Improving the Security of the WordPress Admin User

11 minutes
Share the link to this page
Copied
  Completed
You need to have access to the item to view this lesson.
One-time Fee
$69.99
List Price:  $99.99
You save:  $30
€66.52
List Price:  €95.03
You save:  €28.51
£55.40
List Price:  £79.15
You save:  £23.74
CA$97.77
List Price:  CA$139.67
You save:  CA$41.90
A$107.48
List Price:  A$153.55
You save:  A$46.07
S$94.07
List Price:  S$134.39
You save:  S$40.32
HK$544.73
List Price:  HK$778.22
You save:  HK$233.49
CHF 61.85
List Price:  CHF 88.36
You save:  CHF 26.51
NOK kr773.61
List Price:  NOK kr1,105.21
You save:  NOK kr331.59
DKK kr496.19
List Price:  DKK kr708.87
You save:  DKK kr212.68
NZ$119.31
List Price:  NZ$170.45
You save:  NZ$51.14
د.إ257.07
List Price:  د.إ367.26
You save:  د.إ110.19
৳8,370.95
List Price:  ৳11,959.01
You save:  ৳3,588.06
₹5,916.42
List Price:  ₹8,452.40
You save:  ₹2,535.97
RM312.50
List Price:  RM446.45
You save:  RM133.95
₦117,624.49
List Price:  ₦168,042.19
You save:  ₦50,417.70
₨19,473.08
List Price:  ₨27,819.88
You save:  ₨8,346.79
฿2,426.48
List Price:  ฿3,466.55
You save:  ฿1,040.07
₺2,418.28
List Price:  ₺3,454.83
You save:  ₺1,036.55
B$406.67
List Price:  B$580.99
You save:  B$174.31
R1,268.60
List Price:  R1,812.36
You save:  R543.76
Лв130.09
List Price:  Лв185.85
You save:  Лв55.76
₩98,070.61
List Price:  ₩140,106.88
You save:  ₩42,036.26
₪261.37
List Price:  ₪373.41
You save:  ₪112.03
₱4,133.88
List Price:  ₱5,905.80
You save:  ₱1,771.92
¥10,806.63
List Price:  ¥15,438.71
You save:  ¥4,632.07
MX$1,423.91
List Price:  MX$2,034.25
You save:  MX$610.33
QR255.44
List Price:  QR364.93
You save:  QR109.49
P956.94
List Price:  P1,367.12
You save:  P410.17
KSh9,046.20
List Price:  KSh12,923.70
You save:  KSh3,877.50
E£3,475.04
List Price:  E£4,964.56
You save:  E£1,489.51
ብር8,733.50
List Price:  ብር12,476.97
You save:  ብር3,743.46
Kz63,853.79
List Price:  Kz91,223.61
You save:  Kz27,369.81
CLP$68,157.66
List Price:  CLP$97,372.26
You save:  CLP$29,214.60
CN¥506.84
List Price:  CN¥724.09
You save:  CN¥217.25
RD$4,224.90
List Price:  RD$6,035.83
You save:  RD$1,810.93
DA9,349.94
List Price:  DA13,357.64
You save:  DA4,007.69
FJ$158.89
List Price:  FJ$226.99
You save:  FJ$68.10
Q540.76
List Price:  Q772.55
You save:  Q231.78
GY$14,655.30
List Price:  GY$20,937.04
You save:  GY$6,281.74
ISK kr9,679.61
List Price:  ISK kr13,828.61
You save:  ISK kr4,149
DH699.78
List Price:  DH999.72
You save:  DH299.94
L1,274.52
List Price:  L1,820.82
You save:  L546.30
ден4,093.48
List Price:  ден5,848.08
You save:  ден1,754.59
MOP$561.60
List Price:  MOP$802.33
You save:  MOP$240.72
N$1,270.52
List Price:  N$1,815.10
You save:  N$544.58
C$2,577.69
List Price:  C$3,682.57
You save:  C$1,104.88
रु9,455.06
List Price:  रु13,507.81
You save:  रु4,052.75
S/265.82
List Price:  S/379.77
You save:  S/113.94
K281.99
List Price:  K402.86
You save:  K120.87
SAR262.75
List Price:  SAR375.38
You save:  SAR112.62
ZK1,938.58
List Price:  ZK2,769.51
You save:  ZK830.93
L331.04
List Price:  L472.94
You save:  L141.89
Kč1,685.42
List Price:  Kč2,407.85
You save:  Kč722.43
Ft27,354.11
List Price:  Ft39,078.98
You save:  Ft11,724.86
SEK kr771.99
List Price:  SEK kr1,102.90
You save:  SEK kr330.90
ARS$70,181.20
List Price:  ARS$100,263.16
You save:  ARS$30,081.95
Bs485.08
List Price:  Bs693
You save:  Bs207.92
COP$308,906.07
List Price:  COP$441,313.30
You save:  COP$132,407.23
₡35,572.52
List Price:  ₡50,820.06
You save:  ₡15,247.54
L1,770.13
List Price:  L2,528.86
You save:  L758.73
₲548,589.81
List Price:  ₲783,733.33
You save:  ₲235,143.51
$U2,994.50
List Price:  $U4,278.05
You save:  $U1,283.54
zł289.22
List Price:  zł413.19
You save:  zł123.97
Already have an account? Log In

Transcript

Hello, this is Rob coven. Here, I am going to offer you a few suggestions on how you can improve your admin user security. This is a very important part of WordPress security, somebody gets admin level access to the backend of your WordPress website, then that can be extremely damaging indeed. So let's go into the back end of WordPress by going WP admin and accessing it with your username and password. And that's exactly what we're talking about here. So we'll go into users.

Now in this particular case, we see we have one user and that is me and the role is administrator, you will always have at least one administrator, you may have other users. If you have other users, I would urge you to find out who they are by emailing them or asking whoever is responsible for the site and seeing if they are absolutely necessary to be there. It may be that somebody has created a new user, to a freelance developer to do some work on your website. This is particularly damaging, you really don't want to be creating extra users. They are extra areas that could be vulnerable. You want as few users as possible especially, you want to delete the users that you created for freelance developers, or people who are working with you for a short amount of time, even if they are going to work with you again, sometime in the future.

You can always create another user for them at that stage in the future. Just keep it simple, and have as few users as you need. Another important point that this users name, dog cherry, it shouldn't be admin, ad m i n that is The default username in WordPress. So everyone knows that when you set up a WordPress site that the administrators username is going to be admin ad, m i n, or five letters lowercase. So that gives Packers immediately more information that you want them to have. They know you're the username for the administrator, that's not very clever, you want to change it, as I have here to this name, dog, cherry, or any other name apart from administrator.

However, even this can be hard and further, and I'm going to show you how to do this. And in so doing, I'm going to show you what to do if you have the administrator username as admin, because I really would urge you to change that now. And the way you do it is by getting rid of the administrator of course, you can't get rid of the administrator and have no users at all. You have to create a new user with a new email address. As an administrator, and then you can delete the old one. But wait a minute, before you do that, I've got to show you how because it's very important that you do it in this way, so you don't lose any content that the original user had created.

Okay, so let's add a new user. So we go up here, users add new, or we could of course go here, users add new in the WordPress back end. Now username, course, remember, it's not going to be admin, it can be anything at all. And there it is. So you don't have to go crazy and make that a really hard to remember username, because the password is going to be really very strong, that the important thing is that it's very different from the word admin. And it's different from your name or something else that other people might be able to reverse engineer email address.

So the email address needs to be different from the current admin one has to be a different email address, first name, last name, always good to enter those. If you don't enter those, then the username is sometimes used on the site. And remember, we don't want people to know the username. That's the whole point of this is to not let people be able to guess the username. So we put in first name and last name there. And the website is completely up to you show password.

And here are incredibly strong passwords that WordPress will generate for you, I would recommend you use these passwords. They're fantastic. They're over 30 characters, and they include uppercase, lowercase letters, numbers and special characters. I would urge you to use that sort of strong password everywhere, especially in the cPanel FTP shell. Wh m, access all the other areas that are protected where you administer your website, not just WordPress. And in order to get hold of passwords like that, instead of making them out yourself, go to Google and Google password generator like that.

Click Search. And the first one there is called passwords generator dotnet. Click on that. And there you can generate a really secure password. Get a 30 character long one includes symbols, numbers, lowercase and uppercase characters and click Generate password. And there is a very strong password just like the one we're using here in WordPress.

Remember, copy the password and then use the name at this stage. And remember the role has to be administrator. So add a new user. There it is, and before course now we need to delete the original administrator. We can't do that. Now because we're logged in as the original administrator, we need to log out and log in as this administrator.

So we go, log outs. And there we've got the username and password that we just set up, log in. And now you'll see I saved that to my LastPass account. We'll go back to users here on the left hand side, and there they both are, but we remember we want to delete this one, the original one. So we delete and now this is really important. You have to attribute all content to the other.

The new admin, if you don't do this, you will lose content, confirm deletion. And there you go. If you didn't have an admin with a weak username and password Even if you have a strong username and password, it's a good security task to do this right now, it might be that you have the ID of the administrator as ID number one. So the only user you've ever had that, again, is a slight security vulnerability. So it's good to do this anyway, go back to the site, click on the blog, make sure the blog post written by that administrator or that user you've deleted still exists, because they still do, because we attributed all the content to the new user. Very important that we do that we've got all the blog and the site looking as it should do, as it did before we did this.

So that's good. So that is the most important aspect of user security on WordPress, having a user with a fairly hard username to remember it's not admin. Of course, and a very strong password updated fairly regularly and getting rid of other superfluous users from your site at whatever role they have, whether they're editors, authors, or subscribers, just get rid of them. You only want the people who are accessing the back end of the WordPress website regularly here on the user's screen. However, there is further hardening you can do to this user. And in order to do that, you need to go into the PHP admin section to edit the database.

Now, if you're not comfortable with this level of technical ability, then you're absolutely fine. You've done the most important thing. This is just another layer of security for you to consider doing and in this particular site, we have cPanel you may not be using cPanel on your sites, but you will have some sort of control panel. And it's more than likely, you'll have PHP myadmin to edit the databases. So you go into PHP myadmin. And you should find the database on the left hand side.

And you want to look for the table. That's called WP users. And there you see the user we just created. Look at the user ID, there is ID three. Remember, if you've created only one user, it's user ID number one, which is a slight security concern. And you want to click Edit by the admin username that you want to change.

And the value we're changing here is user underscore nice name. That is because it's the same as the user login name. We don't want to change that but we do want to change this one to something Else because this one is the one that can be seen through the code of the website. So we'll call that something completely different. Put the hackers off the scent. So we'll click go at the end here.

And there is that nice user name changed. Let's go back to the websites, click around discuss the blog. Let's go to back to the back end. There's the user. Still with that username. But the nice name has been changed on the database.

You can't see it here. But you can see it in some places in HTML. So I hope you enjoyed that. That's how to harden the admin user of your WordPress website to make that whole section area A very important area of the website more secure against possible malicious activity. My name is Rob carbon. I'll see you next Video

Sign Up

Share

Share with friends, get 20% off
Invite your friends to LearnDesk learning marketplace. For each purchase they make, you get 20% off (upto $10) on your next purchase.