{"id":214,"date":"2015-08-20T14:20:55","date_gmt":"2015-08-20T14:20:55","guid":{"rendered":"http:\/\/www.ahosting.net\/blog\/?p=214"},"modified":"2015-08-20T14:20:55","modified_gmt":"2015-08-20T14:20:55","slug":"the-all-inclusive-guide-to-securing-your-wordpress-installation","status":"publish","type":"post","link":"https:\/\/www.ahosting.net\/blog\/the-all-inclusive-guide-to-securing-your-wordpress-installation\/","title":{"rendered":"The All-Inclusive Guide To Securing Your WordPress Installation"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">As you well know, WordPress is the most popular content management system in the world. <\/span><a href=\"http:\/\/www.inquisitr.com\/1843518\/wordpress-platform-powers-23-of-websites-in-the-world-statistics-say\/\"><span style=\"font-weight: 400;\">It powers 23% of the web<\/span><\/a><span style=\"font-weight: 400;\">, with over 60 million users worldwide. That popularity has served it well in some regards &#8211; it hosts a thriving development community with scores of passionate users coding plugins and helping one another out with technical problems. <\/span><!--more--><\/p>\n<p><span style=\"font-weight: 400;\">Unfortunately, WordPress\u2019s popularity also means it\u2019s the top target for online ne\u2019erdowells. Why else would we hear about a new vulnerability on a near-weekly basis, why else would there constantly be new security threats to protect against? \u00a0Hackers target WordPress because it\u2019s the most visible target, and because its high volume of users means that shotgun-style attacks have the greatest chance of success. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">What that means for you is that if you don\u2019t take the necessary steps to secure your installation, you\u2019re going to end up paying dearly for it. That\u2019s where we come in. Today, we\u2019re going to go over some of the steps involved in safeguarding your CMS.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Let\u2019s get started. <\/span><\/p>\n<h2><b>Backup Your Stuff<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">First thing\u2019s first &#8211; you need to make sure you\u2019re running regular, automated backups. Even if you aren\u2019t targeted by a criminal or infected by malware, there\u2019s a chance a glitch in either your installation or your host\u2019s hardware could cause data loss. In the event that something like that happens, you need a backup to restore your site. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Without one, you\u2019re going to be left picking up the pieces after something goes wrong. <\/span><\/p>\n<h2><b>Always Limit Access<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The fewer people who have access to your site, the better. <\/span><a href=\"http:\/\/www.nextgov.com\/technology-news\/tech-insider\/2015\/06\/how-secure-wordpress-10-steps\/114226\/\"><span style=\"font-weight: 400;\">Tech Insider recommends that you \u00a0<\/span><\/a><span style=\"font-weight: 400;\">use encrypted SSL on administrative pages and functions, lock down access to the wp-config.php file, and encrypt cookies to protect against cookie hijacking. You should also consider limiting the IP addresses that can access your admin folder, and track usage and login attempts. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Where user accounts are concerned, make sure you\u2019re only giving each user the permissions they <\/span><b>absolutely <\/b><span style=\"font-weight: 400;\">need to do their job. A content creator doesn\u2019t need access to your configuration files, and an SEO professional may not need administrative privileges. Giving users the lowest level of access they need to do their job helps guard against both user error and malice, as well as limiting the number of administrative accounts that can be compromised. \u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><b>Keep Everything Up To Date<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Always pay attention to security advisories and updates &#8211; they exist for a reason. While you can probably avoid cosmetic updates to the WordPress platform, you <\/span><b>cannot <\/b><span style=\"font-weight: 400;\">put off updating your plugins or installing security patches to your site. It\u2019s imperative that you regularly check for new bugfixes and hotfixes, and then install them as soon as possible. Failure to do so means you\u2019re leaving yourself wide open to attack. <\/span><\/p>\n<h2><b>Don\u2019t Be Stupid With Your Usernames And Passwords<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">If your administrator account name is \u2018admin\u2019 \u2014 which it is by default \u2014 and your password is \u2018password,\u2019 then I\u2019ve some bad news for you: your WordPress site is probably going to get hacked sooner rather than later. Change your username so it\u2019s not something visible or obvious to hackers, and make sure your password includes a combination of numbers, letters, and symbols &#8211; the longer it is, the better. <\/span><\/p>\n<h2><b>Install Extra Security<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">WordPress core is fairly secure, true &#8211; but that doesn\u2019t mean you\u2019ve anything to lose by adding a bit of extra protection on your own. There are plenty of top-notch security plugins out there, including brute force protection, malware scanners, and spam protection. Go over what\u2019s available, and install the ones you think you\u2019ll need. \u00a0<\/span><\/p>\n<h2><b>Be Careful Where You Download Your Plugins<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">I\u2019ve lost count of the number of vulnerabilities tied to third-party plugins or untrusted sites. When installing plugins to your WordPress platform, <\/span><b>always <\/b><span style=\"font-weight: 400;\">make sure you\u2019re installing them from a trusted source. A pirated plugin very often contains backdoors or malicious code &#8211; installing one is simply asking for trouble. <\/span><\/p>\n<h2><b>Closing Thoughts<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">WordPress might not be insecure, but it\u2019s still the most popular content management system on the web. That makes it an immensely popular target for cybercriminals. If you\u2019re not doing everything you can to protect your site, then you\u2019ve only yourself to blame if it gets hacked. <\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As you well know, WordPress is the most popular content management system in the world. It powers 23% of the web, with over 60 million users worldwide. That popularity has served it well in some regards &#8211; it hosts a thriving development community with scores of passionate users coding plugins and helping one another out [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":215,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-214","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-wordpress"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts\/214","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/comments?post=214"}],"version-history":[{"count":1,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts\/214\/revisions"}],"predecessor-version":[{"id":216,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts\/214\/revisions\/216"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/media\/215"}],"wp:attachment":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/media?parent=214"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/categories?post=214"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/tags?post=214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}