{"repo":"drego85/htpw","free":true,"listed":false,"github":"https://github.com/drego85/htpw","clone":"git clone https://github.com/drego85/htpw.git","description":"htpw is a project to increase the security of your WordPress!","language":null,"stars":57,"topics":["wordpress","security","apache","htaccess"],"license":null,"category":"security-tools","readme_excerpt":"htpw - Htaccess To Protect WordPress htpw is a curated .htaccess ruleset for Apache that hardens a WordPress site without relying on plugins. The goal is to raise the baseline security posture with low overhead and minimal changes to WordPress itself. What this file does The htaccess ruleset focuses on common hardening measures: - Protects sensitive system files (e.g., wp-config.php , logs, backups). - Disables directory listing. - Adds modern security headers. - Blocks known malicious or scanning user agents. - Prevents PHP execution inside wp-content/uploads . - Restricts xmlrpc.php to trusted services (Jetpack and Akismet). Why use htpw WordPress is a frequent target. Security plugins can be effective, but they may add overhead or conflicts. htpw provides a lightweight alternative using Apache rules that: - Reduce the attack surface. - Require no PHP runtime or plugin. - Are easy to review, audit, and adjust. Installation 1. Download the htaccess file from this repository. 2. Append its contents to the bottom of your existing WordPress .htaccess . 3. Ensure your web server is Apache with mod rewrite and mod headers enabled. Note: These rules are not designed for NGINX. Security headers The file ships with a modern header set (HSTS, X-Frame-Options, X-Content-Type-Options, etc.). There is also a commented Content-Security-Policy (CSP) block that you can enable when ready. CSP can be strict and may require allowlisting external domains used by your theme or plugins. Compatib","default_branch":null,"files":null,"tree":[],"storefront":"/r/drego85","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/drego85/htpw/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}