OneClick WordPress Security Check in iThemes Security

One-Click WordPress Security Check in iThemes Security

Written by

Kristen Wright
on

March 4, 2020

Last Updated On March 6, 2020

The latest version of iThemes Security Pro (6.4.2) & iThemes Security Free (7.6.1) includes a new “one-click” WordPress Security Check for your WordPress site. The Security Check feature is designed to help save you time and ensure your site is using the recommended security settings.

Features/Settings Enabled by Security Check

With just one click of the “Secure Site” button, iThemes Security will enable and configure all the recommended security features and settings within the plugin. This table lists out the feature/setting and the benefits activated by the Security Check.

Feature/Setting Benefit
Banned Users Blocks specific IP addresses and user agents from accessing your site
Database Backups Creates database backups manually or on a schedule
Local Brute Force Protection Protects your site against attackers that try to randomly guess login details to your site
Malware Scan Scheduling (Pro) Protects your site with automated malware scans. When this feature is enabled, your site will be automatically scanned each day
Network Brute Force Protection Protects your site against known attackers before they reach your site
Strong Passwords (Pro) Helps enforce that powerful (admin) accounts choose strong passwords for their logins
Two-Factor Authentication (Pro) Greatly increases the security of your WordPress user account by requiring additional information beyond your username and password in order to log in to the site
User Logging (Pro) Logs user actions such as login, editing or saving content and other actions into a viewable list
WordPress Tweaks This feature has a variety of settings that change the behavior of WordPress

By using the “Secure Site” button, the following settings actions will be taken (if they were not previously set):

  • Enable the Enable Ban Lists setting in Banned Users. This ensures that IPs being blocked by other features are not ignored due to the setting being disabled.
  • Enable the Email Notifications setting in Malware Scan Scheduling to ensure that site admins are notified of potential malware issues.
  • Enable the Time-Based One-Time Password (TOTP) provider for Two-Factor Authentication. When a user sets up their account to use TOTP authentication, they greatly increase the security of their account and make it near impossible for attackers to break into their account.
  • Enable the Email provider for Two-Factor Authentication. The email authentication option is a great alternative for users that cannot use Time-Based One-Time Password (TOTP) authentication.
  • Enable the Backup Verification Codes provider for Two-Factor Authentication. It is recommended that every user creates a set of backup verification codes to use in case they lose access to their Time-Based One-Time Password (TOTP) device or their email account.
  • Disable the File Editor in WordPress Tweaks as the file editor can be used by attackers to quickly add back doors or malware injection to existing files.
  • Change the Multiple Authentication Attempts per XML-RPC Request setting in WordPress Tweaks to “Block”. This prevents attackers from using XML-RPC requests to efficiently brute force user login credentials.
  • Enable the Write to Files setting in Global Settings. Since many features of iThemes Security require writing to wp-config.php and server config files, having this setting disabled prevents a large number of features from working properly.

Using the One-Click Security Check in iThemes Security

The new Security Check module should automatically display as soon as you update to the latest version of iThemes Security and visit the Security > Settings page. Simply click the “Secure Site” button to complete the security check.

security-check-for-wordpress

Security Check will then give you a status of all the settings/features enabled by the plugin.

WordPress-security-check-status

After you’ve used Security Check, you can review the settings again from the Security > Security Check page or from the iThemes Security Settings dashboard.

wordpress-security-settings

Update to iThemes Security Pro 2.5.0
& iThemes Security Free 5.6.0

Pro Customers: All current iThemes Security Pro customers will now find the 2.5.0 update available from the WordPress dashboard (for licensed sites) or as a manual download from the iThemes Member Panel. Save time updating all your sites at once from the iThemes Sync Dashboard.
Free Users: All iThemes Security users will now find the 5.6.0 update available from the WordPress dashboard or as a manual download from WordPress.org Plugin Directory. Save time updating all your sites at once from the iThemes Sync Dashboard.

Get iThemes Security Pro now

Keep reading the article at WordPress News and Updates from iThemes – iThemes. The article was originally written by Kristen Wright on 2020-03-04 12:02:58.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

Show Your ❤️ Love! Like Us
Scroll to Top