Showing posts with label WORDPRESS SECURITY. Show all posts
Showing posts with label WORDPRESS SECURITY. Show all posts

Monday, 9 December 2019

WORDPRESS SECURITY GUIDE: 14 PRO TIPS TO SECURE A WORDPRESS WEBSITE

WORDPRESS SECURITY GUIDE: 14 PRO TIPS TO SECURE A WORDPRESS WEBSITE

WordPress Security
Looking to improve the security of your WordPress website?
Here I’m sharing all the tips and strategies that I have learned running this award-winning WordPress blog.
Just to let you know,
In recent times, WordPress has been highly targeted by hackers. A lot of users has asked, “Is WordPress secure?”
and here is my answer:
Yes, WordPress is secure.
However, when we use various plugins, themes and some time it’s the hosting, which follows security worst-practices and thus makes our WordPress website vulnerable to different kind of attacks and hacks.
Fact: WordPress powers around 33% of the websites in the world, which not only makes it the most popular CMS platform but also is more prone to hacking. If this is your first time here, do check out WordPress guide for Beginners.
As an end-user, there are a few things you can do to secure WordPress blog.
Also read: Best WordPress security plugins (Opens in a new tab)
My site has been hacked nearly 2 times in the past by some Arabian and Turkish hackers (at least that’s what they claim). They infiltrated my site and left it with an ugly black background featuring GIF images of skulls and ravens. This is what made me find out how I could harden WordPress security.
Over the period of 10 years, I have learned many tricks which I’m sharing with you today so that you don’t have to face the hassle of losing your WordPress website in the hands of hackers.

If WordPress is safe the why WordPress security is crucial?

As I mentioned above, WordPress is secure by default but when you host it on an unsecured server or when you add new codes in the form of themes and plugins, you are increasing the possibilities of getting hacked.
As this help page on hardening WordPress adds
The vulnerabilities most affecting WordPress website owners stem from the platform’s extensible parts, specifically plugins and themes. These are the #1 attack vector being exploited by cyber-criminals to hack and otherwise misuse WordPress sites.
These vulnerabilities are usually not introduced intentionally, they are a result of mistakes and oversights during development. Many plugin and theme developers are not highly versed in security, and so they are prone to inadvertently write vulnerable code. As vulnerabilities are discovered, developers usually address them by releasing updates
Hackers usually hack a WordPress site for the personal gain, which is usually in the form of adding backlinks to some spammy sites or redirecting a WordPress site to other websites. Sometimes it’s done so sophisticatedly that you would not even know you are hacked or there is a backdoor installed on your website.
However, the owner starts losing the traffic over time (SEO penalty) and by the time they realize the real issue, things are way out of their hands.  Another worse that could happen is getting blacklisted by a prominent blacklist authority. This will cost you a significant amount of time and money to get your website out of blacklist.
According to security firm Sucuri,
of all the CMS they cleaned in 2018,  WordPress tops the infected CMS with 90%.
Infected Websites Platform
That’s some scary numbers for any WordPress owner and this is why it’s utmost important for you to roll your sleeve and follow these best practices to enhance WordPress security.

14 Proven Tips To Secure WordPress Blog

1. Configure WordPress Backups

Even though I have given a lot of proven tips below to secure your WordPress blog, you need to ensure that if something happens, you won’t lose anything.
Not having a proper WordPress backup solution in place is the biggest mistake you can make. When a big site like Sony or Dropbox can be hacked, your WordPress blog will be relatively easy to be cracked by a hacker.
So the first thing is to ensure you are taking a daily backup of your blog.
You can use the backup system offered by your hosting company or use a 3rd party backup system such as VaultPress or Updraftplus. You can find a list of WordPress backup plugins here.
If your hosting company offers backups, ensure they store the backup on a different server.

2. Use A Reliable & Secure Hosting Company

Server level security
Your WordPress installation is just software installed on a server. The foundation of a secure website is a server which has enough protections that ensure your website is safeguarded against hackers.
A secure WordPress hosting usually has:
  • Server level firewall to mitigate DDOS attacks.
  • Uses the latest hardware and top-notch data center for physical security
  • Regularly update the Operating system and apply the latest security patches
  • Has intrusion detection systems for malicious activity or policy violations
I understand that it’s hard to know which hosting company is reliable against hackers & that’s why I have created this list of secure WordPress hosting companies:
  1. SiteGround: An award-winning hosting that uses anti-bot AI system to prevent some well-known attacks.
  2. Bluehost: One of the top rated hosts which offers great security.
  3. WPEngine: A managed WordPress hosting company which is recommended for business WordPress sites. They offer backups and security on multiple levels.
  4. Kinsta hosting: This one is perfect for WordPress blog with high traffic. ShoutMeLoud.com is also hosted on Kinsta hosting.
If your existing hosting company is not secure and provide no security-related support, moving to any of the above-listed hostings will make a huge difference.

3. Use the Latest version of WordPress

Keeping your WordPress software up to date is the most basic security tip for any WordPress blogger. This is something that you never want to miss.
Whenever WordPress is sending an update, it means that they have fixed some bugs, added some features, and most importantly, added some security features and fixes.
WordPress Updates
When you see the message: “WordPress x.x.x is available!”
Update it.
Nowadays, with one click updates, it’s very easy to upgrade your blog.
Make sure your theme and plugins are compatible with this latest version of WordPress. If an update has been rolled out and it’s not a security update, I suggest you wait for 5-6 days before other users stop reporting bugs in the latest version.

4. Update WordPress Plugins

Update WordPress plugins
As I mentioned above, WordPress releases an update to fix bugs and security holes, and the same goes with plugins.
Many times, a vulnerable plugin or 3rd party script can create a security hole in your WordPress website.
One such issue which we have seen in the past is the Timthumb vulnerability. This was because of a script, and many plugins which were using this script became vulnerable too. Such kind of Zero-day vulnerability is hard to avoid, but by limiting the number of plugins, scripts, and themes you can make WordPress site more secure.
Always use plugins which are continually updated and have good support. If you are using a plugin which has not been updated for a while, find an alternative to it.

5. Use Latest PHP version

PHP is the backbone of WordPress and currently, the 7.3 is the latest version of PHP. According to the official PHP stats page, they offer security support to any stable version of PHP for 2 years only.
Latest PHP version
That means if you are using anything below PHP 7.1, you are not going to get security updates.
Here is an interesting stat from WordPress.org, about 71.8% of the WordPress website are using outdated PHP.
PHP Versions
Depending upon the hosting environment you are using, you can quickly change your PHP version. I strongly recommend you to first create a staging environment and then test the latest PHP version. This is to ensure the compatibility as at times, outdated plugin and theme could cause an issue.
You can check the PHP version of WordPress from the dashboard and ask your hosting support to test and update your PHP version. Bluehost users can follow this tutorial to update PHP version on cPanel.

6. Use Web application firewall (WAF)

A firewall exists between your hosting server and network traffic. The role of the firewall is to filter out the most common threat before it reaches the machine your WordPress website is hosted.
There are three most common types of firewall solution that you can use on WordPress:
  1. At the network level: This is usually stored on the network level or machine level and works when you are hosting WordPress at a data center you own. This is the costliest option and usually used by an enterprise-level website where they have control over the physical space where the server is installed.
  2. At the host level: This is hosted on the web-application level, in our case it’s WordPress. This is not recommended as eventually, your host has to do the heavy lifting of filtering out the traffic. This is definitely better than a network-based WAF but the local server resources it requires, it’s not the best option.
  3. Cloud-based WAF: Cloud-based WAF are usually implemented at DNS level and it filters the most common type of threats before it even hit your WordPress server. This is the easiest one to implement and most economical in sense. The only downside is, it may require you to change the DNS.
Some common type of threat which is detected and protected by WAF are: Cross-site scripting (XSS) attacks, SQL injection attacks, session hijacking, and buffer overflows. This is a protocol level 7 defense in the OSI model.
There are two recommended services that you can use to implement WAF:
This is a highly recommended WordPress security feature for WooCommerce and other WordPress websites which is made for business.

7. Hide WordPress Version

Let’s assume you don’t have those 2 minutes to update your WordPress core files. The listed WP version can spark an idea for a hacker to break in. If you are running an older version of WP and everyone knows it, trust me, you are doomed.
Most theme designers these days get rid of it for you, but just to make sure, go to your functions.php and add this line:
<?php remove_action(‘wp_head’, ‘wp_generator’); ?>

8. Use A Complex Login Password

I shouldn’t have to mention this, but I know too many people who use ingenious and insanely complex passwords like:
  • password
  • ilovejesus
  • 123123
Brilliant.
Please make your passwords complex, add a couple of special characters (%&*#), and keep changing it every 5 or 6 months.
I would also like to recommend a plugin called Login Lockdown. This plugin will record all IPs and time stamps of failed login attempts. After a specific number of failed attempts from a particular IP, the IP will be blacklisted. This helps a lot to prevent any brute-force attack.
At your end, you should also start using a password manager like Dashlane that will help you further improve your password security.
Also, read:

9. Change WordPress Login URL:

By changing the WordPress login URL page, you are preventing a lot of attacks and hacking attempt. Especially, if you are someone who has a handful of people or just you need to login to WordPress dashboard, changing login page will offer a great deal of help. There are a few added benefits that find it in my earlier tutorial on how to change the WordPress admin login URL.

10. Set Google alert for indexed pages

This is one of the less known tricks that you can use right away. You can use Google alerts to send you an alert whenever Google indexes a new page on your domain name. A lot of time, WordPress hackers adds new pages and posts which are not shown in the backend or frontend, but it gets indexed in Google.
When you set an alert like this, you would know if something is happening without your notice. Since it’s free and takes only 2-3 minutes to set it up, it’s totally worth it.
Here is how you can do it
  • Head over to Google alerts
  • In the “create an alert about” field, add site:domain.com
Alerts
  • Change How often to “as it happens”,  language to “any language” and how many to “all results’
Now, you will get instant notifications when a new page is indexed in the search engine.

11. Check WordPress Folders File Permissions

WordPress file Permissions
Go to the File Manager in your cPanel, or log in to your FTP software, and check the file attributes of your WordPress folder.
It’s good if it’s 744 (read only). If you find it to be 777, consider yourself extremely lucky that you haven’t gotten hacked yet.
When most bloggers change hosting, they don’t realize how their file permissions also get changed. Make sure you verify all file permissions after migrating your hosting.

12. Delete Default Admin User

This is one of the most crucial tips for people who are looking to create a secure WordPress blog. The default “admin” username is prone to brute-force attacks because most people never change it.
When you install WordPress, make sure you use a custom username and do not use “admin”.
You can create a new user with “Administrator” rights, and give this new administrator a nickname that will be publicly displayed in case he/she writes a post. Now, log out and then log back into the newly created admin account and delete the old “admin” user.
Make sure you attribute all usernames and links to the new user which you have created.
Here is an alternative way to change the default username:

13.  Hide The Plugins Directory

The plugins folder /wp-content/plugins/ should not be showing the list of folders and files inside of them.
Try visiting your plugins folder (replace domain.com with your domain name):
  • domain.com/wp-content/plugins/
If you see a list of folders and files, you need to hide them.
To hide these folders, you need to create a new .htaccess file and drop it in your plugins directory.
# BEGIN WordPress
RewriteEngine On
RewriteBase /
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
# Prevents directory listing
IndexIgnore *
# END WordPress
If you already have a well written .htaccess file in your root directory, adding a separate .htaccess to an individual folder is not going to cause any harm.
Also, take a look at this post for a better understanding of how to edit the .htaccess file.

14. Turn Off Database Errors

In older versions of WordPress, if there were errors in the MySQL database, it would show the exact error on the browser itself giving the hacker valuable information about your database.
To prevent this, you need to update your WordPress to the latest version, so that it will only show a general error message like “Database connection error” instead of showing exactly what’s wrong
Log in to your WP dashboard and update your WordPress core files.

WordPress Security: Over to you

Well, I hope this guide helped you to understand the importance of WordPress security and helped you harden it.
Again, it’s a wise idea to take automatic backups of your WordPress blog at regular intervals to make sure you can always roll back your blog to a healthy condition.
Do let us know what other security tips you would like to give to other bloggers to keep their WordPress blog secure. Share your tips in the comments below!
Don’t forget to bookmark and share this post!
For further reading:

9+ BEST WORDPRESS SECURITY PLUGINS TO PROTECT WORDPRESS BLOG (2020)

9+ BEST WORDPRESS SECURITY PLUGINS TO PROTECT WORDPRESS BLOG (2020)

best wordpress security plugin
WordPress is a PHP and database-based CMS which is often targeted by hackers. However, there are many WordPress plugins out there which are useful in preventing WordPress hacking.
Therefore, I have created a list of the Top WordPress Security Plugins which will help you protect your blog from hackers.
This article focuses on the popular security plugins that your WordPress blog website needs to have to prevent hacking or spamming activities and improve the security system.
One way to protect your blog is by implementing security measures from day one, you can always use .htaccess method to hardened your security, but as we know WordPress is full of plugins and here I’m sharing some of the best WordPress security plugins, which will help you to make your blog more secure.
As Harsh has discussed earlier, using too many plugins may hamper down your site performance, I recommend you to read the description and use only a few of these plugins that you need.
Though, some of the plugins listed below like Login Lockdown and Akismet are one of those security plugins, which I highly recommend you to Install.
Apart from these plugins, I recommend you to read following posts that will help you to harden your blog security further:

Best WordPress Security Plugins to Improve Security:

As we say, prevention is better than cure, and the same is with WordPress security. WordPress is a PHP and MySQL based system, and it’s vulnerable to hack attempt, so make sure you set up a proper backup system to take backup of your database and wp-content folder regularly.

1. Sucuri Security WordPress plugin (Free + Paid option)

With more than half a million downloads, “Sucuri Security – Auditing, Malware Scanner and Security Hardening” is the top security plugin for WordPress. There is a free version and a paid option also available. For most of the basic WordPress site, the free version is good enough and offer great protection.
The plugin comes with plenty of options including options to integrate with Sucuri web application firewall which is active monitoring of your WordPress site health.
Once you have installed an activated the plugin, you can start by configuring the settings.
Here are features of the plugin:
  • Security Activity Auditing
  • File Integrity Monitoring
  • Remote Malware Scanning
  • Blacklist Monitoring
  • Effective Security Hardening
  • Post-Hack Security Actions
  • Security Notifications
  • Website Firewall (premium)
  • Away mode ( Disable access to the WordPress Dashboard when on vacation)
Most of the security checklist gets activated automatically when you use the security check feature.

2. SecuPress

“DON’T REMAIN DEFENSELESS!” That’s the motto of SecuPress. As you are done installing SecuPress plugin, it will let you run the security scanner and generate a security report of your WordPress website.
As you can see in the screenshot above, it grades the site based on current security settings.
Here are a few things you can find out from the first scan itself:
  • Outdated plugins
  • Reminder to delete deactivated plugins
  • Security suggestions for wp-config.php
  • Security key settings
  • Status of wp-admin/install.php
  • Users and login status
  • WordPress core tweaking
  • Malware Scan
  • Firewall scan
Everything is shown in a beautiful way under different modules. You can click on any module settings to make changes and make your WordPress anti-hack.
This is perhaps most beginner friendly security plugin for WordPress out there.

3. iThemes Security Pro ($80)

iThemes Claimed to be this one as a trusted WordPress security plugin. This plugin offers a comprehensive security dashboard for you to monitor your WordPress website security status. Another feature that I loved about iThemes security pro is Security grade report.
This is super useful for anyone who is offering WordPress security services and can quickly scan the website to create a report of the current security level.
Features:
  • One-click “Secure Site” WordPress security check
  • Ban bad users and I.P
  • Hide login and Admin URL
  • Rename admin account
  • Change the WP-content path
  • Brute force protection
  • Logs of security
  • File permission and integrity check
  • Get a notification when a file is updated
  • Two-factor authentication
  • Many more… (Check here)
All things considered, this is indeed an awesome plugin. The only thing which I feel it lacks is firewall and that you need to complement with another service like Sucuri or Cloudflare. If you don’t need a Firewall, then this is the only security plugin you need for WordPress.

4. All in one Security plugin and Firewall

At the time of writing, this is the most downloaded and well-maintained plugin for improving your WordPress security. The plugin offers all essential features such as :
  • Login lock down
  • Security strength meter
  • System info
  • Firewall
  • Backup Wp-config file
  • Force user logout
  • Account activity logs
  • Enable manual approval of new registrations:
  • Change database default prefix of WP (A highly recommended WordPress database security setting)
  • Check and improve file system permission
  • Block IP or IP range as well as user agents.
  • Block external access to XMLRPC
  • View last file change (Useful to find hacked WordPress files post hack)
And then there are many more features. If you are looking for a standalone security plugin, All In One WP Security & Firewall WordPress plugin is the best option.

5. Jetpack Security

If you have been using WordPress for a while, you must have heard of Jetpack plugin. It’s a multi-purpose WordPress plugin by the same team behind WordPress.
They are constantly adding new features and one of the well-developed plugins in the whole WordPress ecosystem. There are a few features of Jetpack plugin that you should use to keep the bad guys away from WordPress.
The free version has limited features, but it’s the premium plan that cost about $84/year is something you should subscribe to.
Here are those modules:
  • Protection from Brute force attack
  • Downtime monitoring
  • Jetpack Backups
  • Security scanning
The daily, automated scanning ensure your WordPress files are clean from any infected code.  Apart from the security feature, the backup feature alone makes it worth the investment. You should know, Jetpack is part of best WordPress plugins.

6. Login LockDown

login lockdown WordPress plugin
Brute force attack is the most common type of attack a WordPress site gets and login lockdown is the simplest plugin that you can use against brute force attack. What this plugin does is; it logs the login attempt to your site and if too many failed login attempt made from the same I.P within 5 minutes, it will block access of that I.P. for next one hour.
You can always configure and change the time to match your requirement. But before you install this plugin I would suggest the look at other mentioned options, as other WordPress security plugins offer more options along with limit login option.

7. Restricted Site Access

If you intend to restrict access for users/ visitors on one part of your website, then add this plug-in to your blog. For example, you can restrict one part of your website for parallel development or testing. Adding this plug-in will help you handle unwanted visitors to your blog or site as you can define the visibility settings for the same.
Restricted site access implies that visitors who are not logged in to your or allowed by IP address will not able to browse your site. You can a re-direct them to a custom location or display a message, or send them to the login page.
WordPress restricted site
You will also be able to add a range of imp addresses as well as yours to an unrestricted list. The re-direct location can be any path of your choice, choose to send the visitor to the same path and set the HTTP status code to facilitate a friendly search engine.
<Download plugin>

8. BulletProof Security

BulletProof security
BulletProof Security plug-in is the ultimate plug-in that uses .htaccess website security files to protect your root website folder and wp-admin folder and also provides additional website security protection. The different security modes are Root .htaccess security protection, wp-admin .htaccess security protection, Deny All .htaccess self-protection, WordPress default .htaccess mode and .htaccess Maintenance Mode (503 Website under Maintenance).
When you would like to work on your website, use the BPS maintenance mode and allow only yourself to access your WordPress Dashboard or add specific IP addresses that can also access your Dashboard in maintenance mode.
In BulletProof Security Mode, your WordPress website is protected against XSS, RFI, CRLF, CSRF, Base64, Code Injection and SQL Injection hacking.
<Download BP security plugin>

9. Akismet

Akismet
Akismet fights against comment and trackback spam and keeps your blog secured through its Akismet web service. To use this plug-in, you need an API key that you can get from Akismet.com.
A comment status history is where you can list of comments that were found as spam. If any comment has a missing link or a hidden link, they will be highlighted, and you will get more information from the spam and Unspam reports.
<Download Akismet>

Conclusion: Which WordPress security plugin is best for you?

Noe one size fits all and similarly, not every plugin is right for you. You should pick one based on the hosting, your architect and threat level to your site. The basic security is recommended for every WordPress website, but for someone who is into a niche where the attacks are quite common, hardening the security should be taken seriously.
  • Evergreen and reliable: Sucuri security, Jetpack, iThemes security
  • Beginner Friendly: SecuPress
  • Free WordPress security plugin: Sucuri security (free), All in one Security plugin and Firewall
  • Two-factor authentication: iThemes Security Pro or Google authenticator
WordPress community has a plugin database of more than 34000+ plugins ranging from security to adding widgets. Choose to add only those WordPress security plugins that will keep your WordPress site a safe and secure free from virus and hackers.
I hope you enjoyed reading my choice of best WordPress security plugins, and if you believe I missed something do let me know via comments.
If you find this article useful, don’t forget to share it on Facebook and check ShoutMeLoud WordPress guide for more such articles.