Security (2020) - 14 Ways to Secure Your Website\",\"isPartOf\":{\"@id\":\"https:\/\/www.designbombs.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg\",\"datePublished\":\"2022-01-05T06:22:42+00:00\",\"dateModified\":\"2022-08-23T05:46:29+00:00\",\"description\":\"WordPress security should be a top priority for site owners. Why? Because there are up to 90,000 attacks on WordPress sites every minute. Learn how to harden your site and prevent attacks in this comprehensive guide.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.designbombs.com\/wordpress-security\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/#primaryimage\",\"url\":\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg\",\"contentUrl\":\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg\",\"width\":722,\"height\":265},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.designbombs.com\/wordpress-security\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.designbombs.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Tutorials\",\"item\":\"https:\/\/www.designbombs.com\/category\/tutorials\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"WordPress Tutorials\",\"item\":\"https:\/\/www.designbombs.com\/category\/tutorials\/wordpress-tutorials\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"14 Ways to Secure Your WordPress Site &#8211; Step by Step\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.designbombs.com\/#website\",\"url\":\"https:\/\/www.designbombs.com\/\",\"name\":\"Design Bombs\",\"description\":\"Droppin&#039; design bombs everyday!\",\"publisher\":{\"@id\":\"https:\/\/www.designbombs.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.designbombs.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.designbombs.com\/#organization\",\"name\":\"DesignBombs\",\"url\":\"https:\/\/www.designbombs.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.designbombs.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2019\/04\/db-logo.png\",\"contentUrl\":\"https:\/\/www.designbombs.com\/wp-content\/uploads\/2019\/04\/db-logo.png\",\"width\":219,\"height\":92,\"caption\":\"DesignBombs\"},\"image\":{\"@id\":\"https:\/\/www.designbombs.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/designbombs\/\",\"https:\/\/x.com\/designbombs\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.designbombs.com\/#\/schema\/person\/a9265b06816921c5aafbc1b46077ece8\",\"name\":\"Raelene Morey\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.designbombs.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/27dd7e3d488736cacab6c02b618782144f3b9b969299bc2065b2cacbc3fef0c2?s=96&d=https%3A%2F%2Fwww.designbombs.com%2Fwp-content%2Fthemes%2FDesignBombs%2Fimages%2Fgravatar.jpg&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/27dd7e3d488736cacab6c02b618782144f3b9b969299bc2065b2cacbc3fef0c2?s=96&d=https%3A%2F%2Fwww.designbombs.com%2Fwp-content%2Fthemes%2FDesignBombs%2Fimages%2Fgravatar.jpg&r=g\",\"caption\":\"Raelene Morey\"},\"description\":\"Raelene is the chief writer at DesignBombs. Formerly managing editor at WPMU DEV. Computer science grad turned newspaper journalist. When she\u2019s not taming browser tabs she likes brunching and bushwalking.\",\"sameAs\":[\"https:\/\/wordsbybirds.com\/\",\"https:\/\/x.com\/designbombs\"],\"url\":\"https:\/\/www.designbombs.com\/author\/rae\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"WordPress Security (2020) - 14 Ways to Secure Your Website","description":"WordPress security should be a top priority for site owners. Why? Because there are up to 90,000 attacks on WordPress sites every minute. Learn how to harden your site and prevent attacks in this comprehensive guide.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.designbombs.com\/wordpress-security\/","og_locale":"en_US","og_type":"article","og_title":"14 Ways to Secure Your WordPress Site - Step by Step","og_description":"WordPress security should be a top priority for site owners. Why? Because there are up to 90,000 attacks on WordPress sites every minute. If that\u2019s not","og_url":"https:\/\/www.designbombs.com\/wordpress-security\/","og_site_name":"Design Bombs","article_publisher":"https:\/\/www.facebook.com\/designbombs\/","article_published_time":"2022-01-05T06:22:42+00:00","article_modified_time":"2022-08-23T05:46:29+00:00","og_image":[{"width":722,"height":265,"url":"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg","type":"image\/jpeg"}],"author":"Raelene Morey","twitter_card":"summary_large_image","twitter_creator":"@designbombs","twitter_site":"@designbombs","twitter_misc":{"Written by":"Raelene Morey","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.designbombs.com\/wordpress-security\/#article","isPartOf":{"@id":"https:\/\/www.designbombs.com\/wordpress-security\/"},"author":{"name":"Raelene Morey","@id":"https:\/\/www.designbombs.com\/#\/schema\/person\/a9265b06816921c5aafbc1b46077ece8"},"headline":"14 Ways to Secure Your WordPress Site &#8211; Step by Step","datePublished":"2022-01-05T06:22:42+00:00","dateModified":"2022-08-23T05:46:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.designbombs.com\/wordpress-security\/"},"wordCount":2654,"commentCount":2,"publisher":{"@id":"https:\/\/www.designbombs.com\/#organization"},"image":{"@id":"https:\/\/www.designbombs.com\/wordpress-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg","articleSection":["WordPress Tutorials"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.designbombs.com\/wordpress-security\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.designbombs.com\/wordpress-security\/","url":"https:\/\/www.designbombs.com\/wordpress-security\/","name":"WordPress Security (2020) - 14 Ways to Secure Your Website","isPartOf":{"@id":"https:\/\/www.designbombs.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.designbombs.com\/wordpress-security\/#primaryimage"},"image":{"@id":"https:\/\/www.designbombs.com\/wordpress-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg","datePublished":"2022-01-05T06:22:42+00:00","dateModified":"2022-08-23T05:46:29+00:00","description":"WordPress security should be a top priority for site owners. Why? Because there are up to 90,000 attacks on WordPress sites every minute. Learn how to harden your site and prevent attacks in this comprehensive guide.","breadcrumb":{"@id":"https:\/\/www.designbombs.com\/wordpress-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.designbombs.com\/wordpress-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.designbombs.com\/wordpress-security\/#primaryimage","url":"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg","contentUrl":"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg","width":722,"height":265},{"@type":"BreadcrumbList","@id":"https:\/\/www.designbombs.com\/wordpress-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.designbombs.com\/"},{"@type":"ListItem","position":2,"name":"Tutorials","item":"https:\/\/www.designbombs.com\/category\/tutorials\/"},{"@type":"ListItem","position":3,"name":"WordPress Tutorials","item":"https:\/\/www.designbombs.com\/category\/tutorials\/wordpress-tutorials\/"},{"@type":"ListItem","position":4,"name":"14 Ways to Secure Your WordPress Site &#8211; Step by Step"}]},{"@type":"WebSite","@id":"https:\/\/www.designbombs.com\/#website","url":"https:\/\/www.designbombs.com\/","name":"Design Bombs","description":"Droppin&#039; design bombs everyday!","publisher":{"@id":"https:\/\/www.designbombs.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.designbombs.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.designbombs.com\/#organization","name":"DesignBombs","url":"https:\/\/www.designbombs.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.designbombs.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.designbombs.com\/wp-content\/uploads\/2019\/04\/db-logo.png","contentUrl":"https:\/\/www.designbombs.com\/wp-content\/uploads\/2019\/04\/db-logo.png","width":219,"height":92,"caption":"DesignBombs"},"image":{"@id":"https:\/\/www.designbombs.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/designbombs\/","https:\/\/x.com\/designbombs"]},{"@type":"Person","@id":"https:\/\/www.designbombs.com\/#\/schema\/person\/a9265b06816921c5aafbc1b46077ece8","name":"Raelene Morey","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.designbombs.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/27dd7e3d488736cacab6c02b618782144f3b9b969299bc2065b2cacbc3fef0c2?s=96&d=https%3A%2F%2Fwww.designbombs.com%2Fwp-content%2Fthemes%2FDesignBombs%2Fimages%2Fgravatar.jpg&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/27dd7e3d488736cacab6c02b618782144f3b9b969299bc2065b2cacbc3fef0c2?s=96&d=https%3A%2F%2Fwww.designbombs.com%2Fwp-content%2Fthemes%2FDesignBombs%2Fimages%2Fgravatar.jpg&r=g","caption":"Raelene Morey"},"description":"Raelene is the chief writer at DesignBombs. Formerly managing editor at WPMU DEV. Computer science grad turned newspaper journalist. When she\u2019s not taming browser tabs she likes brunching and bushwalking.","sameAs":["https:\/\/wordsbybirds.com\/","https:\/\/x.com\/designbombs"],"url":"https:\/\/www.designbombs.com\/author\/rae\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/www.designbombs.com\/wp-content\/uploads\/2018\/03\/secure-wp-site.jpg","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/posts\/24114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/users\/42"}],"replies":[{"embeddable":true,"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/comments?post=24114"}],"version-history":[{"count":3,"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/posts\/24114\/revisions"}],"predecessor-version":[{"id":29340,"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/posts\/24114\/revisions\/29340"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/media\/24166"}],"wp:attachment":[{"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/media?parent=24114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/categories?post=24114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.designbombs.com\/wp-json\/wp\/v2\/tags?post=24114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}