WORDPRESS SECURITY USING

ITHEMES SECURITY
JASON YINGLING | LEAD DEVELOPER
RED8 INTERACTIVE | RED8INTERACTIVE.COM
@JASON_YINGLING | JASONYINGLING.ME
Page
HHAM
Hosting
Hardening
Access
Maintenance
2
Page
WORDPRESS HOSTING
Support for latest software
Optimized for running WordPress
Malware scanning
Work with WordPress 24/7
Backups
3
Page
HARDENING
Protecting your site from common security
risks
• Don’t use the ‘admin’ username
• Strong passwords
• Hide the login area
• Brute Force Protection
• 404 Protection
• Malware scanning
4
Page
ACCESS
Minimize number of administrators
Remove file editing from dashboard
Two Factor Authentication
5
Page
MAINTENANCE
Keep WordPress up to date
Keep plugins up to date
Remove unused themes and plugins
6
PageProject Name
ITHEMES SECURITY
7
Page
ITHEMES LANDING PAGE
Broken down into high priority, medium
priority, and low priority
8
Page
GLOBAL SETTINGS
Write to wp-config.php
Emails for lockout notifications, file change
warnings, etc.
9
Page
GLOBAL SETTINGS
Error messages to
display to locked out
users
10
Page
GLOBAL SETTINGS
Enables blacklisting
repeat offenders
Good idea to switch
these up from the
defaults
11
Page
GLOBAL SETTINGS
Enables blacklisting repeat offenders
Good idea to switch these up from the
defaults
12
Page
404 DETECTION
Blocks attacker for scanning for known
vulnerabilities
13
Page
AWAY MODE
Allows for disabling
access to the dashboard
between certain hours
Do you really need to
be able to edit 24/7?
Taking a vacation
14
Page
BANNED USERS
Enable
HackRepair.com’s
blacklist feature
Enable Ban Users
Permanently bans
attackers IPs
15
Page
BRUTE FORCE PROTECTION
Limit the number of bad
login attempts before
temporarily locking out
the offending host
16
Page
BRUTE FORCE PROTECTION
Switch it up from the default
4 Max Login Attempts Per Host
9 Max Login Attempts Per User
6 Minutes to Remember Bad Login
17
Page
DATABASE BACKUPS
Sends a database backup via email or stores
on server
Plugins
• BackupBuddy
• BackWPUp
• WPmudev Snapshot
• VaultPress
18
Page
FILE CHANGE DETECTION
Allows you to include
and exclude specific
files that may change
often
Helpful to see what files
were changed if an
attack happens
19
Page
HIDE LOGIN AREA
Change login url
from /wp-admin to 

/something-else
Makes it difficult for
attacker to find login
area
Avoid using iThemes
default /wplogin
20
Page
SSL
Requires SSL setup on server
Allows you to force SSL for Dashboard
21
Page
STRONG PASSWORDS
Enables you to force strong passwords for
users for certain user roles
22
Page
SYSTEM TWEAKS
Some of this may be
performed by your host
Good idea to have on
unless you know
something conflicts on
your site
23
Page
WORDPRESS TWEAKS
24
Page
WORDPRESS TWEAKS
25
Page
WORDPRESS TWEAKS
26
Page
ADVANCED SETTINGS
Change name of ‘admin’ user
Change user with id of 1
27
Page
ADVANCED SETTINGS
Change WordPress salts
28
Page
ADVANCED SETTINGS
Change name of wp-
content directory
Not necessary on most
WP specific hosts
29
Page
ADVANCED SETTINGS
Change database prefix to make your tables
harder to find
30
Page
ITHEMES SECURITY PRO
Allow you to temporarily bump a users
access
31
Page
ITHEMES SECURITY PRO
More password options
Password generator on
user profile
Password expiration
Force password change
32
Page
ITHEMES SECURITY PRO
Use Google’s
reCAPTCHA for login,
registration, and
commenting
33
Page
ITHEMES SECURITY PRO
Allow users to setup
Two Factor
Authentication using
Google Authenticator
app
34
Page
ITHEMES SECURITY PRO
Log user activities at a certain role such as
login, saving content, and more
35
Page
LOCKED YOURSELF OUT?
Login to your database via phpMyAdmin or
a program like Sequel Pro
Navigate to the itsec_lockouts table
Delete the row with your IP
36
Page
LOCKED YOURSELF OUT?
Disable plugin via FTP
Navigate to /wp-content/plugins
Rename the ithemes-security plugin
directory
37
Page
QUESTIONS?
Jason Yingling | Red8 Interactive
@jason_yingling
http://jasonyingling.me
38

More Related Content

PDF
WordPress Security 101: Practical Techniques & Best Practices
PDF
Securing Your WordPress Website - WordCamp Sydney 2012
PDF
Make WordPress Fly With Virtual Server Hosting - WordCamp Sydney 2014
PPTX
Tips for Fixing a Hacked WordPress Site - WordCamp Sydney 2016
PPTX
An example of cms - wordpress
PDF
Webinar NETGEAR - Acronis e Netgear, una soluzione concreta per la virtualizz...
ODP
Securing Your Moodle
PDF
8 Ways to Hack a WordPress website
WordPress Security 101: Practical Techniques & Best Practices
Securing Your WordPress Website - WordCamp Sydney 2012
Make WordPress Fly With Virtual Server Hosting - WordCamp Sydney 2014
Tips for Fixing a Hacked WordPress Site - WordCamp Sydney 2016
An example of cms - wordpress
Webinar NETGEAR - Acronis e Netgear, una soluzione concreta per la virtualizz...
Securing Your Moodle
8 Ways to Hack a WordPress website

What's hot (20)

PDF
10 Steps to Secure Wordpress Sites
PDF
WordPress Security
PPTX
How to Secure your WordPress Website - WordCamp UK 2014
PDF
Wordpress CMS tutorial and guide manual
PPT
WordPress MU 101
PDF
Word camp2011 introwordpresssecurity
PPTX
Wordpress security issues
PDF
Webinar NETGEAR - Acronis e Netgear, una soluzione concreta per la Virtualizz...
PDF
moodle on wamp
PDF
Joomla! security jday2015
PPTX
Joomla! security jday2015
PPT
Installation of wordpress
PDF
Secure wordpress
ODP
CMS and security / privacy
PDF
Secure Wordpress - 2016[17May - Mashhad]
PDF
Top Ten WordPress Security Tips for 2012
PPTX
Content Management System(CMS) & Basic WordPress
PPTX
WordCamp Harare 2016 - Site Speed = Success
PDF
Browser security — ROOTS
PDF
Intro to Wordpress Security
10 Steps to Secure Wordpress Sites
WordPress Security
How to Secure your WordPress Website - WordCamp UK 2014
Wordpress CMS tutorial and guide manual
WordPress MU 101
Word camp2011 introwordpresssecurity
Wordpress security issues
Webinar NETGEAR - Acronis e Netgear, una soluzione concreta per la Virtualizz...
moodle on wamp
Joomla! security jday2015
Joomla! security jday2015
Installation of wordpress
Secure wordpress
CMS and security / privacy
Secure Wordpress - 2016[17May - Mashhad]
Top Ten WordPress Security Tips for 2012
Content Management System(CMS) & Basic WordPress
WordCamp Harare 2016 - Site Speed = Success
Browser security — ROOTS
Intro to Wordpress Security
Ad

Viewers also liked (20)

PDF
WordPress Does eCommerce
DOCX
Ensayo sobre word
PPTX
WordPress und SEO (WordPress Meetup Hamburg)
PDF
SEO Basics for WordPress
PPTX
Protect Your Brand
PPTX
Wordpress Ecommerce for Small Business Analysis
PPT
WordPress como ferramenta essencial para as PME
PPTX
Lady Blogger 2015 Conference
PDF
Performics ces recap_deck
PDF
North Lake Tahoe Tourism Summit - Email Marketing to Travelers
PDF
SEO – Technik, Struktur und Inhalt im Einklang
PDF
Landing Page Best Practices
ODP
Talk WordCamp Porto 2013
PDF
Performics CES Recap Deck
PPTX
WordCamp St. Louis 2014 WordPress for beginners by christoph trappe
PPTX
Themes that perform short: WordCamp Antwerp 2016
PPTX
Embracing Payment Technology to Attract New International Customers
PPTX
The Evolving Role of Product Content
PPTX
Creating Dynamic Sidebars & Widgets in WordPress
PPTX
(( Lucas lima )) Managing WordPress Projects - STL Meetup August 2015
WordPress Does eCommerce
Ensayo sobre word
WordPress und SEO (WordPress Meetup Hamburg)
SEO Basics for WordPress
Protect Your Brand
Wordpress Ecommerce for Small Business Analysis
WordPress como ferramenta essencial para as PME
Lady Blogger 2015 Conference
Performics ces recap_deck
North Lake Tahoe Tourism Summit - Email Marketing to Travelers
SEO – Technik, Struktur und Inhalt im Einklang
Landing Page Best Practices
Talk WordCamp Porto 2013
Performics CES Recap Deck
WordCamp St. Louis 2014 WordPress for beginners by christoph trappe
Themes that perform short: WordCamp Antwerp 2016
Embracing Payment Technology to Attract New International Customers
The Evolving Role of Product Content
Creating Dynamic Sidebars & Widgets in WordPress
(( Lucas lima )) Managing WordPress Projects - STL Meetup August 2015
Ad

Similar to Protect Your WordPress Website - Setting Up IThemes Security (20)

PPTX
Ithemes presentation
PPTX
WordPress Plugins and Security
PPTX
WordPress Security Updated - NYC Meetup 2009
PPT
WordPress Security - WordCamp NYC 2009
PPT
WordPress Security - WordCamp Boston 2010
PDF
ResellerClub Ctrl+F5 - WordPress Security session
PDF
WordPress Security is like a HHAM Sandwich
PDF
Types of Security Threats WordPress Websites Face: Part-1
PPTX
Protect Your WordPress From The Inside Out
KEY
Securing WordPress by Jeff Hoffman
PPTX
WordPress Security - WordPress Meetup Copenhagen 2013
PPT
WordPress Security
PPTX
Word press security
PPT
Now That's What I Call WordPress Security 2010
PDF
WordPress Security - 12 WordPress Security Fundamentals
PPTX
Security Function
PPT
Secure All The Things!
PPTX
WordPress End-User Security
PDF
Word press beirut 9th meetup march
PDF
WordCamp Mid-Atlantic WordPress Security
Ithemes presentation
WordPress Plugins and Security
WordPress Security Updated - NYC Meetup 2009
WordPress Security - WordCamp NYC 2009
WordPress Security - WordCamp Boston 2010
ResellerClub Ctrl+F5 - WordPress Security session
WordPress Security is like a HHAM Sandwich
Types of Security Threats WordPress Websites Face: Part-1
Protect Your WordPress From The Inside Out
Securing WordPress by Jeff Hoffman
WordPress Security - WordPress Meetup Copenhagen 2013
WordPress Security
Word press security
Now That's What I Call WordPress Security 2010
WordPress Security - 12 WordPress Security Fundamentals
Security Function
Secure All The Things!
WordPress End-User Security
Word press beirut 9th meetup march
WordCamp Mid-Atlantic WordPress Security

Recently uploaded (20)

PDF
What Makes a Great Data Visualization Consulting Service.pdf
PDF
MiniTool Power Data Recovery 12.6 Crack + Portable (Latest Version 2025)
PPTX
Swiggy API Scraping A Comprehensive Guide on Data Sets and Applications.pptx
PDF
IT Consulting Services to Secure Future Growth
PDF
Cloud Native Aachen Meetup - Aug 21, 2025
PPTX
A Spider Diagram, also known as a Radial Diagram or Mind Map.
PDF
MAGIX Sound Forge Pro CrackSerial Key Keygen
PPTX
Plex Media Server 1.28.2.6151 With Crac5 2022 Free .
PPTX
Lecture 5 Software Requirement Engineering
PPTX
Human Computer Interaction lecture Chapter 2.pptx
PDF
Sanket Mhaiskar Resume - Senior Software Engineer (Backend, AI)
PPTX
HackYourBrain__UtrechtJUG__11092025.pptx
PDF
Odoo Construction Management System by CandidRoot
PDF
Ragic Data Security Overview: Certifications, Compliance, and Network Safegua...
PPTX
Viber For Windows 25.7.1 Crack + Serial Keygen
PPTX
ESDS_SAP Application Cloud Offerings.pptx
PDF
Mobile App for Guard Tour and Reporting.pdf
PDF
Coding with GPT-5- What’s New in GPT 5 That Benefits Developers.pdf
PPT
3.Software Design for software engineering
PDF
infoteam HELLAS company profile 2025 presentation
What Makes a Great Data Visualization Consulting Service.pdf
MiniTool Power Data Recovery 12.6 Crack + Portable (Latest Version 2025)
Swiggy API Scraping A Comprehensive Guide on Data Sets and Applications.pptx
IT Consulting Services to Secure Future Growth
Cloud Native Aachen Meetup - Aug 21, 2025
A Spider Diagram, also known as a Radial Diagram or Mind Map.
MAGIX Sound Forge Pro CrackSerial Key Keygen
Plex Media Server 1.28.2.6151 With Crac5 2022 Free .
Lecture 5 Software Requirement Engineering
Human Computer Interaction lecture Chapter 2.pptx
Sanket Mhaiskar Resume - Senior Software Engineer (Backend, AI)
HackYourBrain__UtrechtJUG__11092025.pptx
Odoo Construction Management System by CandidRoot
Ragic Data Security Overview: Certifications, Compliance, and Network Safegua...
Viber For Windows 25.7.1 Crack + Serial Keygen
ESDS_SAP Application Cloud Offerings.pptx
Mobile App for Guard Tour and Reporting.pdf
Coding with GPT-5- What’s New in GPT 5 That Benefits Developers.pdf
3.Software Design for software engineering
infoteam HELLAS company profile 2025 presentation

Protect Your WordPress Website - Setting Up IThemes Security