WordPress Security: blocking directory access

This is a very small security tip, but it’s worth the attention. I have been doing this for a while across all my Blogs. I’m also very curious and often try this myself if I want to see the plugins a specific site might be using, and it’s alarming just how many sites/blogs don’t do this, especially some of the larger blogs.

Directory Protection

When you install WordPress, it doesn’t block people browsing your directorys without indexes. This means if someone browses to; example.com/wp-content/plugins/ they will be able to see all the plugins you have installed. Same with example.com/wp-content/themes/ .

If you upload any zips, rars of any custom themes/plugins, anyone can potentially access and download them, as was the recent case with clazh.com whose template has sadly recently been leaked onto warez sites and forums.

Continue reading

WordPress 2.3.2

Just a quick update, WordPress 2.3.2 has been released, it’s an urgent bug fix, otherwise your draft posts could be exposed (we had over 40 drafts so we upgraded quick fast!). An added feature lets you customise the DB not found message which im sure alot of you have witnessed sometime or another. Place the custom template wp-content/db-error.php and it will appear instead of the default error message. We wouldn’t be suprised if someone creates a plugin to be able to customize it within the admin panel in the not to distant future. :)

Download
Upgrade Instructions

Fixed Bugs
Version Changes between 2.3.1 – 2.3.2

It won’t be long until 2.4 is out and we have to do it all again. Just make sure you have a full backup of all the files and the database before upgrading. This will save you alot of frustration in the event something goes wrong in the process.

Adii a WordPress Rockstar in the making

adii - freelancer, wordpress rockstar

As you know, we love WordPress and so does our Sponsor, WordPress freelancer Adii Pienaar who has come a long way in a short time. Adii a rising light in WordPress/blogging circles has developed an inspiring website packed with useful information and some great interviews, with amongst others, Mr WordPress himself Matt Mullenwag.

You can tell by Adii’s commitment and the quality of the content on his website that he’s a determined & focused person who is definitely going places. Adii’s blog, as well as being refreshingly honest, is an integral aspect of his long term business strategy and a promotional tool that helps to generate traffic and potential client’s to his site.

Adii has a particular penchant for creative and fresh business ideas and as well as his custom made WordPress themes, he is currently developing premium WordPress magazine style themes that you can check out here. The feedback on these new magazine style themes has been very positive and its not hard to see why. They are professional and sleek and definitely the way forward for WordPress bloggers and designers.

If your an aspiring WordPress Developer you wont go far wrong in following Adii’s personal blog, which reads as a time-line of his progress over the last 12 months.

http://adii.co.za/