3 ms·
Yes. Put the Wordpress on a completely separate server so the WordPress instance is properly firewalled from your main application/database. But don't leave it
by daveslash 3y ago
Yes.
Put the Wordpress on a completely separate server so the WordPress instance is properly firewalled from your main application/database. But don't leave it on a subdomain -- set up a reverse proxy so you can route to a subdirectory on your main domain. Better SEO. I'm not an SEO hawk, but if the point of Wordpress is marketing, then it's important.
Edit: All good replies regarding cookies. Thank you for the correction. It is not "properly firewalled". The server side code is on a different machine, but this doesn't get you "proper firewall".
- chadd 3y agothis is dangerous because then a rogue piece of content in your wordpress instance can exfiltrate user cookies. subdomains are much safer, if worse for SEO.
- vermilingua 3y agoAnd then a malicious/compromised plugin has access to your primary sites cookies. I think that’d be worse for SEO.
- jansommer 3y agoCouldn't one set the path of cookies to be for your app? Then a malicious plugin shouldn't be able to read your apps cookies, since they won't be sent to Wordpress
- danielheath 3y agoMost web frameworks use encrypted cookie storage by now, right? Without the server key those cookies are useless.
- sznio 3y agoNot if someone takes the cookie and just passes it back to the app from their own browser to steal someone's authentication.
- hobobaggins 3y agoWarning, that's NOT "firewalled" from your main application/database. If it's just part of the path on the same domain, then almost any Wordpress security vulnerability can leak over into your main application (i.e., cookies, credential stuffing, xss, etc)
- acer4666 3y agoClient side web attacks don't affect how the two servers are firewalled from each other. I agree it isn't properly secure, but "firewall" refers to a specific type of security.
- hobobaggins 3y agoActually, network firewalls have nothing to do with website paths at all, but that is how the parent was using the term, so clearly they were thinking in terms of a more ambiguous term like sandboxing or isolation. Not looking to be pedantic, but by conflating the two terms, the parent was confusing both themselves and others -- and giving dangerously insecure advice.
- xp84 3y agoThe thing is, your real app doesn’t need any SEO. just your marketing site. That’s what they need to find (and if they’re customers they go for that Login button that takes them to the app). Marketing site on www Real app on app.example.com or similar
- gerdesj 3y agoYou can get your reverse proxy to hide /wp-admin/ from the outside world but still allow access from your trusted IPs or whatever. That will close off a few potential snags. You might also consider a full web application firewall (WAF) - there are plenty including WP internal solutions, commercial and open source. Me? I slap HA Proxy on the front. As you imply, I wouldn't bother fiddling with domain names - that is not a security solution and will bugger up the "message".