Skip to content

Security defaults

What Avaloi turns on for every WordPress site to keep it safe, why, and how to ask for a relaxation such as XML-RPC for Jetpack.

Every Avaloi site starts with the same security settings. You do not need a security plugin for any of them, and they are chosen so that WooCommerce, page builders such as Elementor and Divi, Jetpack, the block editor, and WP-CLI keep working. This page lists each setting, why it is there, and how to change it when a plugin needs something different.

WordPress settings

  • No file editor. The theme and plugin file editors in wp-admin are off on every environment. Edit code on staging, over SFTP, or in Git.
  • No code changes on live in Git mode. Live runs a read-only release, so wp-admin offers no plugin, theme, or core installs or updates there. Make the change on staging and promote it. See Environments.
  • Application passwords over HTTPS only. Integrations that sign in with an application password keep working, because every Avaloi site is served over HTTPS. WordPress refuses them over plain HTTP.

XML-RPC

XML-RPC (xmlrpc.php) is an old API that attackers use to guess passwords and to send pingback floods. Most sites no longer need it, so Avaloi turns it off: WordPress answers every XML-RPC call with an error and stops advertising pingbacks.

If Jetpack is active, XML-RPC stays on, because Jetpack needs it. Pingbacks stay off.

To choose for yourself, add the environment variable AVALOI_XMLRPC on the Info page (see Environment variables):

Value What it does
on XML-RPC works, for example for the WordPress mobile app or a publishing tool. Pingbacks stay off.
all XML-RPC and pingbacks both work.
off XML-RPC is off, even with Jetpack active.

Remove the variable to go back to the default.

Sign in limits

Avaloi limits how fast one address can send sign in attempts:

  • wp-login.php: 10 attempts a minute, with room for a burst of 20.
  • xmlrpc.php: 60 calls a minute, with room for a burst of 60.

Only form posts count. Opening the sign in page, signing out, and wp-admin pages are never limited. An address over the limit gets 429 Too Many Requests until it slows down. If a team signs in from one office address and hits the limit, contact support.

User names stay private

Attackers often list a site's user names before they guess passwords. For visitors who are not signed in, Avaloi:

  • answers /?author=1 and similar with "not found" instead of redirecting to the author's page. Author links such as /author/jane/ still work. Sites with plain permalinks keep ?author=, because that is their author link.
  • removes the /wp-json/wp/v2/users routes from the REST API. Signed in users and integrations that use an application password still get them, so the block editor works.
  • leaves the users sitemap out of /wp-sitemap.xml.
  • leaves the author's name out of oEmbed answers.

Files the web server never serves

The web server answers 404 Not Found for files that should never be public, wherever they sit in the site. A 404 does not tell a scanner that the file is special, and these requests add no lines to error.log:

  • dotfiles and folders such as .git, .svn, .env, and .htaccess (/.well-known/ still works)
  • copies of wp-config.php, such as wp-config.php.bak or wp-config-old.php
  • logs, database dumps, and editor leftovers: *.log (including wp-content/debug.log), *.sql, *.sql.gz, *.bak, *.old, *.orig, *.swp, and names ending in ~
  • build and tool files: composer.json, composer.lock, auth.json, package-lock.json, yarn.lock, avaloi.yml, wp-cli.yml, and error_log
  • archives in the top folder of the site, such as backup.zip, site.tar.gz, or site.wpress
  • backup plugin folders: wp-content/ai1wm-backups, wp-content/updraft, wp-content/backups-dup-lite, wp-content/backups-dup-pro, wp-content/wpvividbackups, and wp-content/uploads/backwpup-*
  • WooCommerce logs and downloadable product files in wp-content/uploads/wc-logs and wp-content/uploads/woocommerce_uploads
  • readme.html and license.txt, which show the WordPress version

wp-config.php itself sits one folder above the site, out of the web server's reach.

Download backups from your backup plugin's own screen, or over SFTP. For WooCommerce downloadable products, keep the download method on Force downloads. To share a file such as a zip, put it in the Media Library instead of the top folder.

Uploads never run PHP

A PHP file in wp-content/uploads is never run, on any environment. This stops the most common way a hacked plugin turns an upload into a back door.

Security headers

Every page carries three headers:

Header Value Why
X-Frame-Options SAMEORIGIN Other sites can not frame your pages to trick visitors into clicks.
X-Content-Type-Options nosniff Browsers do not guess file types, so an upload can not run as a script.
Referrer-Policy strict-origin-when-cross-origin Other sites see only your domain, not the full address a visitor came from.

WordPress post embeds, the Customizer, and page builder previews can still be framed. Avaloi adds no Content Security Policy, so embeds, payment forms, and page builders work as they do anywhere else.

PHP settings

For web requests, PHP runs with these settings:

  • No shell commands. exec, passthru, shell_exec, system, proc_open, popen, pcntl_exec, and pcntl_fork are off. WordPress does not use them, and backup and image plugins that try them fall back to PHP code. WP-CLI and cron jobs run PHP on the command line, which keeps them.
  • PHP stays inside the site. PHP can open files in your site folder, the temporary folder, the session folder, and the few Avaloi files it needs, such as the page cache and the object cache. It can not read the rest of the server.
  • No remote includes. PHP never includes code from a URL.
  • No version banner. PHP does not announce its version.
  • Safe session cookies. PHP session cookies are HttpOnly and Secure.

Ask for a relaxation

Most needs have a switch you can use yourself:

  • XML-RPC for Jetpack, the mobile app, or a publishing tool: set AVALOI_XMLRPC as described above.
  • PHP limits such as memory and upload size: see PHP settings.

For anything else, such as a plugin that needs exec to run a program on the server, or a page that another site must frame, contact support with the site name, the plugin, and what it needs. We turn the setting on for that site only.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.