HOW TO: Update WordPress Secret Keys

WordPress Secret Keys are kinda similar to passwords, harder the better. Which is tough to crack? This one “3gFi67dfads8FnU9″ or something like “welcome”, “password”, etc.

In the WordPress 2.6, three security keys, AUTH_KEY, SECURE_AUTH_KEY, and LOGGED_IN_KEY, were added to ensure better encryption of information stored in the user’s cookies. WordPress Secret Keys are normally used for better Cookie Security. It makes cookies secure against attacks like when someone hacked into your database via an SQL injection exploit or some other tactics, etc.

Example of WordPress Secret Keys [Don't Use This]

WP Secret Keys

The 8 security keys are AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY, NONCE_KEY with respective salts AUTH_SALT, SECURE_AUTH_SALT, LOGGED_IN_SALT, and NONCE_SALT. They will make your site is harder to hack and crack by hackers.

These keys are required for the enhanced security. The four salts are recommended, but are not required, because WordPress will generate salts for you if none are provided. They are included in wp-config.php by default for inclusiveness.

Updating WordPress Secret Keys

Open wp-config.php file using any of your favorite file editor, I would recommend Notepad++. Find the default secret keys.

Now use the new Secret Code Generator for getting the secret keys, just copy and replace them. Don’t forget to save the file!

Also do remember changing these values will invalidate all existing cookies and logout all WordPress users (including admin) on your site. Who knows, even some hackers will lose their access to your account.

Updating WordPress secret keys is one of the most recommended WordPress Security Tips. If you are not comfortable with editing wp-config.php or facing any issues, you can ask someone you trust to do that for you, because simple mess in wp-config.php can collapse your entire site.



Want to discuss your queries and interact with experts? You can connect with HellBound Bloggers (HBB) Facebook group for free!

On June 20, 2011 by in WordPress | Short Link: http://hbb.me/12KaZAD  

About
CEO and Founder of Slashsquare, Indian Blog Network and Web Consulting Media. HBB is a part of Slashsquare Network. I'm a Tech Blogger, Striving Entrepreneur, Atheist, and Proud Indian. Catch me on Facebook, Twitter and .


We'll be happy to know your views and opinions, you can share them as comments below. If you have any issues, kindly have a look at our Comments Policy and you can also Contact Us.


Also do remember we value our comments like our blog posts, so please avoid simple or silly complimentary comments. We'll be removing them as they won't add any value to the post. Thanks for understanding.



You can also comment using your Facebook Profile here


8 Opinions on “HOW TO: Update WordPress Secret Keys

  1. thanks for the info bro!
    i could see two fb tabs ! lol :D

  2. Yes! its really wonderful tips to update Secret Keys in WP. Thanks for sharing with us.

  3. I think I am gonna try this with my blog, everyone loves security so do I :)

  4. Very useful article to all the people in the world wide. So, thanks for sharing word press secret info on here :)

  5. was a bit confusing, but understood when i read it second time :) Screenshots can be more :P

  6. Really great tips on here. Thank you so much for given up here :)

  7. Yeah, Really valued information… Gonna try this..
    Thanks For sharing great info :)

  8. Awesome post. I never heard about secret keys. Thank you so much. Gonna test these :).

Leave a Reply