close

May 2024 only! Join our Discord free of charge.

Slick­Stack
Lightning-fast WordPress on Nginx

Do I really need security plugin for WordPress?

  • This topic is empty.
Viewing 8 posts - 1 through 8 (of 8 total)
  • Author
    Posts
  • #5106 Reply
    Margaret
    Guest

    I believe SlickStack has some security features although not sure what is the complete list. And if security plugin is still recommended for WordPress?

    #5107 Reply
    Ann
    Guest

    For example Wordfence or Sucuri? not sure if there are other good security plugin also?

    #5108 Reply
    Arthur
    Guest

    NO. Most likely you don’t need any bloated security plugin if you are using SlickStack.

    Even without SlickStack their usefulness is questionable. They don’t really stop malware infections per se if you’re using bad code.

    #5109 Reply
    Isabella
    Guest

    SlickStack has rate limiting built in already for wp-login.php and also blocks access to xmlrpc.php which protects you from DDOS and brute force login attacks.

    #5110 Reply
    Helen
    Guest

    so what security stuff does SlickStack NOT take care of???

    #5112 Reply
    Betty
    Guest

    Firstly define what you mean by “security plugin” because there are many plugins that improve security, not just Wordfence.

    The reason SlickStack doesn’t support Wordfence is because it hacks too many core files and doesn’t play nice with other software layers. For example it provides PHP-level rate limiting of wp-login.php but Nginx is much better for doing that.

    why SlickStack did not support WordFence plugin?

    There are other lightweight security plugins that SlickStack does support and are perhaps a good idea to use, like Disable REST API, etc.

    #5118 Reply
    Alexis
    Guest

    so what security stuff does SlickStack NOT take care of???

    SlickStack uses Nginx to do things like deny requests to certain risky URLs or rate-limit login attempts, but it doesn’t do much PHP-level security inside of WordPress like blocking certain types of malicious requests.

    So a good quality and lightweight security plugin you might use with SlickStack is Jeff’s BBQ firewall plugin maybe:

    BBQ Firewall – Fast & Powerful Firewall Security

    It doesn’t require hacking .htaccess, database, or wp-config.php (some of the reasons why Wordfence is blacklisted by SlickStack).

    #21404 Reply
    Judy
    Guest
Viewing 8 posts - 1 through 8 (of 8 total)
Reply To: Do I really need security plugin for WordPress?

Thanks to our generous sponsors for their support!