Knowledgebase

After Installing: The First Ten Minutes Print

  • otherapplicationsscripts, other, email, https, smtp, ssl, backup, security, hacked, twofactor
  • 0

What to do before building anything.

SECURITY

Change any default administrator credentials Delete any default or sample account Delete the installation directory if one remains Set the configuration file to 600 permissions Enable two-factor authentication if available

CONFIGURATION

Set the site URL to the https version Set the correct timezone Set a working administrator email address Turn debug mode off

HOUSEKEEPING

Delete sample content Remove default themes and plugins you will not use Run AutoSSL and enable Force HTTPS

OPERATIONAL

Set up any cron job the application needs Configure backups Configure email sending through SMTP rather than the default

WHY NOW

Every one of these is harder after you have built the site and have content, users and traffic.

The default administrator account and the leftover install directory are the two that most often lead to a compromise.

RECORD IT

Note what you installed, the version, and any non-default configuration.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot