Thread: WordPress Security
07-05-2016, 03:05 PM #1
Due to the popularity of WordPress it is often the target of hackers. It is a common misconception that WordPress is not a secure content platform but when managed correctly you should not have any security issues. This guide will provide you with all the information you need to keep your WordPress secure.
Brute Force Protection
Many WordPress attacks are done by trying to login to your admin area using many different passwords until they get a match. This is easily combated by using a brute force protection plugin, it will block access from the attacker's IP address for a period of time, blocking them from continuing to attack your site. You can even blacklist repeated offenders. The Brute Force Protection plugin is recommended.
Attackers can force access to your site by exploiting bugs in old versions of WordPress, plugins and themes which have not been updated. It is recommend you update your WordPress installation when a new release is issued and keep your plugins and themes updated to the latest version. Keeping your WordPress updated is easy and only takes a few clicks when updates are available.
07-05-2016, 03:22 PM #2
07-05-2016, 03:28 PM #3
Those tools could be useful for hackers yes.
An alternative to the brute force plugin would be to block access to WordPress admin page by using .htaccess to require a password to proceed to your admin login page.
This solution can also be used with a brute force plugin for an additional layer of security.
07-05-2016, 03:44 PM #4
A very good post about WordPress security at KeyCDN blog here
But to answer to the thread, you should use a software solution like fail2ban instead of a plugin, as each plugin can be another security breach.
07-06-2016, 04:14 AM #5
Thanks LJSHost for cool post!
I would add a way to secure your wordpress site is block your wp-admin by htaccess file or protecting it by a function in your hosting control panel manager and just allow your IP address access it.
07-06-2016, 10:47 AM #6
One of the major things that each wordpress owner should do is change the login directory to a very long and random string. this will prevent the finding of the admin panel in the first place or at least make it much much harder.
07-06-2016, 01:14 PM #7
If you host your website on a vps or dedicated server install config server firewall and comodo WAF ruleset. This will help preventing a lot of attacks.
07-09-2016, 04:02 PM #8
07-09-2016, 04:14 PM #9
Application layer and Operating systems layers are two different things but they do share the same brute force security solutions,
If a VPS has its own firewall this will block access to repeated login attempt's to mail and other system services, but access control to an application such as wordpress requires it's own security, as others have also said it's best double up the security using .htaccess controls also.
08-26-2016, 01:23 AM #10
Also, thanks for sharing the Brute Force plugin. I wasn't aware of that particular one myself.
09-01-2016, 04:29 AM #11
Great post LJSHost!, But i don't think that most of newbie cares about there website security that much as they tries to earn money through it
10-09-2016, 05:51 PM #12
Nice post, basically Wordpress is secured but theme and plugins used in Wordpress caused problem, therefore be careful while using any new theme or plugins and try to install unwanted themes and plugins.
01-12-2017, 07:13 AM #13
I have had some brute force attacks a couple of years ago and they kept happening a couple times a month or so. Finally I decided to use .htaccess to only allow access to it from my IP and not from other IP's.
This has worked great for stopping the attacks and it's easy to implement, even for people that are new and don't understand many aspects of websites including the .htaccess file.
By bknights in forum VPS HostingReplies: 8 | Views: 455Last post by VirtuBox, 07-09-2016, 06:25 PM
Replies: 2 | Views: 184Last post by ExpertHosters, 07-06-2016, 12:50 PM
By Steve32 in forum Running a Web Hosting BusinessReplies: 15 | Views: 702Last post by HostXNow, 02-17-2017, 01:30 PM
By theshri in forum Web Hosting RequestsReplies: 7 | Views: 452Last post by peteynessx, 09-02-2016, 11:32 PM
Replies: 11 | Views: 1394Last post by Deacon Jones, 10-10-2016, 12:07 PM
Replies: 21 | Views: 3020Last post by jwn, 12-11-2016, 07:26 PM
By AliGibbs in forum Internet MarketingReplies: 2 | Views: 172Last post by taanya, 08-02-2016, 06:54 AM
Replies: 8 | Views: 494Last post by amberhuntus, 09-23-2016, 12:14 PM
By web3k in forum Reseller Hosting OffersReplies: 0 | Views: 288Last post by web3k, 07-04-2016, 10:04 PM
By web3k in forum Shared Hosting OffersReplies: 0 | Views: 147Last post by web3k, 07-04-2016, 10:03 PM
Replies: 8 | Views: 67Last post by DaRecordon, Today, 04:14 AM
By HosterDaddy in forum Content Management SystemsReplies: 0 | Views: 34Last post by HosterDaddy, Yesterday, 03:58 PM
Replies: 3 | Views: 46Last post by HosterDaddy, Today, 04:20 AM
Replies: 7 | Views: 79Last post by HosterDaddy, Yesterday, 08:22 PM
Replies: 0 | Views: 24Last post by HosterDaddy, Yesterday, 12:41 PM
Replies: 0 | Views: 322Last post by meetdilip, 04-19-2016, 07:00 PM
By Mihai B. in forum Hosting Security and TechnologyReplies: 3 | Views: 467Last post by meetdilip, 04-19-2016, 06:56 PM
By arronmattwills in forum Web HostingReplies: 11 | Views: 743Last post by SenseiSteve, 01-13-2016, 10:21 PM
Replies: 5 | Views: 797Last post by ron13315, 04-28-2015, 01:17 PM
Replies: 1 | Views: 732Last post by Holly Nicole, 03-08-2013, 02:53 PM
By Little Alien in forum Dedicated Server