Best practices to avoid attack on my MainWP installation

Hi team,

I have 20+ sites on my MainWP and a bit worried about something could fail on my Wordpress installation and an attacker get access into all sites through my panel.

Please, how could I protect it? I am thinking about adding a basic auth on it, or blocking IPs to only allow some IPs to connect on it, but I do not know how it impacts MainWP operation and connection to child sites. Any advise?

Thanks a lot and regards

You can of course apply security like on every other website. I’m using Wordfence Security including it’s 2FA.
The website is on a (sub)domain that’s only used for my dashboard, so don’t mix it with a public facing website or other tools on the same install.

There’s also the https://mainwp.com/add-on/dashboard-lock/ extension, that can help you with IP limitation and redirect the frontend of the site to your business site for example.

1 Like

Looks like Dashboard Lock will help me a lot, I am thinking about allowing only my VPN IP server into it :slight_smile:

2 Likes