Keeping your databases secure

Protect your website’s databases: separate users, strong passwords, prepared statements, safe credential storage and backups.

How-to guideIntermediate2 min readUpdated

1. One user per application

Each application gets its own database user with access only to its own database. Managing database users and privileges

2. Strong, unique passwords

Generate them. Never reuse a database password for anything else.

3. Prevent SQL injection

Never build SQL with user input:

// Unsafe
$db->query("SELECT * FROM users WHERE email = '$_POST[email]'");

// Safe
$stmt = $pdo->prepare('SELECT * FROM users WHERE email = ?');
$stmt->execute([$_POST['email']]);

Connecting a PHP application to your database

4. Keep credentials out of reach

  • Store configuration outside public_html where possible. Storing configuration and secrets outside public_html
  • Never commit credentials to a public Git repository.
  • Remove backup copies like wp-config.php.bak or config.old from public_html: the server may serve them as plain text.

5. Don’t leave SQL dumps in public_html

A backup.sql file in the web root can be downloaded by anyone who guesses the name. Store exports off the server.

6. Keep phpMyAdmin access to trusted devices

Log out when finished, especially on shared computers.

7. Back up

A secure database you can’t restore is still a single point of failure. A simple backup strategy for your website

Looking for somewhere to run PHP and MySQL? Traxio’s free PHP MySQL hosting includes phpMyAdmin and is free for your first 30 days.

Popular

Tip: press / to search from any pageSee all results