Removing Wordpress plugin references

March 4th, 2008
No Gravatar

I’d like remove all references Wordpress plugins put into my HTML code.
Am I selfish? Or just prudent about security?

Whilst I am in no way against plugin authors advertising themselves in the HTML code of any Wordpress blogs I set up (for myself, i9000 Networks, or clients), I still feel a little concerned that the more devious of web users can instantly gain a list of plugins I use, to potentially exploit.

But wait, I’m not selfish! I’d love to give the authors kudos for all their hard work in coding the plugins I use, they are much better programmers than myself. I just don’t how to do it securely.

I enjoy being anonymous, a decade’s experience in hosting web sites proves this. Every day I see servers shouting the fact they are running Apache 1.3.2 and PHP 4.1.2 or similar which (may) have huge security holes in them.

Check this server, go on! All you’ll get is;

Server: Apache

Which is the minimum Apache lets me. You’d never even know I use PHP. Shhh, its a secret!

So why stop there, after all, security is only as strong as the weakest link. I’ve anonymised my server and server software. I should now anonymise my Wordpress install, removing the

<meta name="generator" content="WordPress 2.3.3" /><!-- leave this for stats -->

reference, footer tags and various other Wordpress-isms, but I’m not going to. After all, its still reasonably obvious if the blog is Wordpress. I can usually spot them instantly.

The next logical step is to edit all the plugins you use so they don’t make any HTML comments in the code, but doing this would make me feel really guilty. Wouldn’t you? Removing all references to 17 people’s hard work?

With uberdose releasing updates for the All In One SEO Pack nearly daily, it would prove overly time consuming across all the Wordpress installations I have.

So, although I’d like to secure, with a by-product of apparently being selfish, there’s no easy way of doing it.

Bookmark it del.icio.us | Reddit | Slashdot | Digg | Facebook | Technorati | Google | StumbleUpon | Window Live | Tailrank | Furl | Propeller | Yahoo


Was this post useful to you? Let me know, buy me a beer!
Alternatively, if you're feeling impecunious, you may like to subscribe to my RSS feed, or see other articles in the Wordpress category.

3 Responses to “Removing Wordpress plugin references”

  1. ColinNo Gravatar Says:

    Great article, thanks

  2. Web HostingNo Gravatar Says:

    This is a good start on securing your WordPress installation however I think this is only a preliminary thing and would only stop newbie hackers

  3. Betting systemsNo Gravatar Says:

    Nice blog,i will come back here everyday, greetings

Leave a Reply