Hello. I’m pretty new here. I just managed to get my Raspberry Pi setup at home to selfhost a simple website that will act as my portfolio for some art I do.

I’m using WordPress to make the content of the website, meaning it runs on Apache, MariaDB and MySQL in the background. It’s connected via port 80 since I don’t want to pay for SSL certificates to setup https. There will be no accounts or transactions happening on my website. I don’t have anything to manage my dynamic IP but I’ll figure that out later. I’ve deleted the default Pi user on the RPi.

Are there security issues I should address preemptively? I’m worried for instance that I am exposing my home network, making it easier for someone to breach into whatever is connected there.

Any tips on making sure my setup is secure?

  • Rimu@piefed.social
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 month ago

    The WordFence plugin is a must-have for security.

    If you use Caddy instead of Apache then you get SSL automatically. You’ll need php-fpm as well, tho.

      • Rimu@piefed.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 month ago

        After X attempts to log in, it bans the IP address.

        It will scan your wordpress files and alert you if any of them have changed in suspicious ways (hacked).

        It can disable the xml-rpc endpoint which is rarely used and is a big vector for hacking.

        … and a lot more but those are the main ones for me.