Are the wordpress settings (abspath, disable core updates) added by SiteGround of any use after I’ve migrated to a different host?

Both of these settings are used in all WordPress installs – they’re not specific to any host. The ABSPATH ensures that WordPress knows which folder to look in to find all of its files. Whether Core auto-updates are good or bad really comes down to your own processes and preferences. For security reasons, enabling the … Read more

hide wp-content from urls

You don’t need a separate rule in your .htaccess. Add … define( ‘WP_CONTENT_DIR’, ‘YOUR_LOCAL_PATH’ ); define( ‘WP_CONTENT_URL’, ‘YOUR_PUBLIC_PATH’ ); … to your wp-config.php. Do not write into wp-settings.php. This file will be overwritten during the next update – never touch a core file.

How secure is a wp-config file?

This is really more of a server configuration question. By necessity, wp-config.php must be readable by WordPress itself, but file access/security beyond that is really a matter of how your server is configured. Refer to the Codex for recommended file permissions for WordPress. Refer to the Codex for recommended ways to secure wp-config.php Refer to … Read more