Rubenerd: The fewest enabled features security model (opens in new tab)
Calling this a security model is probably a stretch, but the first thing I do when installing any web-facing software is determine which features I can remove, disable, or otherwise make unavailable. I’ll review: Dependencies, to see if I can avoid installing any. For example, I don’t need XML-RPC packages if I never intend to use features that depend on them, and won’t ever have them enabled or exposed. Plugins, add-ons, extensions, and extra themes which are moved, then deleted when confirm...
Read the original article