Strive for lofty goals

About FEEI.CN

A

About FEEI.CN’s Cybersecurity

LayerThreatProtective Measures
NetworkDDoS/CCSet DNS record to gov site
MITMHTTPS(SSLLabs Test Score A+); HSTS; HSTS Preload
ApplicationXSSSecurity Header(CSP/X-XSS-Protection)
iFrameSecurity Header(X-Frame-Options)
MIME SniffingSecurity Header(X-Content-Type-Options)
Fronted BackdoorSecurity Header(Permissions-Policy)
SQLiChange Database Prefix; No sensitive data;
Brute-force login accoundCustom username; Strong password; 2FA; Disable xmlrpc; Hidden login url; Automatic IP Blocking Brute-Force
Sensitive data leakgeDEBUG False; Disable PHP Error; Hidden PHP/Wordpress/Nginx Version; Automatic IP Blocking Vulnerability Detection
Trojan/Mining/WebshellDISALLOW_FILE_EDIT; Separate user group for static/php files, read-only permissions, no write access except in upload directory;
0daySeparate user WP-CLI mode for automatic updates of Core/Plugin/Theme to latest version; inotify www directory; Automatic IP Blocking When Web attack;
RansomwareDaily Backup of files and database to remote server; Daily backup of ECS Image;
ServerService Brute-force/VulnerabilityOnly 80/443 ports opened; Automatic IP Blocking When Port Scan; Private IP Login with Key; Outbound Internet Access Restriction;

About FEEI.CN’s Speed

LayerItemsCompanyConfig/VersionResult
NetworkDNSDNSPod<60ms
VPSAliyun4M, Hangzhou(South) + Beijing(North)<15ms
CDN
Base ApplicationBlog SoftwareWordPressAutomatic Update
Web ServerNginx1.20.1+HTTP2
Program LanguagePHP8.0.30+OPCache+FastCGI Cache
Software ApplicationThemeTypologyText based with no image required
TextLighthouse/
Compression/TextMinify/
Compression/ImageWebp/
Compression/TransmissionGZipAll file type
Async/TextasyncStatis files
Async/MediaLazy Load/
Cache/BrowserHTTP Cacheno-cache
Cache/ApplicationFILE CachePage/Post
Cache/DatabaseRedis3.2.12
Other/URL Redirect/0
Other/Other domains resources/0
Speed TestPageSpeed Insights(Lighthouse)Performance Score100
PingdomPerformance Score94
Strive for lofty goals
Loading