fplanzer

htaccess wordpress completo

Nov 29th, 2017
261
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.18 KB | None | 0 0
  1. #https://premium.wpmudev.org/blog/htaccess/
  2.  
  3. 1.- En .htaccess de la raiz del sitio
  4.  
  5. #Evitar el listado de directorios
  6. #Options All -Indexes
  7.  
  8. #Evitar llamadas a wp-includes
  9. #wp-includes NO debe recibir llamaras directas, es el CORE del Framework
  10. RewriteEngine On
  11. RewriteBase /
  12. RewriteRule ^wp-admin/includes/ - [F,L]
  13. RewriteRule !^wp-includes/ - [S=3]
  14. RewriteRule ^wp-includes/[^/]+\.php$ - [F,L]
  15. RewriteRule ^wp-includes/js/tinymce/langs/.+\.php - [F,L]
  16. RewriteRule ^wp-includes/theme-compat/ - [F,L]
  17.  
  18. #Evitar llamadas a URL php en pluggins
  19. #RewriteCond %{REQUEST_URI} !^/wp-content/plugins/file/to/exclude\.php
  20. #RewriteCond %{REQUEST_URI} !^/wp-content/plugins/directory/to/exclude/
  21. RewriteRule wp-content/plugins/(.*\.php)$ - [R=404,L]
  22.  
  23. #Evitar llamadas a URL php en themes
  24. #RewriteCond %{REQUEST_URI} !^/wp-content/themes/file/to/exclude\.php
  25. #RewriteCond %{REQUEST_URI} !^/wp-content/themes/directory/to/exclude/
  26. RewriteRule wp-content/themes/(.*\.php)$ - [R=404,L]
  27.  
  28. #Prevenir scan de usuarios del sistema
  29. RewriteCond %{QUERY_STRING} author=d
  30. RewriteRule ^ /? [L,R=301]
  31.  
  32. #Proteger los archivos .htaccess de llamadas
  33. # Deny access to all .htaccess files
  34. <files ~ "^.*\.([Hh][Tt][Aa])">
  35. order allow,deny
  36. deny from all
  37. satisfy all
  38. </files>
  39.  
  40. #Proteger llamadas a wp-config
  41. <files wp-config.php>
  42. order allow,deny
  43. deny from all
  44. </files>
  45.  
  46. #Habilitar el cache del browser del cliente
  47. <IfModule mod_expires.c>
  48. ExpiresActive On
  49. ExpiresByType image/jpg "access 1 year"
  50. ExpiresByType image/jpeg "access 1 year"
  51. ExpiresByType image/gif "access 1 year"
  52. ExpiresByType image/png "access 1 year"
  53. ExpiresByType text/css "access 1 month"
  54. ExpiresByType application/pdf "access 1 month"
  55. ExpiresByType text/x-javascript "access 1 month"
  56. ExpiresByType application/x-shockwave-flash "access 1 month"
  57. ExpiresByType image/x-icon "access 1 year"
  58. ExpiresDefault "access 2 days"
  59. </IfModule>
  60.  
  61. #DESDE AQUI AGREGAR LO QUE TRAE EL ORIGINAL DE WORDPRESS
  62.  
  63.  
  64.  
  65.  
  66.  
  67. 2.- en carpeta wp-content, crear .htaccess (incluye uploads)
  68.  
  69. # Permitir el llamado solo a archivos seguros
  70. Order deny,allow
  71. Deny from all
  72. <Files ~ ".(xml|css|js|jpe?g|png|gif|pdf|docx|rtf|odf|zip|rar)$">
  73. Allow from all
  74. </Files>
Advertisement
Add Comment
Please, Sign In to add comment