BradBlogging
Skip to content
  • About
  • Contact
  • Advertise
  • What Is R.S.S and Why Subscribe To Us?
  • Free Premium WordPress Themes
Tweet
Share
« Conducting an Experiment – Advertising And Guest Posts
How Simple Is Your Advertise Page? »

Weekend WordPress Security Tip: Index.html

Don’t want people knowing which plugins you have installed on your WordPress? Don’t want people knowing what version it is? If you haven’t done this fix yet for WordPress, I can go to http://yourblogurl.com/wp-content/plugins and see everything that you have installed and what version it is.

Not so good for security is it?

The Fix:

Make a blank file and save it as “index.html” and upload it to your plugins folder. Now the method above will just produce a blank page.

If your not code savvy – I’ve made one for you to achieve the same thing and can be downloaded here. (Right-Click and select “Save As”, Upload to your plugins folder, and your done)

Related posts:

  1. Weekend WordPress Security Tip: Restrict Your Wp-Admin
  2. Weekend WordPress Security Tip: What To Do When Your Blog Is H4CK3D
  3. Saturday Weekend Security Tip: Remove This Useless Tag
This entry was posted in Web Security and tagged Web Security. Bookmark the permalink. Post a comment or leave a trackback: Trackback URL.

Enjoy this post? Theres more to come, so click here to subscribe to our RSS Feed.

Loading...
« Conducting an Experiment – Advertising And Guest Posts
How Simple Is Your Advertise Page? »

11 Comments

  1. gadgets
    Posted August 16, 2008 at 5:20 pm | Permalink

    Great tip Brad, might I also recommend a redirect to the home page?

    gadgets’s last blog post..By: bobeatspizza

    Reply
  2. Blog for Beginners
    Posted August 16, 2008 at 11:48 pm | Permalink

    This is one of the tip that is often overlooked by many. It’s a nice gesture of you to share it here with your readers.@gadget: Care to show how to redirect it to home page? I’m pretty weak on this .htaccess thingy.Yan

    Blog for Beginners’s last blog post..Top 10 Blogging Tips of All Time

    Reply
  3. Peter Answers
    Posted August 17, 2008 at 4:18 pm | Permalink

    Oh my gosh, what a shock to see my plugin files like that! I am fixing it now, thanks@!

    Peter Answers’s last blog post..Why Doesn’t Peter Answer Me?

    Reply
  4. gadgets
    Posted August 18, 2008 at 4:06 pm | Permalink

    @Yan: You can either use an HTML meta refresh tag like so:

    >meta http-equiv=”refresh” content=”2;url=http://somesite.com”< (2 is the number of seconds before the refresh)or do a little php:

    header("Location: http://somesite.com");

    ?>

    best part is the php one is instant, I think there is a minimum of a 1 second delay with the meta tag.

    gadgets’s last blog post..Augmented reality comes to iPhone, ARToolkit

    Reply
  5. Wendy
    Posted August 21, 2008 at 2:56 pm | Permalink

    Hmm… I tried it with my blog and didn’t get anything except my error page (I think LOL)
    Interesting though
     

    Reply
  6. bradblog
    Posted August 22, 2008 at 3:52 pm | Permalink

    @ gadgets – Redirecting to the homepage would be a fine idea!

    @ Peter Answers – Yea, It is pretty pathetic of WordPress not to automatically install that on every new installation.

    @ gadgets – Thanks for your code wizardry :)

    @ Wendy – LoL! Are you sure you typed it in right??

    Reply
  7. Blog for Beginners
    Posted August 22, 2008 at 7:34 pm | Permalink

    Cool, thanks for the tip, Brad. I’m not aware of it. You know php and me don’t really get along well sometimes…Yan

    Blog for Beginners’s last blog post..20 Possible Ways to Optimize Your Blog

    Reply
  8. bradblog
    Posted August 23, 2008 at 4:20 am | Permalink

    Glad you liked it Yan. I plan on doing one today (Sat.)

    Reply
  9. Armand
    Posted August 24, 2008 at 6:11 am | Permalink

    This is a little security issue that almost missed.

    Armand’s last blog post..Google Adsense Website Temporarily Down

    Reply
  10. Armand
    Posted August 24, 2008 at 10:36 am | Permalink

    Hey, it could also be implemented into wp-content/themes and wp-content/uploads folder. Don’t you think to make a little privacy to those folders? I have visited several professional wp blogs and I could see their installed themes. That’s a funny thing, right :)

    Armand’s last blog post..Hiding Installed Plugins For Security Reason

    Reply
  11. Sire
    Posted May 16, 2009 at 9:47 pm | Permalink

    Man, I wish all fixes were that easy. I’ve done and tested in on wassublog and it worked a charm and so I will use it on my other blogs. Thanks brad.

    Reply

2 Trackbacks

  1. By Balkhis Sweet Monday Link Roundup - 08/18/08 on August 18, 2008 at 2:33 am

    [...] WordPress is a very secure platform. There are alot of other security steps you can take to make it even safer. Did you just miss the simplest one? [...]

  2. By Hiding Installed Plugins For Security Reason on August 24, 2008 at 8:01 am

    [...] see them all by accessing http://www.wpblogname.com/wp-content/plugins. There’s a nice tips I’ve just read and it’s very simple to [...]

Post a Comment

Click here to cancel reply.

Your email is never published nor shared. Required fields are marked *

*
*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

CommentLuv badgeShow more posts

2136 RSS Subscribers

Subscribe today to receive any updates on this blog for free!

You'll also receive, "The Blog Manual" free of charge for being a subscriber which you can download at the bottom of each post.

 


Hosted by EZP.net

You might notice how quick this site loads. This is because of EZP.net's awesome web hosting services, from quick support to premium hardware, this company is one notch above the rest. You should use EZP.net to host your sites... They care about their customers.

  • Popular Posts
  • Categories

Popular Articles

  • Optimize Repeated Web Backgrounds with Photoshop
  • 16 Jquery Slideshow Scripts You Cannot Miss
  • How to Create your Own 4 Column Blog Footer - HTML/CSS Included!
  • How To: Reduce Your Blog's Bounce Rate

Blog Categories

  • Advertising & Blogs
  • Article Readability
  • Asides
  • Blog Comments
  • Blog Design
  • Blog Loading Speed
  • Contemplation
  • Featured Posts
  • How To
  • Increase Readers
  • Increase Traffic
  • Interviews
  • Jquery Tools
  • Previous Contests
  • Tutorials
  • Unique Widgets
  • Web Security
  • Website Reviews
  • Wordpress Coding
  • Wordpress Templates

About The Author

Brad Ney

I am a Wordpress enthusiast, part-time website designer, and enjoy using the latest technology via the internet for website promotion. I enjoy writing about startup websites, XHTML, CSS, Wordpress based on what I've learned in the industry.

01. Subscribe!

Click the shiny button for the RSS Feed. This will allow you to recieve each update either via email or via your favourite RSS Reader.
Beats checking the site for new updates!

02. Hand-Picked Articles

  • The Following Mentality Of The Internet
  • Blog Comment Spam
  • Increase Audience Participation with Blog Polls
  • 9 Jquery Slideshow Applications You Cannot Miss

Spend some time reading BradBlogging's most famous blog articles.

03. Start a Blog!

Take advantage of all the information here by using the resources below to start your website:

1. Register A Domain Name

2. Top Notch Web Hosting

04. Contribute

Have a great idea for an article? Want something written about? Drop me a line!

Claim Your Free Blog Guide and Wordpress Template!

It's Brad Here and I just wanted to let you know that you are missing out on two free downloads I have for my readers. You can obtain these downloads for free by subscribing below - I promise that I will not spam and only send you updates from this blog.

Subscribe Today: