{"id":19,"date":"2026-07-04T18:45:00","date_gmt":"2026-07-04T13:15:00","guid":{"rendered":"https:\/\/softcrony.com\/blog\/?p=19"},"modified":"2026-07-04T18:45:00","modified_gmt":"2026-07-04T13:15:00","slug":"wordpress-security-checklist-2026","status":"publish","type":"post","link":"https:\/\/softcrony.com\/blog\/wordpress-security-checklist-2026\/","title":{"rendered":"WordPress Security Checklist: 10 Steps to Harden Your Site in 2026"},"content":{"rendered":"<p class=\"font-claude-response-body break-words whitespace-normal\">Most WordPress sites get hacked not because of sophisticated attacks \u2014 but because of basic security steps that were never taken.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">This checklist covers the 10 most important things you can do right now to harden your WordPress site. No security expertise required.<\/p>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">1. Keep WordPress, Themes, and Plugins Updated<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">This is the single most important security step and the one most commonly skipped.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">Over 60% of hacked WordPress sites were running outdated software at the time of the breach. Updates patch known vulnerabilities \u2014 leaving them unpatched is like locking your front door but leaving the window open.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Go to Dashboard \u2192 Updates and apply everything pending<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Enable automatic updates for minor WordPress versions<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Delete plugins and themes you don&#8217;t actively use \u2014 inactive code is still vulnerable code<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">2. Use Strong, Unique Passwords and a Password Manager<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">&#8220;admin123&#8221; and &#8220;softcrony2024&#8221; are not passwords. They&#8217;re invitations.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">Every WordPress account \u2014 admin, editor, author \u2014 needs a unique, randomly generated password of at least 16 characters. Use a password manager like Bitwarden (free) or 1Password to generate and store them.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Go to Users \u2192 All Users and force password resets for all accounts<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Install Bitwarden browser extension \u2014 it&#8217;s free and open source<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Never reuse passwords across different sites or services<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">3. Change the Default Admin Username<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">When WordPress is installed, the default username is often &#8220;admin&#8221;. Attackers know this and use it as the first guess in brute force attacks.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Create a new admin user with a different username<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Log in as the new user<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Delete the original &#8220;admin&#8221; account (reassign posts to the new user)<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">4. Enable Two-Factor Authentication<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">Even if an attacker gets your password, 2FA stops them from logging in without physical access to your phone or authenticator app.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Install the <strong>WP 2FA<\/strong> plugin (free)<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Enable 2FA for all admin accounts<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Use an authenticator app like Google Authenticator or Authy \u2014 not SMS<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">5. Limit Login Attempts<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">By default, WordPress allows unlimited login attempts. This makes brute force attacks \u2014 trying thousands of password combinations \u2014 trivially easy.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Install <strong>Limit Login Attempts Reloaded<\/strong> (free plugin)<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Set lockout after 5 failed attempts<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Set lockout duration to 30 minutes<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Enable email notification for lockouts<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">6. Install an SSL Certificate<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">If your site still runs on HTTP instead of HTTPS, fix this immediately. An SSL certificate encrypts data between your site and visitors \u2014 and Google actively penalises sites without it.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Most hosting providers (cPanel, Hostinger, SiteGround) offer free Let&#8217;s Encrypt SSL \u2014 enable it in your hosting panel<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Install the <strong>Really Simple SSL<\/strong> plugin to handle the WordPress side<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Verify by checking for the padlock icon in your browser address bar<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">7. Disable XML-RPC If You Don&#8217;t Use It<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">XML-RPC is a WordPress feature that allows remote connections \u2014 including the Jetpack plugin and mobile apps. If you don&#8217;t use these, XML-RPC is just an open attack surface.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">Attackers use XML-RPC to run brute force attacks because it allows multiple login attempts per request, bypassing login attempt limits.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><br \/>\nAdd this to your <code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">.htaccess<\/code> file:<\/p>\n<div class=\"relative group\/copy bg-bg-000\/50 border-0.5 border-border-400 rounded-lg focus:outline-none focus-visible:ring-2 focus-visible:ring-accent-100\" tabindex=\"0\" role=\"group\" aria-label=\"Code\">\n<div class=\"sticky opacity-0 group-hover\/copy:opacity-100 group-focus-within\/copy:opacity-100 top-2 py-2 h-12 w-0 float-right\">\n<div class=\"absolute right-0 h-8 px-2 items-center inline-flex z-10\"><\/div>\n<\/div>\n<div class=\"overflow-x-auto\">\n<pre class=\"code-block__code !my-0 !rounded-lg !text-sm !leading-relaxed p-3.5\"><code># Disable XML-RPC\r\n&lt;Files xmlrpc.php&gt;\r\n  Order Deny,Allow\r\n  Deny from all\r\n&lt;\/Files&gt;<\/code><\/pre>\n<\/div>\n<\/div>\n<p class=\"font-claude-response-body break-words whitespace-normal\">Or install the <strong>Disable XML-RPC<\/strong> plugin if you&#8217;re not comfortable editing <code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">.htaccess<\/code>.<\/p>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">8. Set Correct File Permissions<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">Incorrect file permissions are a common entry point for attackers. WordPress files and folders should have specific permission levels.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>Correct permissions:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Folders: <code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">755<\/code><\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Files: <code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">644<\/code><\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">wp-config.php<\/code>: <code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">440<\/code> or <code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">400<\/code><\/li>\n<\/ul>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Access your server via FTP or cPanel File Manager<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Right-click <code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">wp-config.php<\/code> \u2192 Change Permissions \u2192 set to 440<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Your hosting provider&#8217;s support team can help if this is unfamiliar<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">9. Regular Backups \u2014 Automated and Off-Site<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">No security measure is 100% effective. Backups are your last line of defence \u2014 but only if they&#8217;re automatic, recent, and stored somewhere other than your main server.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Install <strong>UpdraftPlus<\/strong> (free) \u2014 the most widely used WordPress backup plugin<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Configure automatic daily backups<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Store backups to Google Drive or Dropbox \u2014 not just your hosting server<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Test a restore at least once to confirm your backups actually work<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">10. Use a Web Application Firewall (WAF)<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">A WAF filters malicious traffic before it reaches your WordPress site \u2014 blocking known attack patterns, bad bots, and suspicious requests.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>Free options:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Cloudflare Free plan<\/strong> \u2014 adds a WAF, CDN, and DDoS protection at the DNS level. This is our first recommendation for any WordPress site in India because it also significantly improves page speed.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\"><strong>Wordfence<\/strong> (free tier) \u2014 a WordPress plugin that adds a firewall and malware scanner directly in WordPress<\/li>\n<\/ul>\n<p class=\"font-claude-response-body break-words whitespace-normal\"><strong>What to do:<\/strong><\/p>\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Sign up for Cloudflare (free) at cloudflare.com<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Add your domain and update your nameservers at your domain registrar<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">Enable the WAF rules in the Cloudflare dashboard<\/li>\n<\/ul>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Quick Reference Checklist<\/h3>\n<div class=\"overflow-x-auto w-full px-2 mb-6\">\n<table class=\"min-w-full border-collapse text-sm leading-[1.7] whitespace-normal\">\n<thead class=\"text-left\">\n<tr>\n<th class=\"text-text-100 border-b-0.5 border-[hsl(var(--border-300)\/0.6)] py-2 pr-4 align-top font-bold\" scope=\"col\">Step<\/th>\n<th class=\"text-text-100 border-b-0.5 border-[hsl(var(--border-300)\/0.6)] py-2 pr-4 align-top font-bold\" scope=\"col\">Done?<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">WordPress, themes, plugins updated<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">Strong unique passwords on all accounts<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">Default admin username changed<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">Two-factor authentication enabled<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">Login attempts limited<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">SSL certificate active<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">XML-RPC disabled<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">File permissions correct<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">Automated off-site backups running<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">WAF enabled (Cloudflare or Wordfence)<\/td>\n<td class=\"border-b-0.5 border-[hsl(var(--border-300)\/0.3)] py-2 pr-4 align-top\">\u2610<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">How We Handle Security at Softcrony<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal\">For every WordPress site we build or maintain, these 10 steps are part of our standard delivery checklist. Security isn&#8217;t an add-on \u2014 it&#8217;s built into the process from day one.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal\">If you&#8217;d like a security audit of your existing WordPress site, or want us to implement these steps for you, <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/softcrony.com\/contact\/\">get in touch with our team<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most WordPress sites get hacked not because of sophisticated attacks \u2014 but because of basic security steps that were never taken. This checklist covers the 10 most important things you can do right now to harden your WordPress site. No security expertise required. 1. Keep WordPress, Themes, and Plugins Updated This is the single most [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":20,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[23,24,26,22,25],"class_list":["post-19","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-security","tag-web-security","tag-website","tag-wordpress","tag-wordpress-security"],"_links":{"self":[{"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/posts\/19","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/comments?post=19"}],"version-history":[{"count":1,"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/posts\/19\/revisions"}],"predecessor-version":[{"id":21,"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/posts\/19\/revisions\/21"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/media\/20"}],"wp:attachment":[{"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/media?parent=19"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/categories?post=19"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/softcrony.com\/blog\/wp-json\/wp\/v2\/tags?post=19"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}