Perhaps in the future I’ll expand on the topics below, but for the sake of brevity and simplicity here are some easy to implement Wordpress security tricks.
- Delete the xmlrpc.php file from your server, or at the very least make sure its disabled (do that by going to Writing under Settings in the administration area). If you need the file (it’s require for desktop blogging tools) then at least rename the file to something unique.
- Disable user registration if you don’t require the functionality. Go to the General page under Settings and verify that “Anyone can register” is not checked.
- Rename your /wp-admin folder to something unique, and make sure there are no references to the renamed version in your robots.txt or .htaccess file.