This is my take on a Wordpress install from scratch
- Download fresh new version from Wordpress.org every new install
- Create new database user for WP specifically
- Use long and strong passwords for everything, never reuse
- Admin-username is not admin or similar, never reuse
My preferred setup
- GeneratePress
- GeneratePress Premium
- GenerateBlocks
- GenerateBlocks Pro
- Yoast SEO
- ManageWP - Worker
- EWWW Image Optimizer
- Yoast Dupliser innlegg
- White Label CMS
- Block Navigation
- Permalinks (flat)
- Media: 300x300, 600x600, 1920x1920
- Discussion: do not allow
- Check time and date format
- Import setting for White Label CMS
- Google and Bing verification code for Yoast
- Connect to ManageWP (Orion)
- Delete all extra themes, except last official WP theme
- Turn on modules features in GeneratePress
- Delete example comment and article
- WPForms Lite (easy) / Contact Form 7 (custom, old school)
- Activate turnstile captcha
- Simple Cloudflare Turnstile
- WPMail SMTP Pro
- AzAD
- Simple Cloudflare Turnstile
- Smash Balloon Instagram Feed
- Flamingo
- Font Awesome
- Mailchimp for WooCommerce
- Loco oversettelse
- Translate Press
- Regenerate Thumbnails
- Media File Renamer
- Strong Testimonials
- ACF (Pro)
These are for the wrapup, when optimizing site for loading speed, google page speed, gtmetrix
- Lazy Load for Videos
- Autoptimize
- Async Javascript
- Turn on webP in image plugin
- Child Theme Configurator version 2.6.6