Plugins
- NinjaFirewall
- Cloudflare
- Connect using Cloudflare API token
- Child Theme Configurator
- Deactivate once you have created the child theme
Cloudflare settings
- Page rule
- Restrict access to wp-login*
- whitelist your home country
- whitelist IP address
- (advanced) Cloudflare Zero Trust
- Access
- Restrict access to wp-login.php
- Requires email code
- Requires specific email addresses
- (advanced) Security > WAF
- Rate limiting rules
- wp-login*
- Limit the time
e.g. 2 requests in 10 seconds
Housekeeping
- Delete built-in plugins
- Settings > Discussion
- Before a comment appears
- Comment must be manually approved