{"id":236,"date":"2018-01-25T04:49:19","date_gmt":"2018-01-25T04:49:19","guid":{"rendered":"http:\/\/99techpost.com\/?p=236"},"modified":"2022-01-09T12:12:18","modified_gmt":"2022-01-09T12:12:18","slug":"wordpress-security-101","status":"publish","type":"post","link":"https:\/\/www.99techpost.com\/wordpress-security-101\/","title":{"rendered":"WordPress Security 101"},"content":{"rendered":"<p>WordPress is one of the most commonly used Content Management Systems (CMS). More than 70 million websites, from almost every industry, depend on it.Unfortunately, many WordPress users overlook the topic of security.<\/p>\n<p>Every website owner is responsible for the security of their website and data.Google blacklists almost 100,000 websites for malware or phishing attacks every week. As such, we\u2019ve covered the most important information about WordPress security and the best practices on how you can strengthen it and make your website even more secure.<\/p>\n<p>Are you ready to protect your website in 2022? Then let\u2019s get to it!<\/p>\n<h4>WordPress Security in General<\/h4>\n<p><a href=\"https:\/\/premium.wpmudev.org\/blog\/is-wordpress-secure\/\" target=\"_blank\" rel=\"nofollow\">WordPress is considered secure<\/a> as it is maintained and updated regularly. However, hackers also update their methods regularly, so security breaches can happen at any time. Fortunately, even if you aren\u2019t a tech-savvy security professional, you can still do a lot to improve the security of your WordPress site, increase its privacy and reduce the risk of it being hacked.<\/p>\n<p>In this guide, we discuss methods ranging from the very basics to advanced safety techniques.<\/p>\n<p><a href=\"http:\/\/99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-2.jpg\" target=\"_blank\"><img decoding=\"async\" class=\"aligncenter wp-image-238 size-full\" src=\"http:\/\/99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-2.jpg\" alt=\"\" width=\"605\" height=\"408\" srcset=\"https:\/\/www.99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-2.jpg 605w, https:\/\/www.99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-2-300x202.jpg 300w, https:\/\/www.99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-2-435x293.jpg 435w\" sizes=\"(max-width: 605px) 100vw, 605px\" \/><\/a><\/p>\n<h4>Basic Security Measures<\/h4>\n<ul>\n<li>Use reliable antivirus\/antimalware software and run scans on a regular basis \u2013 at least once a week.<\/li>\n<li>Enable your computer\u2019s firewall and configure it properly. If you don\u2019t have a firewall, then install one.<\/li>\n<li>Don\u2019t log into your control panel or WordPress admin dashboard through an unsecure internet network or over public Wi-Fi.<\/li>\n<li>Use <a href=\"https:\/\/www.howtogeek.com\/195430\/how-to-create-a-strong-password-and-remember-it\/\" target=\"_blank\" rel=\"nofollow\">strong and various passwords<\/a> for your site. Include capitals, letters, numbers and other marks, withat least 8-10 characters.<\/li>\n<li>Don\u2019t use \u201cadmin\u201d as a username. It\u2019s very common and unsecure.<\/li>\n<li>Keep yourself up-to-date about the newest threats, security steps and methods.<\/li>\n<\/ul>\n<h2><a href=\"http:\/\/99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-3.jpg\" target=\"_blank\"><img decoding=\"async\" class=\"aligncenter wp-image-239 size-full\" src=\"http:\/\/99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-3.jpg\" alt=\"\" width=\"598\" height=\"426\" srcset=\"https:\/\/www.99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-3.jpg 598w, https:\/\/www.99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-3-300x214.jpg 300w, https:\/\/www.99techpost.com\/wp-content\/uploads\/2018\/01\/wordpress-security-3-435x310.jpg 435w\" sizes=\"(max-width: 598px) 100vw, 598px\" \/><\/a><\/h2>\n<h4>More Advanced WordPress Security Practices<\/h4>\n<h4>1.\u00a0\u00a0\u00a0 Enable Two-factor Authentication (2FA)<\/h4>\n<p><a href=\"https:\/\/www.wpwhitesecurity.com\/wordpress-plugins\/best-two-factor-authentication-plugins-wordpress\/\" target=\"_blank\" rel=\"nofollow\">Two-factor authentication<\/a> is one of the best ways to provide secure access andprevent hackers getting into your site and\/or database. This is an essential part of keeping your accounts safe.<\/p>\n<h4><b>2.\u00a0\u00a0<\/b>Enable HTTPS to WordPress site<\/h4>\n<p>HTTPS is a HyperText Transfer Protocol with Secure Sockets Layer (SSL) used to authenticate website and its associated with web server in order to provide protected communication over the Internet. So, SSL certificate is especially utilized on a website to keep confidential data secure such as Email ID, Password, Bank details etc. To convert the site from HTTP to HTTPS, WordPress user to needs to purchase SSL certificate and installed it on a Web server. Now, You can obtain <a href=\"https:\/\/www.cheapsslshop.com\/comodo\" rel=\"external nofollow\" target=\"_blank\">Comodo SSL<\/a> Certificates with 1-3 years validity with warranty at cheapest price from an authorized reseller.<\/p>\n<p>Once you enable HTTPS to your existing WordPress site, you can fix &#8220;Not secure&#8221; warning in the web address bar of Google Chrome. Even you can secure WordPress Login and admin area with SSL 256-bit encryption.&#8221;<\/p>\n<h4>3.\u00a0\u00a0\u00a0 Limit Login Attempts<\/h4>\n<p>There are many brute force attacks and bot attacks that can break into a website. By limiting your number of login attempts, you can prevent hackers making multiple attempts to log into your admin dashboard. There is a default option for this when you install WordPress; make sure it is checkedduring the install process.<\/p>\n<h4>4.\u00a0\u00a0\u00a0 Be Careful with XML-RPC<\/h4>\n<p>XML-RPC is an API many plugins and themes use to help the connection of applications.It\u2019s been around for a while now. The problem is, it can amplify brute force attacks. Think twice about whether you really need it for your site and only enable it if you really need do.<\/p>\n<h4>5.\u00a0\u00a0\u00a0 Disable File Editing<\/h4>\n<p>WordPress has a built-in feature that allows users to edit codes. If a hacker gets access to it, it\u2019s the easiest way to do massive damage. You can disable it by going to Appearance \u2013 Editor and adding this code to your wp-config.php file:<\/p>\n<p>\/\/ Disallow file edit<\/p>\n<p>define( \u2019DISALLOW_FILE_EDIT\u2019 , true )<\/p>\n<p>That\u2019s it \u2013 you\u2019ve successfully disabled file editing in WordPress.<\/p>\n<h4>6.\u00a0\u00a0\u00a0 Disable PHP File Execution<\/h4>\n<p>Disabling PHP file executions where they\u2019re not needed is a good way to strengthen the security of your WordPress website. It\u2019s relatively easy to do:\u00a0 You can take the help of <a href=\"http:\/\/www.imensosoftware.com\/technologies\/php-application-development\/\" rel=\"external nofollow\" target=\"_blank\">PHP Web Development Company<\/a> to do it proper way.<\/p>\n<p>Open a text editor and paste the following code:<\/p>\n<p>&lt;Files *.php&gt;<\/p>\n<p>deny from all<\/p>\n<p>&lt;\/Files&gt;<\/p>\n<p>Next, you\u2019ll have to save it as a .htaccess file, then upload it to the \/wp-content\/uploads folder. Job done!<\/p>\n<h4>7.\u00a0\u00a0\u00a0 Create Backups Regularly<\/h4>\n<p>One of the most important steps you can take is to create backups on a schedule. In case of any trouble with your site, you can use a backup to restore the entire site, as well as your whole database. When you make a backup, make sure you <a href=\"https:\/\/codex.wordpress.org\/Hardening_WordPress#Data_Backups\" target=\"_blank\">create a backup<\/a> of your site, your WordPress installation and your MySQL databases.There are ways to automate your backups, for example by using <a href=\"https:\/\/ithemes.com\/purchase\/backupbuddy\/\" target=\"_blank\" rel=\"nofollow\">BackupBuddy<\/a>. Thissolution enables you to make the most of your WordPress backups.<\/p>\n<h4>8.\u00a0\u00a0\u00a0 Use the MostTrusted Security Plugins<\/h4>\n<p>There are plenty of plugins that can add extra layers of security to your site, so don\u2019t be afraid of using them. However, be careful when you choose security plugins \u2013 only install the most trusted ones. Luckily, you can easily find reviews and comparisons of the best plugins for WordPress. For example, WordFence is a no-brainer when it comes to security. You can download it for free with the most important features included. It also has a premium version, which is definitely worth the investment. Sucuri is also one of the most recommended plugins for keeping your WordPress site safe and secure.<\/p>\n<h4>9.\u00a0\u00a0\u00a0 <a href=\"https:\/\/www.ipburger.com\/pricing\/vpn\/\" target=\"_blank\" rel=\"nofollow\">Secure Your Network<\/a><\/h4>\n<p>A secure network connection is just as important as the security of your site. Having a reliable VPN with <a href=\"https:\/\/vpnalert.com\/best-virtual-private-network\/country\/cyprus\/\" target=\"_blank\" rel=\"nofollow\">good services to protect your privacy<\/a> can add an extra layer of security with encryption to your network. A safe network connection can protect your site from hackers and other forms of unauthorized access. Here are more <a href=\"https:\/\/www.top50vpn.com\/vpn-guides\/benefits-of-vpn\" target=\"_blank\" rel=\"nofollow\">VPN benefits<\/a> for you to find out.<\/p>\n<h4>Conclusion<\/h4>\n<p>You are responsible for the security of your site and the data stored within it. By implementing these security-enhancing steps, you can make sure your WordPress site is safe to use.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress is one of the most commonly used Content Management Systems (CMS). More than 70 million websites, from almost every industry, depend on it.Unfortunately, many WordPress users overlook the topic &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"WordPress Security 101\" class=\"read-more button\" href=\"https:\/\/www.99techpost.com\/wordpress-security-101\/#more-236\">Read More<span class=\"screen-reader-text\">WordPress Security 101<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":237,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-236","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-wordpress","no-featured-image-padding"],"_links":{"self":[{"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/posts\/236","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/comments?post=236"}],"version-history":[{"count":0,"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/posts\/236\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/media\/237"}],"wp:attachment":[{"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/media?parent=236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/categories?post=236"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.99techpost.com\/wp-json\/wp\/v2\/tags?post=236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}