SiteGround Security Configuration Guide
System Sections

SiteGround Security Guide
Practical WordPress Hardening and Administrative Security
SiteGround Security provides login protection, WordPress hardening, and administrative security controls that help reduce unnecessary exposure within a WordPress installation. The primary reasons I use SiteGround Security include:
- login URL hardening
- two-factor authentication
- username protection
- XML-RPC protection
- administrative hardening
- environment security controls
While Wordfence handles firewall protection, malware scanning, and monitoring, SiteGround Security focuses primarily on environment-level hardening and administrative access controls. As a result, the two tools complement one another rather than serving the same role within the security stack.
The settings documented throughout this article reflect the current configuration used on this website. Furthermore, they form part of a broader layered security architecture designed to reduce unnecessary exposure while maintaining long-term operational simplicity.

Site Security Settings
SiteGround Security Hardening Settings

The following hardening features are currently enabled on this website.
The following hardening features are currently enabled on this website.
Lock and Protect System Folders
- This setting helps prevent malicious script execution within protected WordPress directories and reduces unnecessary exposure within the file system.
Hide WordPress Version
- This setting removes WordPress version information from public output where possible. As a result, visitors and automated scanners receive less information about the underlying installation.
Themes & Plugins Editor (Disable)
- This setting prevents code changes from being made through the WordPress administration panel. Consequently, an attacker who gains administrative access cannot immediately modify theme or plugin files from within the dashboard.
XML-RPC (Disable)
- XML-RPC functionality remains disabled on this website. For most modern WordPress installations, this feature is unnecessary and can introduce additional attack surface.
RSS and ATOM Feeds (Disable)
- Disabled.
- While SiteGround recommends disabling feeds, this website currently leaves RSS and ATOM feeds enabled to preserve native WordPress functionality and avoid unnecessary restrictions.
Advanced XSS Protection
- This setting provides additional protection against certain cross-site scripting scenarios. Furthermore, it forms part of the broader hardening strategy used throughout the website.
Delete the Default Readme.html
- The default
readme.htmlfile is removed because it can expose unnecessary information about a WordPress installation. Although the security benefit is relatively small, removing unnecessary files helps maintain a cleaner environment.

Login Security Settings
SiteGround Security Login Settings

The following login security features are currently enabled on this website:
Custom Login URL
- This setting replaces the default WordPress login URL with a custom endpoint. As a result, the website receives fewer automated login scans and brute-force attempts targeting common WordPress login locations.
Two-Factor Authentication
- Two-factor authentication requires an additional verification step beyond a username and password. Consequently, administrative accounts remain better protected even if login credentials become compromised.
Disable Common Usernames
- This setting prevents the use of commonly targeted usernames such as “admin.” Furthermore, it removes one of the most frequently targeted variables used during automated login attacks.
Login Access Restrictions
- Disabled.
- While IP-based restrictions can provide additional security, they can also create operational challenges when IP addresses change or when administrators travel between networks. As a result, this feature remains disabled on this website.
Limit Login Attempts
- Disabled.
- Wordfence currently manages brute-force protection, login monitoring, and lockout management. Therefore, this feature remains disabled to avoid overlapping functionality and simplify troubleshooting.

Security Through Simplicity
WordPress Security Made Simple
One of the most common mistakes in WordPress security is enabling every available security feature without considering operational complexity.
The approach used throughout this website focuses on maintaining a sensible security baseline while avoiding unnecessary overlap between tools.
For example:
- SiteGround Security manages login hardening and environment-level security controls.
- Wordfence manages firewall protection, brute-force mitigation, malware scanning, and monitoring.
- Security Headers provide browser-level hardening and exposure reduction.
- All In One Security provides additional account, login, and administrative security controls where appropriate.
Each layer serves a specific purpose within the broader security architecture. As a result, the security stack remains easier to maintain while reducing configuration conflicts and simplifying troubleshooting.

Concluding Thoughts
Final Notes on SiteGround Security
SiteGround Security provides a practical collection of WordPress hardening and administrative security controls that help reduce unnecessary exposure within a WordPress installation.
Its primary role within this website’s security architecture is not firewall protection or malware scanning. Instead, it focuses on login security, environment hardening, and administrative protection.
The configuration documented throughout this article reflects the settings currently used on this website. Although individual settings may evolve over time, the overall approach remains consistent:
Maintain a sensible baseline, avoid unnecessary complexity, and focus on long-term maintainability rather than aggressive security tuning.
Ultimately, effective WordPress security comes from multiple layers working together rather than relying on any single plugin or configuration.
Project Disclaimer
WordPress Security Disclaimer
The information provided throughout this page reflects the security tools, configurations, and operational practices currently used across my WordPress websites.
This content is shared for educational and documentation purposes only and should not be interpreted as a guarantee of security or protection against vulnerabilities, attacks, data loss, service interruptions, or infrastructure failures.
Website security depends on many factors, including hosting, server configuration, software updates, access control, operational maintenance, and user behaviour. Therefore, no individual plugin, configuration, or security measure can provide complete protection.
The settings and recommendations discussed throughout this page should be evaluated and adapted based on the specific requirements of each website, hosting environment, and operational workflow.
As with all systems documented on this website, the tools, configurations, and processes described here may evolve as infrastructure, requirements, and operational practices change.
Share This Article
Disciplined Maintenance.
