Thread: WordPress Security
07-05-2016, 03:05 PM #1
Due to the popularity of WordPress it is often the target of hackers. It is a common misconception that WordPress is not a secure content platform but when managed correctly you should not have any security issues. This guide will provide you with all the information you need to keep your WordPress secure.
Brute Force Protection
Many WordPress attacks are done by trying to login to your admin area using many different passwords until they get a match. This is easily combated by using a brute force protection plugin, it will block access from the attacker's IP address for a period of time, blocking them from continuing to attack your site. You can even blacklist repeated offenders. The Brute Force Protection plugin is recommended.
Attackers can force access to your site by exploiting bugs in old versions of WordPress, plugins and themes which have not been updated. It is recommend you update your WordPress installation when a new release is issued and keep your plugins and themes updated to the latest version. Keeping your WordPress updated is easy and only takes a few clicks when updates are available.
07-05-2016, 03:22 PM #2
07-05-2016, 03:28 PM #3
Those tools could be useful for hackers yes.
An alternative to the brute force plugin would be to block access to WordPress admin page by using .htaccess to require a password to proceed to your admin login page.
This solution can also be used with a brute force plugin for an additional layer of security.
07-05-2016, 03:44 PM #4
A very good post about WordPress security at KeyCDN blog here
But to answer to the thread, you should use a software solution like fail2ban instead of a plugin, as each plugin can be another security breach.
07-06-2016, 04:14 AM #5
Thanks LJSHost for cool post!
I would add a way to secure your wordpress site is block your wp-admin by htaccess file or protecting it by a function in your hosting control panel manager and just allow your IP address access it.
07-06-2016, 10:47 AM #6
One of the major things that each wordpress owner should do is change the login directory to a very long and random string. this will prevent the finding of the admin panel in the first place or at least make it much much harder.
07-06-2016, 01:14 PM #7
If you host your website on a vps or dedicated server install config server firewall and comodo WAF ruleset. This will help preventing a lot of attacks.
07-09-2016, 04:02 PM #8
07-09-2016, 04:14 PM #9
Application layer and Operating systems layers are two different things but they do share the same brute force security solutions,
If a VPS has its own firewall this will block access to repeated login attempt's to mail and other system services, but access control to an application such as wordpress requires it's own security, as others have also said it's best double up the security using .htaccess controls also.
08-26-2016, 01:23 AM #10
Also, thanks for sharing the Brute Force plugin. I wasn't aware of that particular one myself.
09-01-2016, 04:29 AM #11
Great post LJSHost!, But i don't think that most of newbie cares about there website security that much as they tries to earn money through it
10-09-2016, 05:51 PM #12
Nice post, basically Wordpress is secured but theme and plugins used in Wordpress caused problem, therefore be careful while using any new theme or plugins and try to install unwanted themes and plugins.
01-12-2017, 07:13 AM #13
I have had some brute force attacks a couple of years ago and they kept happening a couple times a month or so. Finally I decided to use .htaccess to only allow access to it from my IP and not from other IP's.
This has worked great for stopping the attacks and it's easy to implement, even for people that are new and don't understand many aspects of websites including the .htaccess file.
By bknights in forum VPS HostingReplies: 8 | Views: 1149Last post by VirtuBox, 07-09-2016, 06:25 PM
Replies: 2 | Views: 477Last post by ExpertHosters, 07-06-2016, 12:50 PM
By Steve32 in forum Running a Web Hosting BusinessReplies: 21 | Views: 3220Last post by Kieran2001, 03-26-2017, 11:34 PM
By theshri in forum Web Hosting RequestsReplies: 7 | Views: 1082Last post by peteynessx, 09-02-2016, 11:32 PM
Replies: 17 | Views: 4795Last post by Kieranlewix, 09-24-2017, 10:03 AM
Replies: 21 | Views: 4529Last post by jwn, 12-11-2016, 07:26 PM
By AliGibbs in forum Internet MarketingReplies: 2 | Views: 635Last post by taanya, 08-02-2016, 06:54 AM
Replies: 8 | Views: 1165Last post by amberhuntus, 09-23-2016, 12:14 PM
By web3k in forum Reseller Hosting OffersReplies: 0 | Views: 713Last post by web3k, 07-04-2016, 10:04 PM
By web3k in forum Shared Hosting OffersReplies: 0 | Views: 467Last post by web3k, 07-04-2016, 10:03 PM
By HostColor in forum Shared Hosting OffersReplies: 0 | Views: 12Last post by HostColor, Today, 10:48 AM
Replies: 0 | Views: 13Last post by Lene, Today, 06:18 AM
Replies: 0 | Views: 14Last post by pau18, Today, 12:12 AM
Replies: 1 | Views: 20Last post by 24x7serverman, Today, 05:59 AM
Replies: 2 | Views: 29Last post by LJSHost, Today, 02:02 PM
Replies: 0 | Views: 681Last post by meetdilip, 04-19-2016, 07:00 PM
By Mihai B. in forum Hosting Security and TechnologyReplies: 3 | Views: 743Last post by meetdilip, 04-19-2016, 06:56 PM
By arronmattwills in forum Web HostingReplies: 11 | Views: 1117Last post by SenseiSteve, 01-13-2016, 10:21 PM
Replies: 5 | Views: 1247Last post by ron13315, 04-28-2015, 01:17 PM
Replies: 1 | Views: 1001Last post by Holly Nicole, 03-08-2013, 02:53 PM