Thread: WordPress Security
07-05-2016, 03:05 PM #1
Due to the popularity of WordPress it is often the target of hackers. It is a common misconception that WordPress is not a secure content platform but when managed correctly you should not have any security issues. This guide will provide you with all the information you need to keep your WordPress secure.
Brute Force Protection
Many WordPress attacks are done by trying to login to your admin area using many different passwords until they get a match. This is easily combated by using a brute force protection plugin, it will block access from the attacker's IP address for a period of time, blocking them from continuing to attack your site. You can even blacklist repeated offenders. The Brute Force Protection plugin is recommended.
Attackers can force access to your site by exploiting bugs in old versions of WordPress, plugins and themes which have not been updated. It is recommend you update your WordPress installation when a new release is issued and keep your plugins and themes updated to the latest version. Keeping your WordPress updated is easy and only takes a few clicks when updates are available.
07-05-2016, 03:22 PM #2
07-05-2016, 03:28 PM #3
Those tools could be useful for hackers yes.
An alternative to the brute force plugin would be to block access to WordPress admin page by using .htaccess to require a password to proceed to your admin login page.
This solution can also be used with a brute force plugin for an additional layer of security.
07-05-2016, 03:44 PM #4
A very good post about WordPress security at KeyCDN blog here
But to answer to the thread, you should use a software solution like fail2ban instead of a plugin, as each plugin can be another security breach.
07-06-2016, 04:14 AM #5
Thanks LJSHost for cool post!
I would add a way to secure your wordpress site is block your wp-admin by htaccess file or protecting it by a function in your hosting control panel manager and just allow your IP address access it.
07-06-2016, 10:47 AM #6
One of the major things that each wordpress owner should do is change the login directory to a very long and random string. this will prevent the finding of the admin panel in the first place or at least make it much much harder.
07-06-2016, 01:14 PM #7
If you host your website on a vps or dedicated server install config server firewall and comodo WAF ruleset. This will help preventing a lot of attacks.
07-09-2016, 04:02 PM #8
07-09-2016, 04:14 PM #9
Application layer and Operating systems layers are two different things but they do share the same brute force security solutions,
If a VPS has its own firewall this will block access to repeated login attempt's to mail and other system services, but access control to an application such as wordpress requires it's own security, as others have also said it's best double up the security using .htaccess controls also.
08-26-2016, 01:23 AM #10
Also, thanks for sharing the Brute Force plugin. I wasn't aware of that particular one myself.
09-01-2016, 04:29 AM #11
Great post LJSHost!, But i don't think that most of newbie cares about there website security that much as they tries to earn money through it
10-09-2016, 05:51 PM #12
Nice post, basically Wordpress is secured but theme and plugins used in Wordpress caused problem, therefore be careful while using any new theme or plugins and try to install unwanted themes and plugins.
01-12-2017, 07:13 AM #13
I have had some brute force attacks a couple of years ago and they kept happening a couple times a month or so. Finally I decided to use .htaccess to only allow access to it from my IP and not from other IP's.
This has worked great for stopping the attacks and it's easy to implement, even for people that are new and don't understand many aspects of websites including the .htaccess file.
By bknights in forum VPS HostingReplies: 8 | Views: 575Last post by VirtuBox, 07-09-2016, 06:25 PM
Replies: 2 | Views: 260Last post by ExpertHosters, 07-06-2016, 12:50 PM
By Steve32 in forum Running a Web Hosting BusinessReplies: 20 | Views: 1246Last post by HostaPolis, 03-11-2017, 07:16 AM
By theshri in forum Web Hosting RequestsReplies: 7 | Views: 558Last post by peteynessx, 09-02-2016, 11:32 PM
Replies: 14 | Views: 1976Last post by serverbundle, 03-07-2017, 03:05 PM
Replies: 21 | Views: 3269Last post by jwn, 12-11-2016, 07:26 PM
By AliGibbs in forum Internet MarketingReplies: 2 | Views: 239Last post by taanya, 08-02-2016, 06:54 AM
Replies: 8 | Views: 605Last post by amberhuntus, 09-23-2016, 12:14 PM
By web3k in forum Reseller Hosting OffersReplies: 0 | Views: 363Last post by web3k, 07-04-2016, 10:04 PM
By web3k in forum Shared Hosting OffersReplies: 0 | Views: 206Last post by web3k, 07-04-2016, 10:03 PM
By VirtuBox in forum Search Engine OptimizationReplies: 0 | Views: 13Last post by VirtuBox, Today, 10:54 AM
Replies: 1 | Views: 24Last post by HostBastic, Today, 06:55 AM
Replies: 2 | Views: 29Last post by David Beroff, Today, 02:22 AM
By Kaz Wolfe in forum Hosting Software and Control PanelsReplies: 2 | Views: 25Last post by LJSHost, Today, 01:04 PM
Replies: 0 | Views: 20Last post by reddyash, Yesterday, 08:18 AM
Replies: 0 | Views: 404Last post by meetdilip, 04-19-2016, 07:00 PM
By Mihai B. in forum Hosting Security and TechnologyReplies: 3 | Views: 546Last post by meetdilip, 04-19-2016, 06:56 PM
By arronmattwills in forum Web HostingReplies: 11 | Views: 802Last post by SenseiSteve, 01-13-2016, 10:21 PM
Replies: 5 | Views: 874Last post by ron13315, 04-28-2015, 01:17 PM
Replies: 1 | Views: 789Last post by Holly Nicole, 03-08-2013, 02:53 PM