jbQ Media

Web Design, SEO Services and Media Production | Boston | Suffolk | MA

(917) 861-1242
  • Home
  • About
    • Why Us
    • Jon Burr | Site Designer
    • Our Rates
    • Contact
    • Our Location
    • News via Twitter
  • Our Services
    • WordPress Training
    • WordPress Site Design
    • Website Multimedia Production Services
    • Website Editorial Services
    • SEO Services
    • Online SEO Coaching Services via Zoom
    • Wix SEO Tutorial Services
    • CD Covers and Packages
  • Website Portfolio Gallery
  • Articles
  • Reviews
You are here: Home / Security / Protect Wordpress From Hackers! | Wordpress Site Security

Protect WordPress From Hackers! | WordPress Site Security

February 2, 2015 By Jon Burr

Hacker attacks on WordPress sites are constant, persistent, increasing, ongoing, and pervasive. Without some level of protection, your site WILL be hacked.

No server can offer an ironclad guarantee against hacking, although so-called “Managed WordPress” services do a pretty good job. Many of these charge significantly more (as much as ten times more) than self-managed servers. As a developer, my own preference is for maximum configurability and site speed for minimum cost.

Many Managed WordPress hosting providers only permit one domain per account, and place restrictions on site file management. If you’ve got multiple sites, a hosting account allowing multiple add-on domains is a must. When you choose this type of account, you’ve assumed the responsibility for managing it, including guarding against hacker attacks.

Common security mistakes to avoid for self-hosted WordPress

  • “admin” or “wp-admin” as a site username
  • Short passwords
  • Incorrect file permissions
  • Old versions of WordPress
  • “Orphan” (inactive) plugins
  • Vulnerable or malicious plugins

One of our customers has 9 WordPress websites we migrated over from Network Solutions and consolidated into a single account on A2 Hosting. His account was hacked (Not A2’s fault!!). A2’s support tech said “this is a bad one.”

Avoidable Security Mistake Number One

Some sites had WordPress versions not updated for many years.

At the client’s direction, we had redesigned and updated 3 of them and left the rest alone.

Avoidable Security Mistake Number Two

The client insisted on the same login for all of the sites.

Result – a hacker got in, and polluted the entire account matrix with obfuscated code and created 2 link-spam posts advertising a golf equipment site in Canada and a hotel in the Middle East!

According to A2’s site scan, every php file in all the accounts was infected with malicious code.

Fortunately, A2’s cPanel has “Site Rewind,” an app that can restore a site to a date within the last 30 days.

The procedure to recover the sites was as follows:

  • Delete all content, visible and invisible, in the public_html directory
  • Use Site Rewind to replace the content with uninfected code (this took a few re-tries – its performance was not flawless, having skipped some subdirectories)
  • Replace all databases
  • Change all passwords
  • Install a login “fence” putting the admin login behind another URL.

Hacker Protection and Speed Optimization for WordPressA2 has created “A2Optimized,” a multifunction WordPress plugin that can:

  • Put the WordPress login behind another url, protecting it from bots scanning for default login pages
  • Add “Captcha” verification to comments and site login
  • Optimize site code through caching, compression and minification for maximum site speed.

Lesson learned: Make sure you and your client understand the potential consequences and cost of inadequate site maintenance and security practices.

Advice?

Get the benefit of the experience of a developer with experience dealing with hacked sites and restoration.

Get a proactive assessment of your site’s setup and likely security vulnerabilities.

Act now. It’s cheaper than after you’re hacked.

Related Posts:

  • Wix SEO Tutorial Services Lots of options and many things to do! Welcome to…
  • Online SEO Coaching Services via Zoom We Offer Expert Zoom Tutoring in SEO! Unlock the Power…
  • CD Covers and Packages Collected past work from a variety of projects we did…

Filed Under: Security, Services, Support, Useful Tools, Wordpress Tagged With: caching, hacking, protection, security

Site Search

Our Services

  • WordPress
  • SEO
  • Strategy
  • Consulting
  • Website Design
  • Useful Tools
  • Tutorials
  • Editorial

Recent Articles

  • Why SEO is Better than Paid Google Ads
  • Creating a Glossary for a WordPress Site with ChatGPT AI
  • Converting WordPress Widgets for use in the Block Editor
  • How to Change the Styling of a Column in the WordPress Block Editor
  • Connecting Calendly to Zoom
  • Upgrading an old HTML site with a WordPress blog to WordPress
  • WordPress 5.0 and Gutenberg – What it Means for Genesis Themes
  • Migrating a WordPress Site if Wordfence is Installed, Using Duplicator and MAMP
  • Keeping up with Google’s New Features – SSL, AMP, and Google Posts
  • Adding a full-width responsive header in a Genesis theme (January 2018)
  • LBS Markets Mystery Shopper Fraud
  • Basic SEO In Six Steps
  • Navigating Google My Business, Google Brand Accounts, and Google+
  • SEO Tools Test Drive and Comparison
  • SEO Training | Tutorial | Boston | Suffolk County MA
  • SEO Tools, Links and Learning
  • Certified Google Trusted Photographer | Boston MA
  • Social Media Marketing Services | Facebook Ads Services | Boston | Suffolk County MA
  • What Does SEO Cost?
  • Moving a Live WordPress Site to Local with Mamp Pro

Contact us now! :)

Why delay? Initial consultation is on the house!

call (917) 861-1242

    Your First Name (required)

    Your Last Name (required)

    Your Email (required)

    (please double-check it!)

    Subject

    Contact from jbQ Media Website

    Your Message

    *required


    Subscribe me your mailing list

    Human?*

    • Production
    • WordPress Sites
    • Strategy
    • SEO
    • Websites
    • Editorial
    • Contact
    • Terms of Service
    • Cookie policy

    © 2014 jbQ Media

    Google+
    Manage Cookie Consent
    We use cookies to optimize our website and our service.
    Functional cookies Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}