Our great sponsors
-
ModSecurity
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis. With over 10,000 deployments world-wide, ModSecurity is the most widely deployed WAF in existence.
-
InfluxDB
Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
I no longer use it actively but CraftCMS was good to me for several years: https://craftcms.com/
Is anyone on HN doing WordPress administration? I recently 'inherited' a webshop built on WP/WooCommerce, and all the conflicting security advice in the WP space is making my head spin.
There are a dozen competing 'security' plugins, with some saying 'you don't need any of them, WP is secure enough by default', and others saying 'you actually need ModSecurity [1] / Jeff Starr's nG firewall [2]'.
The agency that (shoddily...) built the webshop installed Wordfence Free [3], so I've just kept that for now, though I feel it's kind of slow (but that might just be caused by the bottom-of-barrel performance of the shared webhost it's currently running on).
[1] https://github.com/SpiderLabs/ModSecurity
Depending on the site, ask yourself "How dynamic does it actually have to be?". Perhaps using the GUI to update the content, and then creating static files and serving those may be an option: