The Recommended Baseline

The hardening screen has forty-three toggles. Most of them are safe on any membership site, a few will break things you might be using, and the module's Enable All button doesn't know which is which. This page is the list the button wishes it had: the set you can enable in one sitting, on nearly every membership site, with nothing at risk.

Enable all of these today

Login and authentication (the whole section):

  • Remove login error hints
  • Disable user enumeration
  • Disable REST user enumeration
  • Limit login attempts
  • Idle session timeout

One exception: Disable application passwords if you or anyone on the team uses the WordPress mobile app or an integration that authenticates with an app password. Otherwise include it.

Security headers (the whole section, all five). Browsers enforce them; no plugin or workflow notices they're there.

REST API, the three quiet ones:

  • Remove REST link from head
  • Remove REST link from headers
  • Block JSONP

XML-RPC, level one:

  • Remove X-Pingback header

Information disclosure:

  • Remove WP version from head
  • Remove WP version from feeds
  • Remove script/style versions
  • Remove RSD link
  • Remove WLW manifest link
  • Remove shortlink
  • Remove oEmbed discovery

Comments:

  • Disable pingbacks and trackbacks
  • Disable comments REST API

That's twenty-odd toggles, and the common thread is that they only remove things no member and no legitimate integration was using. Advertisements, leftovers, version numbers, and spam channels.

Enable after a five-minute check

These are safe for nearly everyone but deserve a glance:

  • Disable ?rest_route= requires pretty permalinks, which you almost certainly have. If your URLs contain index.php?, skip it.
  • Remove oEmbed JavaScript if you paste YouTube or tweet URLs into the editor and want them to keep auto-embedding. If your embeds are raw iframes or your own video features, enable it.
  • Disable emoji scripts and Throttle Heartbeat API are pure performance wins; enable both and never think about them again.
  • Disable REST API for guests on any conventional membership site where the theme renders pages and no external app consumes your API. If you run a headless frontend or a mobile app, read the REST API article first.

The ones to read before flipping

Everything with a high-impact warning exists in this module for a reason, but each has a specific blast radius:

  • Disable XML-RPC: breaks Jetpack and the WordPress mobile apps.
  • Disable application passwords: breaks app-password integrations.
  • Disable comments globally: hides existing comments, silences all comment flows.
  • Disable embeds: ends URL-paste embeds in the editor.
  • Disable feeds: breaks podcast and feed-reader distribution.
  • Disable XML sitemaps: removes core's SEO map (third-party SEO plugins keep their own).
  • Remove jQuery Migrate: can break old themes and plugins.
  • Disable autosave: your editors must save manually.

Most membership sites should end up enabling most of these eventually, feeds being the notable exception for podcasters. Read where paywalls leak for the reasoning, check the list against what your site actually uses, and flip them one at a time, verifying the site after each.

And the three constants

The strongest measures aren't toggles at all. Edit wp-config.php in the site root. WordPress marks the spot: paste the constants between the two anchor comments near the bottom of the file.

/* Add any custom values between this line and the "stop editing" line. */

define( 'DISALLOW_FILE_EDIT', true );
define( 'FORCE_SSL_ADMIN', true );
// define( 'DISALLOW_FILE_MODS', true );

/* That's all, stop editing! Happy publishing. */

Each takes effect on the next page load, and the hardening screen's status card flips to green as it finds them. The wp-config trio article walks through each.

After the first pass

Come back in a week and read what each article covers. You'll know your site better by then: which integrations you actually use, which pages complain in the console, whether anyone misses the admin bar. Hardening is reversible by design, so the baseline isn't a commitment; it's a starting configuration you adjust with evidence.