Secure Setup
Enhance WordPress security by setting recommended file permissions, securing .htaccess, and disabling sensitive endpoints.
Plugin info
Maintenance & Compatibility
Maintenance score
Stale • Last updated 305 days ago
Is Secure Setup abandoned?
Likely maintained (last update 305 days ago).
Compatibility
Similar & Alternatives
Explore plugins with similar tags, and compare key metrics like downloads, ratings, updates, support, and WP/PHP compatibility.
Description
Securing Setup helps protect your WordPress installation by:
1. Allowing users to set recommended file permissions for directories and subdirectories.
2. Automatically modifying the .htaccess file to:
– Protect the debug.log file from being accessed via the web.
– Restrict execution of specific file types (e.g., .png, .jpg), ensuring only selected file types are processed by the web server.
3. Disabling sensitive WordPress endpoints such as:
– system.multicall from XML-RPC.
– The users endpoint in the REST API.
The plugin is user-friendly and includes an easy-to-access settings page.
You can view or contribute to the plugin’s source code on GitHub:
[GitHub Repository]https://github.com/deeprahman/sswp)
Features
- Set directory and subdirectory permissions for enhanced security.
- Automate
.htaccessfile modifications. - Disable potentially vulnerable endpoints.
- Tested with the latest version of WordPress.
Notes
After activation, the plugin adds a submenu named File Permission under the Tools menu, where you can configure settings.
Installation
- Upload the
securing-setupfolder to the/wp-content/plugins/directory. - Activate the plugin through the ‘Plugins’ menu in WordPress.
- Navigate to Tools > File Permission to configure settings.
Frequently Asked Questions
The plugin will recommend secure file permissions (e.g., 755 for directories and 644 for files) to reduce risks from unauthorized access.
Yes, the plugin provides options to revert changes made to the .htaccess file.
No, you can configure which file types are allowed for execution by the web server, ensuring normal functionality.
The plugin disables:
– The system.multicall function in XML-RPC to prevent potential attacks.
– The users endpoint in the REST API to hide user enumeration.
Review feed
Screenshots
Changelog
1.0.2
- Readme updated
1.0.1
- Added OS warning.
- Implemented REST API rate limiting.
1.0.0
- Initial release.
- File permissions management for directories and files.
.htaccesscustomization for secure file handling.- Disabled
system.multicallandusersREST endpoint for added protection.