How to Choose a Secure Admin Username for Wordpress Website Beginners Guide

Поділитися
Вставка
  • Опубліковано 19 жов 2024
  • During install the WordPress suggests to use "admin" username as a default administrator user. Most part of WordPress sites have this username. WordPress does not limit number of login attempts. So many WordPress sites are attacked by brute-forcing the password for "admin" user. For example, my site is attacked about 2-3 times each week.
    Solutions:
    do not use "admin" user;
    install Limit Login Attempts plugin;
    using captcha on login page;
    It would be better if WordPress will limit number of login attempts or at least does not suggest "admin" username by default.
    I don't remember if this was in the latest version or a few versions before, but I remember you could choose the username during installation (and a password of course).
    However, this does not solve the other issue. The default/first user has an ID of 1 in the database. This opens the door for a lot of XSS attacks if a vulnerability occurs. It is always that you create a new admin user with a different username immediately after installation, login with it and delete the first admin. You are given the option to assign the current content (the Hello World post, the default page and the default comment) to the new admin, which I personally just choose to delete.
    Limiting login attempts by default is not a good idea since a lot of users with non-technical knowledge may experience issues if they fail to login for a given amount of attempts.

КОМЕНТАРІ •