Moodle Security Hardening on Shared Hosting: Lock Down moodledata, Admin Paths, and HTTP Headers
Moodle installs on shared hosting often leave the data directory web-reachable, the config file loosely permissioned, and login pages open to brute force. This guide walks through concrete fixes using File Manager, .htaccess, config.php, and the Moodle AdminCP.