ADMIN – A WordPress Security Risk


Why is ADMIN a WordPress Security Risk?

ADMIN - A WordPress Security Risk

We are filling out our blog with ideas from other WordPress Developers.  Lee is a developer and web maestro and tweeted out this message.  To use WordPress developers, the message is obvious, to those struggling with the beast themselves here is the message plain and simple terms:

Every installation of WordPress out of the box has an administrator account called admin.   Part of login in security is knowing both username and password.  If evil-doers have half the code to get in (admin) then they will just test the site with a tireless login hacker and if they get lucky.. wow an administrator account!

Lee’s problem appears to be that he went to a WordPress based site that was still using the admin username which had been locked out after too many attempts.  A frustrating situation that hampers that quick little job you were going to do, as it has now expanded to the task of remembering how to go into the SQL database and manually change the passwords.

One of the first things you should do after an install is get rid of username admin from your site.  Should be Job #1 or at least in your top 10.

 

Do you want to build something? build@fotunesrocks.me


13 responses to “ADMIN – A WordPress Security Risk”

  1. Hello there! This really is our primary review the following so i simply just desired to give you a fast shout out along with say My partner and i genuinely appreciate reading through your current content. Could you recommend any other blogs/websites/forums in which deal with the identical themes? Thank you!

Leave a Reply

Your email address will not be published. Required fields are marked *