{"id":13591,"date":"2014-12-16T22:37:15","date_gmt":"2014-12-16T15:37:15","guid":{"rendered":"http:\/\/tom.ji42.com\/?p=13591"},"modified":"2020-11-05T13:46:02","modified_gmt":"2020-11-05T06:46:02","slug":"protect-and-secure-wordpress-site-from-hackers-2","status":"publish","type":"post","link":"https:\/\/tom.tomwork.net\/?p=13591","title":{"rendered":"Protect and secure WordPress site from Hackers"},"content":{"rendered":"<p>WordPress is among the most popular blogging platforms being used. And because it is so popular it becomes a common target for hackers. Fortunately, it supports a wide ecosystem of free plugins and services that can help you enhance the security of your WordPress blog. We have already seen <a title=\"How to keep websites secure\" href=\"http:\/\/www.thewindowsclub.com\/how-to-keep-websites-secure\" target=\"_blank\" rel=\"noopener noreferrer\">how to keep websites secure<\/a> and deal with threats and vulnerabilities in general. In this post we will see how to harden security so as to protect and secure your self-hosted WordPress site.<\/p>\n<h2>Secure WordPress site<\/h2>\n<p><!--more--><\/p>\n<p>1]\u00a0 Make sure your <strong>Windows computer<\/strong> is free of malware. No amount of security in WordPress or on your web server will make any difference if there is an illegal keylogger installed on your computer.<\/p>\n<p>2] Always make sure that you have the <strong>latest version<\/strong> of WordPress and your Plugins installed. Your web server can have vulnerabilities too. Therefore, make sure that your <strong>Web Host<\/strong> is running latest, secure, stable versions of server software on it. Better still, make sure you are using a trusted host that takes care of these things for you.<\/p>\n<p>3] Use a <strong>strong username<\/strong> and a <strong>strong passwords<\/strong>. Best to go for mixed complex passwords using upper, lower case alphabets, numerals and special characters of length exceeding 15 characters. Enforce usage of strong passwords for all your Authors too.<\/p>\n<p>4] <strong>Change the Administrator username<\/strong> of your WordPress installation from the default <em>admin<\/em> to something strong and unrelated to your own or sites name. <span class=\"gmw_\">You can create another administrator account, login as new administrator user and delete the old default admin username account. Or you could use <strong>Admin username changer<\/strong> or <strong><span class=\"gmw_\">Admin <span class=\"gm_ gm_c0f0af24-11ab-2fc2-b8c2-f8c7bb2fdcc6 gm-spell\">renamer<\/span>extended<\/span><\/strong> plugin or one of the security plugins mentioned below to rename the default admin username.<\/span><\/p>\n<p>5] Use a Captcha for login purposes.<\/p>\n<p>The <strong>Captcha plugin from BWS<\/strong> is a good one you may want to have a look at. It lets you choose the operations and the complexity levels.<\/p>\n<p>6] The <strong>Limit Login Attempts<\/strong> plugin will limit the rate of login attempts, by way of cookies, for each IP. It will allow only the configured number of attempts after which the user will get locked out. You can configure all its settings like number of attempts allowed, lock out period, allowed re-tries and so on. This plugin is useful in preventing brute force attacks.<\/p>\n<p>If a user uses and incorrect username or password, he or she will see this message.<\/p>\n<p>7] <strong>Change the WordPress Panel login URL<\/strong> from default <em>\/wp-admin\/<\/em> to something else using <strong>Rename wp-login<\/strong>plugin.\u00a0 This plugin is useful in preventing brute force attacks too.<\/p>\n<p>&nbsp;<\/p>\n<p>8] Use a <strong>Security Scanner plugin<\/strong> to scan your WordPress installation files periodically. The <strong>Sucuri Security \u2013 SiteCheck Malware Scanner<\/strong><span class=\"gmw_\"><span class=\"gmw_\"> plugin enables you to scan your WordPress site using <span class=\"gm_ gm_9313fb2a-a2f5-320f-fa9f-9aab497c31c0 gm-spell\">Sucuri<\/span> SiteCheck right in your WordPress dashboard. It checks for malware, spam, blacklisting, .htaccess redirects, hidden <\/span><span class=\"gm_ gm_0ea6ab48-f132-3281-5a9c-ef361ffcf41e gm-spell\">eval<\/span> code, and other security issues.<\/span><\/p>\n<p>Furthermore, it verifies if WordPress and PHP is up-to-date and hides the WordPress version from public etc, if your site is protected by a Web Firewall. It also protects your Uploads Directory, restricts wp-content and wp-includes access by hardening file permissions and checks for the integrity of your core WordPress files. It monitors a large number of actions, including, Login attempts, Failed Logins, File Changes and so on.<\/p>\n<div><\/div>\n<p>Sucuri also checks if your site has been black-listed anywhere like Google Safe Browsing, Norton Safe Web, Phish Tank, SiteAdvisor, Eset, Yandex, etc and informs you about it.<\/p>\n<p><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">Apart from <\/span><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\"><span class=\"gm_ gm_a71b8bb5-10f7-a632-9cc4-f9cd28212178 gm-spell\">Sucuri<\/span><\/span><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">, <\/span><strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">Secure WordPress<\/span><\/strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\"> plugin, <\/span><strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">Exploit Scanner<\/span><\/strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">, <\/span><strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">WordFence Security<\/span><\/strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">, <\/span><strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">WordPress Sentinel<\/span><\/strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">, <\/span><a title=\"Quttera Web Malware Scanner\" href=\"http:\/\/www.thewindowsclub.com\/quttera-web-malware-scanner\" target=\"_blank\" rel=\"noopener noreferrer\"><strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\"><span class=\"gm_ gm_89c6aa1b-f611-ff06-843c-02a2729bc6c1 gm-spell\">Quttera<\/span><\/span><\/strong><\/a><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">, <\/span><strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">VIP Scanner<\/span><\/strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">, <\/span><strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\"><span class=\"gm_ gm_50094264-42fb-5d34-06ce-2b0408b2816f gm-spell\">iThemes<\/span><\/span><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\"> Security<\/span><\/strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\"> (formerly Better WP Security),\u00a0<\/span><strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">BulletProof Security<\/span><\/strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\"> and <\/span><strong><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">All In One WP Security &amp; Firewall<\/span><\/strong><span class=\"gmw_\"><span class=\"gm_ gm_d5b74f27-45fc-81cf-15a8-5e5d1a231ddc gm-spell\">are among the other good scanners and security plugins you may want to have a look at.<\/span> Most of these plugins, apart from scanning your site for malware, will also help you Harden File Permissions, delete ReadMe files, hide WordPress version, and more.<\/span><\/p>\n<p><em>Remember to back up your database or full site before making any notable changes to your WordPress installation as some of these 1-click fixes could potentially break some functionality of your site. So please be careful here.<\/em><\/p>\n<p><span class=\"gm_ gm_7156f983-3b40-be87-4ecd-a9206dc798d5 gm-spell\">8] Use <\/span><strong><span class=\"gm_ gm_7156f983-3b40-be87-4ecd-a9206dc798d5 gm-spell\"><span class=\"gm_ gm_3480ad77-330f-f503-dbba-5081a8afe20b gm-spell\">Cloudlare<\/span><\/span><\/strong><span class=\"gmw_\"><span class=\"gm_ gm_7156f983-3b40-be87-4ecd-a9206dc798d5 gm-spell\"> free content delivery network to filter all your traffic and minimizes the risk of your WordPress website from becoming a target, as it acts as a proxy between your visitors and the server your website is hosted on.<\/span> Cloudflare basic is free, but if you pay a nominal amount, you can also avail of its <\/span><strong>Web Application Firewall<\/strong> service. It\u00a0stops real-time attacks like SQL injection, cross-site scripting, comment spam and other abuse at the network edge. <strong>Sucuri<\/strong> offers a great firewall, but it is not free.<\/p>\n<p>9] Minimize the <strong>number of plugins<\/strong> you use. Deactivate or even better, delete the ones you don\u2019t use.<\/p>\n<p>10] Keep creating <strong>backups<\/strong> of your site at regular intervals, and upload them to some Cloud service and\/or to your desktop. <strong>BackWPUp<\/strong>, <strong>VaultPress<\/strong>, <strong>BackupBuddy<\/strong>, <strong>DropBox for WordPress,<\/strong> <strong>BackUpWordPress<\/strong> are among the good Backup plugins you may want to check out.<\/p>\n<p>While this may be enough for most WordPress sites, if you need to go further, you could read this post on <a href=\"http:\/\/codex.wordpress.org\/Hardening_WordPress\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">WordPress<\/a>. You might want to also read about <a title=\"what is badware\" href=\"http:\/\/www.thewindowsclub.com\/what-is-badware\" target=\"_blank\" rel=\"noopener noreferrer\">Badware and Badware websites<\/a>.<\/p>\n<p>Some of you might want to check out my post on <strong><a title=\"Useful tips for new bloggers\" href=\"http:\/\/www.thewindowsclub.com\/10-basic-useful-tips-for-new-bloggers\">Useful tips for new bloggers<\/a><\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress is among the most popular blogging platforms being used. And because it is so popular it becomes a common target for hackers. Fortunately, it supports a wide ecosystem of free plugins and services that can help you enhance the security of your WordPress blog. We have already seen how to keep websites secure and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[13],"tags":[],"class_list":["post-13591","post","type-post","status-publish","format-standard","hentry","category-13"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p6cOVM-3xd","_links":{"self":[{"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=\/wp\/v2\/posts\/13591","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13591"}],"version-history":[{"count":11,"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=\/wp\/v2\/posts\/13591\/revisions"}],"predecessor-version":[{"id":24781,"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=\/wp\/v2\/posts\/13591\/revisions\/24781"}],"wp:attachment":[{"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tom.tomwork.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}