Hardening

WordPress ships with every feature enabled so that any kind of site can work: feeds, XML-RPC, pingbacks, public REST API, user listings, emoji scripts. A blog wants some of those. A membership site wants almost none of them, and each one it doesn't want is a door left open.

The Hardening module is a wall of toggles that close those doors, one at a time. There's no scanner, no definitions database, nothing to update. Each switch turns off a WordPress feature or adds a security header, and together they shrink the amount of your site an attacker can even see.

Everything is opt-in and reversible. Most toggles are safe on any membership site; a handful (marked in the admin as high impact) can break integrations, so they carry a short warning and an honest list of what they'll take down with them.

The settings are grouped the way attackers group them:

  • Login and authentication makes it harder to harvest usernames and brute-force passwords.
  • REST API controls decide how much of your site's data is reachable without logging in.
  • XML-RPC controls shut down WordPress's oldest remote-access back door, in steps.
  • Information disclosure removes the version numbers and links that fingerprint your site as WordPress.
  • Kill switches turn entire features off outright: comments, feeds, embeds, sitemaps.
  • Security headers tell browsers to enforce rules your server can't.
  • Admin cleanup removes distractions and buttons your editors should never see.

Start with the recommended baseline if you want the short version of what to enable today, or read what hardening means compared to a firewall before you begin.

Articles

Editors and the Admin Experience

Half of hardening isn't security at all. Update nags, dashboard widgets, heartbeat traffic, emoji scripts: remove the WordPress your team and members don't need to see.

Disrupting the Attacker's Workflow

Nobody hacks a site in one step. They enumerate, confirm, brute-force, and linger. Each login hardening toggle breaks one step of that chain.

Hardening vs a Firewall

Wordfence and Sucuri guard the doors you have. Torii's hardening removes doors you don't need. Different jobs, and they work fine together.

Where Paywalls Leak

Feeds, embeds, sitemaps, comments: four WordPress features built to spread your content around. On a membership site, each is a hole in the fence.

The Recommended Baseline

Enable these toggles today in one sitting. Safe on nearly every membership site, with no integrations at risk. The rest can wait until you've read their articles.

The REST API on a Membership Site

WordPress's public API can expose your content and your member list. Five toggles decide how locked down it should be, from gentle to airtight.

Security Headers

Five response headers that tell browsers to enforce rules your server can't. What each one does, and the one that turns a legacy protection off on purpose.

Erasing the WordPress Fingerprint

WordPress announces itself everywhere: generator tags, version strings, RSD links, shortlinks. Security by obscurity alone is weak, but as one layer it's free.

The wp-config Trio

Three constants in wp-config.php that no plugin can set for you: disable the file editor, lock down plugin installation, and force HTTPS on admin.

XML-RPC: The Legacy Back Door

A remote-control interface from WordPress's early days that almost nothing needs and bots constantly probe. Three escalations from gentle to total shutdown.