A high risk client wants to use #WordPress. I may be ultimately responsible.
I believe I can handle doing things correctly at the LAM but the P concerns me. How to harden WP? My first thoughts are lock down the users table and move wp-config.php out of the web root. Change control on core and I handle updates.
How else to harden wp? Jokes welcome but bonus points for actual suggestions.