D.K. Smith – WordPress Security Handbook: Facts & Fiction

Layer Nine: Security Plugins

Simple is better!  We believe giant multi-functional plugins are not the best approach to WordPress security.

For Annabelle... who should not have to deal with working, a baby, and spam too!  Try these...

IMHO, monitoring is not an effective method of securing WP... typically provides a false sense of being secure
  • "OOOPS, your site has been hacked... we'll fix it"
    • MUCH BETTER to keep hackers out in the first place
  • on-site monitors often generate lots of false positives
    • after a while site owners ignore all changes
  • some things change... many site owners don't know if file changes are okay or bad
  • okay to use monitoring if it's part of a comprehensive security plan