tips for a secure wordpress website

22
Tips For A Secure Wordpress Website

Upload: valuecoders

Post on 11-Jan-2016

62 views

Category:

Documents


2 download

DESCRIPTION

More than 70% of WordPress sites and blogs are vulnerable to attack due to their security flaws. Once you have started with your WordPress site the next major step should be its security.

TRANSCRIPT

Page 1: Tips for a secure wordpress website

Tips For A Secure Wordpress Website

Page 2: Tips for a secure wordpress website

Introduction ● More than 70% of WordPress sites and blogs are vulnerable to attack due to their

security flaws. Once you have started with your WordPress site the next major step

should be its security.

● Not taking security seriously is an open invitation to hackers. If you are wondering

how to secure WordPress website, here are 20 simple tips that would help you

prevent malicious attacks to your site.

Page 3: Tips for a secure wordpress website

Use The Latest Wordpress Version The Legacy versions of WordPress are most vulnerable to attacks as they often have

known security flaws.

You need to constantly update to the latest version of the CMS.

Page 4: Tips for a secure wordpress website

Clean Your SiteYou should clean your site like you would clean your kitchen and remove stale

food items.

Delete plugins and themes that you no longer use as the legacy versions can be

exploited easily.

Page 5: Tips for a secure wordpress website

Keep Workstations SanitisedYou don’t need a hacker to harm your site, viruses and malwares in your

workstation are enough.

Keep your workstation sanitized to prevent such kinds of security breaches.

Page 6: Tips for a secure wordpress website

Secure Hosting ProviderChoose a reliable hosting service provider or move your existing site to one that

assures security features.

They adopt state-of-the-art measures that thwart most attacks keeping your site/blog

secure.

Page 7: Tips for a secure wordpress website

Use .htaccessIt is one of the best ways to secure your site where you would be able to block IPs.

It is a a very simple process and you can do it using htaccess.

Page 8: Tips for a secure wordpress website

SSL EncryptionIt encrypts all the data that your blog or site would send and prevent it from

being intercepted midway via your router or other network.

SSL data even if intercepted is hard to decrypt.

Page 9: Tips for a secure wordpress website

Don’t Use Admin as Username● This is the default setup in WordPress and most attackers would target it. Using a

strong admin name secure you against petty cyber criminals.

● Also use a strong password that has alphabets, numerics and special characters.

Page 10: Tips for a secure wordpress website

User Accounts● Monitor the permission levels in all your user accounts and make sure you offer

access to users who really need it.

● Check for the passwords in all the accounts and remove any unused account

created during development.

Page 11: Tips for a secure wordpress website

Two Step Authentication● There are several plugins such as Clockwork SMS, Clef, Duo Two-Factor

Authentication that allow you two step authentication mostly using your mobile as

an additional security step.

● It is like doubling up the guards outside the gate!

Page 12: Tips for a secure wordpress website

Deny Multiple Login Attempts● Hackers often use the ‘brute-force’ technique using random usernames and

passwords.

● Track down the IPs used in such attacks and block them using the User Locker

plugin.

Page 13: Tips for a secure wordpress website

Hide Login Error Messages● Login error messages often offer much more information to a seasoned hacker to

study the vulnerabilities of your site. Hide it using the following code:

○ add_filter(‘login_errors’,create_function(‘$a’, “return null;”));

Page 14: Tips for a secure wordpress website

Hide Directories● Keeping all your directories visible and accessible to the hackers is a big threat.

Placing the following code in the .htaccess file would do it for you.

○ # Prevent folder browsing

○ Options All-Indexes

Page 15: Tips for a secure wordpress website

Database Security● WordPress uses MySQL database which is automatically created on your web

hosting server.

● The database password must be strong or else it would act as a weak link in your

site security.

Page 16: Tips for a secure wordpress website

Use SFTP● In place of using a FTP while uploading your files you can use a Secure FTP or SFTP.

● Here all your files would be encrypted and this discourages any attempts of

hacking.

Page 17: Tips for a secure wordpress website

Use an Anti-Virus● Installing an antivirus keeps your site secured against bots, viruses and malwares

that are floating all around in the Internet.

Page 18: Tips for a secure wordpress website

Be Careful While Cleaning Up● If you are cleaning up your site or database, you need to be careful about the

vulnerable information.

● So don’t leave behind files such as phpinfo.php, readme.html and SQL database

files.

Page 19: Tips for a secure wordpress website

Isolate Websites● While it is a common practice to use the same hosting account for multiple sites,

you should try and avoid this as much as possible as one site’s vulnerability affects

the others.

Page 20: Tips for a secure wordpress website

Backup Site● While all these measures should secure your site, you need to be prepared for a day

when the security is compromised.

● Backup your site using a robust plugin as this will allow you to restore the site in

case of an attack.

Page 21: Tips for a secure wordpress website

Hiring WordPress Developers

To keep your WordPress site secure, you must hire experts developers to manage your

website. ValueCoders provides remote, dedicated developers on monthly rolling

contracts. The teams provide expert solutions to all kinds of requirements related to

WordPress and a host of other technologies.

Page 22: Tips for a secure wordpress website

Get in Touch

[email protected]

www.facebook.com/valuecoders

www.twitter.com/valuecoders

www.linkedin.com/company/valuecoders

IND: +91 859 535 5175 1000 - 2130 HRS IST

www.valuecoders.com