{"id":12146,"date":"2022-04-22T18:49:42","date_gmt":"2022-04-22T10:49:42","guid":{"rendered":"https:\/\/www.cldy.com\/sg\/?p=12146"},"modified":"2023-02-28T20:46:55","modified_gmt":"2023-02-28T12:46:55","slug":"wordpress-security-guide","status":"publish","type":"post","link":"https:\/\/www.cldy.com\/sg\/blog\/wordpress-hosting\/wordpress-security-guide\/","title":{"rendered":"Protecting Your Website and More: A Guide to WordPress Security"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"12146\" class=\"elementor elementor-12146\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-11738056 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"11738056\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-213730fe\" data-id=\"213730fe\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d977df7 elementor-widget elementor-widget-text-editor\" data-id=\"d977df7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The security of your WordPress website is a top priority especially when most of your website functions are reliant on the platform. WordPress is an all-in-one tool with very dependable features and services that can help you manage your website. And along with maximizing the use of WordPress and its features, is the increasing need to keep your website free from the dangers of security attacks.<\/p><p>WordPress is the most widely used content management system (CMS), and thus it is also the most common target for cyberattacks. While cyberattacks can still occur elsewhere, it is important to be vigilant and make sure that your website is always secured.\u00a0<\/p><p>Read on to know how you can design a game plan to secure your WordPress website and more.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3b18bca elementor-toc--minimized-on-tablet elementor-widget elementor-widget-table-of-contents\" data-id=\"3b18bca\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;headings_by_tags&quot;:[&quot;h4&quot;,&quot;h6&quot;],&quot;exclude_headings_by_selector&quot;:[],&quot;marker_view&quot;:&quot;bullets&quot;,&quot;icon&quot;:{&quot;value&quot;:&quot;fas fa-circle&quot;,&quot;library&quot;:&quot;fa-solid&quot;},&quot;no_headings_message&quot;:&quot;No headings were found on this page.&quot;,&quot;minimize_box&quot;:&quot;yes&quot;,&quot;minimized_on&quot;:&quot;tablet&quot;,&quot;hierarchical_view&quot;:&quot;yes&quot;,&quot;min_height&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"table-of-contents.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-toc__header\">\n\t\t\t<h4 class=\"elementor-toc__header-title\">\n\t\t\t\tTable of Contents\t\t\t<\/h4>\n\t\t\t\t\t\t\t<div class=\"elementor-toc__toggle-button elementor-toc__toggle-button--expand\" role=\"button\" tabindex=\"0\" aria-controls=\"elementor-toc__3b18bca\" aria-expanded=\"true\" aria-label=\"Open table of contents\"><i aria-hidden=\"true\" class=\"fas fa-chevron-down\"><\/i><\/div>\n\t\t\t\t<div class=\"elementor-toc__toggle-button elementor-toc__toggle-button--collapse\" role=\"button\" tabindex=\"0\" aria-controls=\"elementor-toc__3b18bca\" aria-expanded=\"true\" aria-label=\"Close table of contents\"><i aria-hidden=\"true\" class=\"fas fa-chevron-up\"><\/i><\/div>\n\t\t\t\t\t<\/div>\n\t\t<div id=\"elementor-toc__3b18bca\" class=\"elementor-toc__body\">\n\t\t\t<div class=\"elementor-toc__spinner-container\">\n\t\t\t\t<i class=\"elementor-toc__spinner eicon-animation-spin eicon-loading\" aria-hidden=\"true\"><\/i>\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-03c94cf elementor-widget elementor-widget-spacer\" data-id=\"03c94cf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7d89f78 elementor-widget elementor-widget-heading\" data-id=\"7d89f78\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-large\">WordPress Security Risks Explained<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-836fea8 elementor-widget elementor-widget-text-editor\" data-id=\"836fea8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>WordPress is the core of more than 40% of websites around the world, so the big question is &#8211;\u00a0<i>\u201cis WordPress really secure?\u201d<\/i><\/p><p>WordPress on its own IS secure &#8211; BUT, it is not always a 100% guarantee. This is because some WordPress functionalities are from third-party providers who may (or may not) be always up-to-date with their security measures. The main vulnerabilities in WordPress arise from plugins and themes, with only 0.58% of security risks coming from the main WordPress system. 91.38% of these detected vulnerabilities are from free plugins and themes; some of which were already removed due to security bugs that were not resolved.<\/p><p>If plugin bugs are not addressed, or security patches are not released on a timely basis, more users become prone to security risks.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-71c1506 elementor-widget elementor-widget-heading\" data-id=\"71c1506\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-large\">Why Do You Need To Protect Your WordPress Website?<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4fcfa4d elementor-widget elementor-widget-text-editor\" data-id=\"4fcfa4d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>When you protect your WordPress website, you are not only keeping your information safe, but you also protect your customers\u2019 information that is stored within your database. An eCommerce website holds tens to hundreds of customer accounts &#8211; even more for growing and established businesses.<\/p><p>Small matters like file uploads are actually highly susceptible and can compromise the security of your WordPress website. This can come from any of your team or your customers, who upload files and sends them over to your website. Any file can compromise the stability of the website\u2019s PHP codes (e.g. any file that may have a \u201c.php\u201d within its file name), and can overall affect the security of your WordPress website.<\/p><p>Take a look at these common types of security attacks below and how they can affect your WordPress website:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-248c70c elementor-widget elementor-widget-heading\" data-id=\"248c70c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h5 class=\"elementor-heading-title elementor-size-medium\">Common types of WordPress security attacks<\/h5>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-624cc7e elementor-widget elementor-widget-text-editor\" data-id=\"624cc7e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><a href=\"https:\/\/www.cldy.com\/support\/help\/what-is-a-brute-force-attack\/\"><strong>Brute-Force Attacks<\/strong><\/a><\/p><ul><li>Brute force attacks are \u201cforceful\u201d attempts to open a file or an account. It involves trying multiple combinations of passwords to gain access, whether it be authorized or unauthorized.<\/li><li>There are different\u00a0<a href=\"https:\/\/www.cldy.com\/support\/help\/what-are-the-types-of-brute-force-attacks\/\">types of brute force attacks<\/a>\u00a0&#8211; ranging from a simple dictionary attack [a hacker uses sets of password combinations that are related to you] to credential stuffing [they utilize successful passwords\/login credentials that have successfully gotten through in previous attempts (e.g. within a company\u2019s logins or accounts)].<\/li><li>There are even software that are actually designed for brute force attacks, which can be used to try to get into your WordPress website.<\/li><\/ul><p>\u00a0<\/p><p><strong>Cross-Site Scripting (XSS)<\/strong><\/p><ul><li>XSS, by far, is the most common, accounting for 47% out of all WordPress vulnerabilities.<\/li><li>During an XSS attack, a malicious JavaScript code is added to your WordPress website\u2019s pages, enabling an attacker to get ahold of a user\u2019s session cookies. This, in turn, can be used by hackers to imitate and impersonate a user online \u2013 leaving only the user\u2019s stolen information as a trail.<\/li><\/ul><p>\u00a0<\/p><p><strong>DoS Attacks<\/strong><\/p><ul><li>Organizations and businesses are mostly the targets of Denial-of-Service (DoS) attacks.<\/li><li>It involves creating fake internet traffic towards its intended website, which in turn will render the website impossible to access for other legitimate users. These attacks are usually carried out by bots, purposely sent to a network or a server to overwhelm it with access requests.<\/li><li>DDoS (distributed denial-of-service) attacks are on a larger scale. While DoS attacks are done through a single internet connection, DDoS attacks are initiated through multiple devices that make it almost impossible to counter.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0a3b4c5 elementor-widget elementor-widget-spacer\" data-id=\"0a3b4c5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-11e2b2c elementor-widget elementor-widget-heading\" data-id=\"11e2b2c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-large\">How To Protect Your WordPress Website?<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-642c7eb elementor-widget elementor-widget-text-editor\" data-id=\"642c7eb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Aside from the primary security that WordPress provides, here are other tips to utilise to make sure that your website WordPress security is safe from any vulnerabilities:<\/p><p><strong>Always Use The Latest Version Of WordPress<\/strong><\/p><p>WordPress updates are released to incorporate more features that can help you manage your website. Not only that, bug fixes and additional security measures are also integrated within the update to enhance WordPress security. So when you use an outdated version of WordPress, it makes your WordPress website more vulnerable to security risks.<\/p><p>\u00a0<\/p><p><strong>Hide The WordPress Version You Are Using<\/strong><\/p><p>This one is related to the tip above. When hackers get a hold of what WordPress version you are using, they are then made aware of how to go around the codes and make their way into your WordPress website. Here\u2019s how you can do it:<\/p><ol><li>Go to your WordPress theme\u2019s <i>functions.php<\/i>\u00a0file.<\/li><li>Use the following code:<br \/>function wp_version_remove_version() {<\/li><\/ol><p>return &#8221;;<br \/>}<br \/>add_filter(&#8216;the_generator&#8217;, &#8216;wp_version_remove_version&#8217;);<\/p><ul><li><i>We recommend that you check with your web hosting provider how to go about it to make sure that no other codes are modified.<\/i><\/li><\/ul><p>\u00a0<\/p><p><strong>Use Two-Factor Authentication For Logins<\/strong><\/p><p>You may have seen this used in other websites and platforms, and you can have this done with your WordPress website, too! Two-factor authentication can be done through email, SMS, or a phone call. This is an indispensable tool against brute force attacks because you will always be notified every time your account is being accessed &#8211; especially when it\u2019s from an unknown device or location.<\/p><p>\u00a0<\/p><p><strong>Keep All WordPress Plugins And Themes Up-To-Date<\/strong><\/p><p>Similar to keeping your WordPress version updated, you must also make sure that your WordPress plugins and themes are up-to-date with the latest patches and releases. You can set up\u00a0<a href=\"https:\/\/wordpress.org\/plugins\/notification\/\" rel=\"nofollow noopener\" target=\"_blank\">notifications<\/a>\u00a0so you can receive alerts whenever there is a new update on a plugin or theme you have on your WordPress website. Otherwise, you will have to manually check on any updates so you can have them installed, or removed so you can find the latest versions or better alternatives.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5dcd8d7 elementor-widget elementor-widget-heading\" data-id=\"5dcd8d7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h6 class=\"elementor-heading-title elementor-size-large\">WordPress Plugins to Further Secure your Website<\/h6>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a775cee elementor-widget elementor-widget-text-editor\" data-id=\"a775cee\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>There are specific WP plugins dedicated to enhance security, and we have some of them listed here:<\/p><p><strong>WPS Hide Login<\/strong><\/p><p>This is used to secure a website\u2019s WordPress account from any attempts of being accessed by outside parties. WordPress users would know that adding a \/login after a website\u2019s URL will easily give them the path to the linked WordPress account. WPS Hide Login is the perfect plugin to secure your login URL from any hacking attempts. Click\u00a0<a href=\"https:\/\/www.cldy.com\/support\/help\/how-to-install-wps-hide-login-plugin\/\">here<\/a>\u00a0to know how you can have it installed for your WordPress website.<\/p><p>\u00a0<\/p><p><strong>Perfmatters<\/strong><\/p><p>Perfmatters is a premium plugin that helps in optimizing your overall WordPress website\u2019s performance. Here are some security features that you can take advantage of:<\/p><ul><li><b>Hide WP Version.<\/b>\u00a0Keep your WordPress version off-limits to any viewers.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-12150\" src=\"https:\/\/www.cldy.com\/sg\/wp-content\/uploads\/sites\/7\/2022\/04\/perfmatters-hide-wp-version.png\" alt=\"\" width=\"243\" height=\"46\" \/><\/li><li><b>Hide WP Login.<\/b>\u00a0Change your WordPress login URL to a custom link.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-12148\" src=\"https:\/\/www.cldy.com\/sg\/wp-content\/uploads\/sites\/7\/2022\/04\/perfmatters-custom-login-url.png\" alt=\"\" width=\"430\" height=\"107\" srcset=\"https:\/\/www.cldy.com\/sg\/wp-content\/uploads\/sites\/7\/2022\/04\/perfmatters-custom-login-url.png 430w, https:\/\/www.cldy.com\/sg\/wp-content\/uploads\/sites\/7\/2022\/04\/perfmatters-custom-login-url-300x75.png 300w\" sizes=\"(max-width: 430px) 100vw, 430px\" \/><\/li><li><b>Disable XML-RPC.<\/b>\u00a0XML-RPC allows your WordPress website to initiate multiple commands from a single request, which unfortunately allows hackers to easily manipulate for brute force attacks.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-12149\" src=\"https:\/\/www.cldy.com\/sg\/wp-content\/uploads\/sites\/7\/2022\/04\/perfmatters-disable-xml-rpc.png\" alt=\"\" width=\"226\" height=\"46\" \/><\/li><\/ul><p>\u00a0<\/p><p><strong>iThemes Security<\/strong><\/p><p>This plugin combines both security and storage components. Here are some of the features you can activate under this plugin:<\/p><ul><li>Two-factor authentication<\/li><li>Lockouts (for any network or local brute force attacks)<\/li><li>Lockout time limit<\/li><li>Site scan scheduling<\/li><li>Scheduled database backups<\/li><\/ul><p>\u00a0<\/p><p><strong>WP Activity Log<\/strong><\/p><p>This plugin helps you monitor user activity including logins and logouts (also failed login attempts), changes to WordPress plugins and themes, updates to website posts and pages, changes in user profiles, and a lot more. It also details exactly what changes have been made by a specific user. There are specific event IDs assigned depending on the action made, and the\u00a0<i>severity<\/i>\u00a0or the level of security risk.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-88f7131 elementor-widget elementor-widget-heading\" data-id=\"88f7131\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h6 class=\"elementor-heading-title elementor-size-large\">Protecting Your WordPress Website - The CLDY Way<\/h6>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d120a63 elementor-widget elementor-widget-text-editor\" data-id=\"d120a63\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Security is one of the core principles we implement to achieve web hosting excellence. Our servers are protected against malicious attacks, which is why you can rest assured that your data is secure with us.<\/p><p>Our\u00a0<a href=\"https:\/\/www.cldy.com\/sg\/web-hosting\/\">web hosting plans<\/a>\u00a0are integrated with these security features:<\/p><p><img decoding=\"async\" class=\"size-full wp-image-12151 aligncenter\" src=\"https:\/\/www.cldy.com\/sg\/wp-content\/uploads\/sites\/7\/2022\/04\/cldy-web-hosting-security-features.png\" alt=\"\" width=\"546\" height=\"399\" srcset=\"https:\/\/www.cldy.com\/sg\/wp-content\/uploads\/sites\/7\/2022\/04\/cldy-web-hosting-security-features.png 546w, https:\/\/www.cldy.com\/sg\/wp-content\/uploads\/sites\/7\/2022\/04\/cldy-web-hosting-security-features-300x219.png 300w\" sizes=\"(max-width: 546px) 100vw, 546px\" \/><\/p><center><em>This screenshot is owned by CLDY<\/em><\/center><p>\u00a0<\/p><p>Out of these various ways to protect your WordPress website, it\u2019s up to you to employ whichever functions you deem necessary to ensure maximum security. Ultimately, you are in charge of how you will keep your information and your customers\u2019 information secure. For\u00a0<a href=\"https:\/\/www.cldy.com\/sg\/wordpress-hosting\/\">secure WordPress hosting<\/a>\u00a0options, reach out to us\u00a0today at\u00a0<em>sales@cldy.com\u00a0<\/em>and seize the unparalleled security and support you need for your business.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>The security of your WordPress website is a top priority especially when most of your website functions are reliant on the platform. WordPress is an all-in-one tool with very dependable features and services that can help you manage your website. And along with maximizing the use of WordPress and its features, is the increasing need [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":12157,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[68],"tags":[],"class_list":["post-12146","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-wordpress-hosting"],"_links":{"self":[{"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/posts\/12146","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/comments?post=12146"}],"version-history":[{"count":24,"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/posts\/12146\/revisions"}],"predecessor-version":[{"id":21627,"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/posts\/12146\/revisions\/21627"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/media\/12157"}],"wp:attachment":[{"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/media?parent=12146"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/categories?post=12146"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cldy.com\/sg\/wp-json\/wp\/v2\/tags?post=12146"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}