Quote:
Originally Posted by Shoplifter
WordPress in a htpasswd protected members directory.
|
I would be remiss in not mentioning that htpasswd protection is a dated, and potentially vulnerable method of securing any kind of directory or domain.
It is absolutely an acceptable way to protect something, and I use it all the time.
But you do not have access to statistics or analytics about usage, there is no way to two-factor authenticate your users, and brute-forcing and CAPTCHA protection is non-existent. You would need to rely on a WAF for that. Plus, you can't retarget users with htaccess/htpasswd as effectively as a programmed alternative.
I'm biased though, because I build software to replace htpasswd prompts.
WordPress gets a lot of hate, but it's definitely able to work as a small paysite CMS. I have clients who use LoginBlue with WordPress, and it works really well to deliver their content.