How your servers are secured
The firewalls, updates, isolation and sign-in protection every server comes with.
2 min read Updated
Every server is hardened the moment it's built, and kept that way. Here's what protects your sites, layer by layer, and what you can do on top.
-
Ubuntu
-
OWASP
-
Let's Encrypt
The network
- Firewalls in front of the server. On DigitalOcean, Vultr, Hetzner and Rabbitflare Edge, a firewall at the cloud lets in only web traffic and the connection Rabbitflare uses; on the server itself, UFW does the same. Everything else is refused.
- Brute-force protection. fail2ban blocks addresses that keep failing to sign in to the server.
- Key-only sign-in. Servers we create don't accept SSH passwords; Rabbitflare's automation signs in with its own key, on its own port. (A server you connected yourself keeps however you sign in to it.)
The software
- Automatic security updates for Ubuntu are installed as they're released.
- WordPress minor releases, which carry WordPress's security fixes, install automatically.
- Free SSL on every domain: visitors' connections are encrypted, and certificates renew by themselves.
Each site
- Isolation. Each site runs as its own Linux user, with its own PHP process and its own database user, so one site can't read another's files or data, even on the same server.
- A web application firewall checks every request against the OWASP Core Rule Set and blocks attacks before they reach WordPress. New sites start protected. See Protect a site with the firewall.
- Login protection slows down password-guessing bots on
wp-login.php. - Limits, if you set them, stop one site from using up the server. See Site resources.
Your part
A few habits make a big difference:
- Keep plugins and themes up to date in WP Admin, and remove the ones you don't use.
- Use strong, unique passwords for every WordPress administrator, and avoid the username
admin. - Turn on site backups, so you can always go back.
- Try big updates on a staging copy first.