{"repo":"igorhrcek/wp-cli-secure-command","free":true,"listed":false,"github":"https://github.com/igorhrcek/wp-cli-secure-command","clone":"git clone https://github.com/igorhrcek/wp-cli-secure-command.git","description":"Secure package for WP CLI, built to provide an easier way of securing your WordPress installation","language":"PHP","stars":95,"topics":["wordpress","security","hardening","nginx","apache","wp-cli","wp-cli-package"],"license":null,"category":"security-tools","readme_excerpt":"wp-cli/secure-command Official website: Hackthewp.com Manages common security aspects of WordPress. Supports nginx and Apache. Basic Usage This package implements the following commands: Deploy All Security rules Deploys all above-mentioned rules at once. Remove All Security Rules Removes all security rules. Add Security Headers Adds the HSTS, Referrer-Policy, X-Content-Type-Options and X-Frame-Options You can choose to add all above or only one or more by using --headers argument. Example: Block the access to sensitive files and directories By default, this command blocks the direct access to sensitive files and directories: readme.txt , readme.html , xmlrpc.php , wp-config.php , wp-admin/install.php , wp-admin/upgrade.php , .git , svn , cache and vendors Possible options are: - sensitive-files - sensitive-directories - xmlrpc - htaccess - custom - all (does all the above) Examples: However, you can also block custom files and/or folders of your choice. To do that you should use custom argument and pass one of two additional options --files and/or --directories . If you want to block custom files, make sure that you pass only file names, not a full file paths. Examples: Block Author Scanning Blocks author scanning. Author scanning is a common technique of brute force attacks on WordPress. It is used to crack passwords for the known usernames and to gather additional information about the WordPress itself. Examples: Block Direct Access and Execution in certain directories Blo","default_branch":null,"files":null,"tree":[],"storefront":"/r/igorhrcek","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/igorhrcek/wp-cli-secure-command/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}