How to make your WordPress website more secure

I recently had an intriguing conversation with a developer who held the belief that WordPress's status as the most popular CMS on the Internet is its weakness, attracting hackers to exploit its vulnerabilities.

And you know what? He was right!

It's a scary thought, isn't it? Let's take a step back and analyze what this means.

Every CMS has its weak spots.

Yes, WordPress, Joomla, Drupal (to name the main players) have security holes. But, to be fair, so do Apple, Microsoft, Sun Microsystems, Oracle, and even The Pentagon. Since WordPress relies on a community of people, every security hole is quickly identified and patched up. Here's the first piece of advice: keep your WordPress core up to date!

Brute force attacks.

It's as scary as it sounds. A hacker attempting to breach your login scripts until they guess your admin credentials, wreaking havoc on your website. Imagine this scenario: John is searching for a "used Ford Galaxy in York" on Google, and your website comes up as #2 (well done, by the way). He clicks on the link, and oops, he didn't want any Viagra.

Let's be honest – if the Pentagon can get hacked, so can you. Online security is about minimizing the chances. If your main administrator username is still "admin," you've already given away 50% of your credentials. And even if it's not, a skilled person (or script) can find it easily. For example, requesting www.yourwebsite.co.uk/?author=1 can reveal www.yourwebsite.co.uk/author/mysecretname/, where "mysecretname" is the name of the website admin. Simple, isn't it?

Especially since most brute force attempts target the default login page at /wp-login.php… But what if your login page isn't there?

There are plugins like Shield WordPress Security that can help you with that. WordPress also encourages you to use complex passwords, but, hey, we know how much you like "password12345." Just do yourself a favor and don't. Cleaning up the mess after a website hack can be expensive and embarrassing (especially when you have to send an email to your 1,281 subscribers explaining that you really don't have Viagra on offer).

There's a plugin for that.

Yes, there is. Whatever you need. But when you install a plugin, make sure it comes from a reputable source, has been installed many times, and has good ratings. These three factors are like a price – you usually get what you pay for. And while we're on that subject – don't be afraid to pay £30 for a plugin that makes you money. The support is usually great, and if you're into single malts, you can drain £30 over the weekend.

The important point about plugins is – they can extend the functionality of your website, but if they are poorly written, they can deliver a blow to your business (see the Viagra point above). Yes, WP plugins can be a serious weakness of your website, so be careful. And most importantly – keep all your plugins up to date!

Hosting is hosting – £1.99 a month will do.

Nope. It won't. Unless your business makes £200 a year and £23.88 is a significant investment…

Admittedly, it all depends on your project and its scale. But terms like bandwidth, SPF, DKIM, SSL, SSH, firewall, SMTP Relay, IP reputation, etc., are "a thing," and they affect your business. Trust me – they often don't come cheap (they sure don't sound cheap)!

And the bottom line is that you don't want (just) hosting. You have your business to run, and you don't want to be bothered with things that you can't even pronounce! That's why it's a good idea to team up with people that offer comprehensive infrastructure support that aligns with your web requirements.

Final note.

There is no denying that satisfying the requirements mentioned above may not be enough to keep your website 100% secure (if such a thing exists). However, addressing the issues outlined in this article can keep you safe from 98% of WordPress threats and keep your website and your business intact.

If you feel you might be vulnerable and some aspects of WordPress security have not been properly taken care of, give us a ring at 07999 250 870.

crossmenu