.htaccess for /wp-content/plugins
-
Hi developer,
I found BPS does not have .htaccess for /wp-content/plugins directory. Plugin directory contains useful information for attackers. e.g. readme.txt contains version information.
Even if access to readme.txt/etc is prohibited, attacker could do fingerprinting against css/js/etc to determine plugin version, but limiting access to *.txt would be useful for simple attack/information gathering.
Please consider adding access control to /wp-content/plugins directory.
Thank you.
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
- The topic ‘.htaccess for /wp-content/plugins’ is closed to new replies.