So you’ve bitten the bullet and gone with WordPress for your Web Site system, good for you! I like it, and have been using it for many years (although I am not a zealot either, whatever system works just fine, if you are comfortable with it). One of the first security things you really should think about it is to change the Administrator account on your system. Why? Well if I look at Wordfence, to see who is trying to log into my system I see the following:
Hanoi, Vietnam attempted a failed login using an invalid username “admin”.
Let me assure you that none of these log in attempts are from me (given I am not in any of those countries), but do you see a trend here? They are all attempting to log in with the user name Admin and that is the first (and primary) attack vector for many of the hackers out there.
How to Remove Admin from WordPress ?
- Go to the Users Menu on your WordPress site
- Create a NEW userid, and call it what you wish (e.g. ThisIsNotAdmin ) that has Admin privileges, and give this user id a good password (not that crappy one you use for most sites)
- Log out of your Admin account, and try to log in with your new Admin UserID, make sure you can do all you want, and that it is really an Admin account (be really sure before you do the next step).
- From your new Admin userID, delete the Admin user id (maybe after you have done a full backup of your site just to be paranoid).
That is it, you have shut down the first attack vector for hackers, so your site is a little more secure (but don’t get cocky, there are many other ways into your site, this is just shutting off one of the easiest to attack).