Verify WordPress is up-to-date | Make the WordPress version private |
Block PHP in directories | Remove WordPress readme file |
Enable DISSALLOW_FILE_EDIT in WordPress |
One of the ways a site can be compromised is by PHP files being injected into your WordPress folders and executed from there. The following steps will help you block PHP files in those directories, but you will want to test your site functionality to ensure these settings are not interferring with your theme and plugins.
If the section turns green, the plugin was able to enable this feature. If the section is still red, the plugin does not have permission to make this change.