i think first you need to review website secure issue
1. LOG ,LOG,LOG
develop some log for admin to manage and block some ip or useragent to view forum or API,record action ,post ,delete etc. this is very important .we can view clean flood that is from where
2.I don't know why we need to use...