you can mitigate a lot of potential wordpress attacks on cloudflare with filters, if you know a bit about wordpress and bots and attackers metrics . i use a couple of older wp versions and also older php versions and they havent been hacked yet. just close everything that lets people from outside try to comment, mail, post etc. the easiest way is to use cloudflares waf > xmlrpc.php, wp-login.php, wp-comments.php, wp-admin, wp-mail, rest api, throw and block everyone out who is trying to access those from outside,+ it also takes load from your own server , its also good to do this on newer versions
|