make site faster
Enable gzip compression: Gzip compresses your website files before sending them to the user’s browser, which reduces the file size and makes your site load faster. Add the following code to your .htaccess file:
<IfModule mod_deflate.c>
# Compress HTML, CSS, JavaScript, Text, XML and fonts
AddOutputFilterByType DEFLATE application/javascript
AddOutputFilterByType DEFLATE application/rss+xml
AddOutputFilterByType DEFLATE application/vnd.ms-fontobject
AddOutputFilterByType DEFLATE application/x-font
AddOutputFilterByType DEFLATE application/x-font-opentype
AddOutputFilterByType DEFLATE application/x-font-otf
AddOutputFilterByType DEFLATE application/x-font-truetype
AddOutputFilterByType DEFLATE application/x-font-ttf
AddOutputFilterByType DEFLATE application/x-javascript
AddOutputFilterByType DEFLATE application/xhtml+xml
AddOutputFilterByType DEFLATE application/xml
AddOutputFilterByType DEFLATE font/opentype
AddOutputFilterByType DEFLATE font/otf
AddOutputFilterByType DEFLATE font/ttf
AddOutputFilterByType DEFLATE image/svg+xml
AddOutputFilterByType DEFLATE image/x-icon
AddOutputFilterByType DEFLATE text/css
AddOutputFilterByType DEFLATE text/html
AddOutputFilterByType DEFLATE text/javascript
AddOutputFilterByType DEFLATE text/plain
AddOutputFilterByType DEFLATE text/xml
# Remove browser bugs (only needed for really old browsers)
BrowserMatch ^Mozilla/4 gzip-only-text/html
BrowserMatch ^Mozilla/4\.0[678] no-gzip
BrowserMatch \bMSIE !no-gzip !gzip-only-text/html
Header append Vary User-Agent
</IfModule>
Leverage browser caching: This instructs the user’s browser to store certain files (such as images, CSS, and JavaScript) in its cache, so they don’t have to be downloaded again on subsequent visits. Add the following code to your .htaccess file:
<IfModule mod_expires.c>
ExpiresActive On
ExpiresByType image/jpg “access 1 year”
ExpiresByType image/jpeg “access 1 year”
ExpiresByType image/gif “access 1 year”
ExpiresByType image/png “access 1 year”
ExpiresByType text/css “access 1 month”
ExpiresByType text/html “access 1 month”
ExpiresByType application/pdf “access 1 month”
ExpiresByType text/x-javascript “access 1 month”
ExpiresByType application/x-shockwave-flash “access 1 month”
ExpiresByType image/x-icon “access 1 year”
ExpiresDefault “access 1 month”
</IfModule>
Enable caching headers: This sets HTTP headers that instruct the user’s browser to cache certain files for a specific amount of time. Add the following code to your .htaccess file:
<IfModule mod_headers.c>
<FilesMatch “\.(ico|jpe?g|png|gif|swf|css|js)$”>
Header set Cache-Control “max-age=2592000, public”
</FilesMatch>
</IfModule>
make site more secure
Block directory browsing: This prevents anyone from being able to browse the contents of your website’s directories. Add the following code to your .htaccess file:
Options -Indexes
Prevent hotlinking: This prevents other websites from using your images and other media files by linking to them directly. Add the following code to your .htaccess file:
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http(s)?://(www\.)?yourwebsite.com [NC]
RewriteRule \.(jpg|jpeg|png|gif)$ – [NC,F,L]
Make sure to replace “yourwebsite.com” with your actual website URL.
Set proper file permissions: This prevents unauthorized users from accessing your website files. The following code sets the correct file permissions for your WordPress installation:
<Files wp-config.php>
Order allow,deny
Deny from all
</Files>
# Block the include-only files.
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^wp-admin/includes/ – [F,L]
RewriteRule !^wp-includes/ – [S=3]
RewriteRule ^wp-includes/[^/]+\.php$ – [F,L]
RewriteRule ^wp-includes/js/tinymce/langs/.+\.php – [F,L]
RewriteRule ^wp-includes/theme-compat/ – [F,L]
</IfModule>
Limit login attempts: This prevents hackers from brute-forcing their way into your WordPress dashboard by limiting the number of login attempts. Add the following code to your .htaccess file:
<IfModule mod_authz_core.c>
<FilesMatch “wp-login.php”>
AuthName “WordPress Login”
AuthType Basic
AuthUserFile /dev/null
Require valid-user
LimitRequestBody 102400
</FilesMatch>
</IfModule>
<Files wp-login.php>
LimitRequestBody 102400
</Files>
# Limit Login Attempts
<IfModule mod_security.c>
SecFilterEngine Off
SecFilterScanPOST Off
</IfModule>
<IfModule mod_limitipconn.c>
<Location “/wp-login.php”>
# Increase timeout for client IP
LimitIPConnRemTime 3600
# Lock out the client IP after x failed attempts
LimitIPConn max 10
</Location>
</IfModule>