Deprecated: Function create_function() is deprecated in /home2/blogwebhostingbu/public_html/wp-content/plugins/facebook-like-box-responsive/facebook-like-box.php on line 29
{"id":2713,"date":"2014-08-11T07:05:55","date_gmt":"2014-08-11T07:05:55","guid":{"rendered":"http:\/\/www.webhostingbuzz.com\/blog\/?p=2713"},"modified":"2015-08-07T23:11:06","modified_gmt":"2015-08-07T23:11:06","slug":"10-tips-securing-wordpress-site","status":"publish","type":"post","link":"https:\/\/blog.webhostingbuzz.com\/2014\/08\/11\/10-tips-securing-wordpress-site\/","title":{"rendered":"10 Tips for Securing Your WordPress Site"},"content":{"rendered":"

Thanks to its established large developer community and offering two Beta releases before major versions are pushed out for use on production sites, WordPress is generally kept free of bugs; if site owners remember to update!<\/p>\n

One downside to using WordPress is that since 22.8% of websites use it, it has become a prime target for hackers.<\/p>\n

For example, a bug was recently identified in WordPress and Joomla installations which would allow a hacker to run a highly resource-intensive process which would result in the server crashing and the website going down.<\/p>\n

WordPress swiftly released 3.9.2 which fixed this, however many people will still be on older versions which are still vulnerable.<\/p>\n

1. Use a Secure Password<\/h2>\n

One of the most obvious tips is to make sure you have a fairly complex password, and not something which will be easily guessed by a potential hacker.
\nIf you think you’ll forget it, simply use a password manager such as LastPass.<\/p>\n

2. Update WordPress Core & WordPress Plugins<\/h2>\n

I regularly see WordPress sites which are heavily outdated. If you’re running an older version of WordPress, you may as well be asking to be attacked.<\/p>\n

So if you see a yellow bar\/banner at the top of the WordPress admin area, don’t delay – hit update!<\/p>\n

3. Remove any unused plugins<\/h2>\n

These not only have to potential to slow down your site, but once they become outdated, they can pose a security risk.<\/p>\n

If you spot any plugins you’re no longer using and will become outdated and forgotten about, deactivate and delete them.<\/p>\n

4. Install a WordPress security plugin<\/h2>\n

Plugins such as Wordfence can be great to help you implement some quick security features, such as changing the URL of the admin login from ‘\/wp-admin’ to a URL of your choice.<\/p>\n

5. Delete any unused WordPress accounts<\/h2>\n

If you’ve had a blog running for a few years or more. have a blog, it’s likely you’ll have created accounts for contributors.<\/p>\n

Additionally, developers often create test accounts within WordPress that they might have forgotten to delete afterwards, so it’s always good to double-check.<\/p>\n

6. Limit Dashboard Accessibility by IP Address<\/h2>\n

You can easily restrict access to the WordPress dashboard by a specific IP address. For example, if you only want people to be able to access the dashboard at your workplace, you can find out the IP address and add it to the below code, which can be added to your .htaccess file.<\/p>\n

order deny,<\/p>\n

allow<\/p>\n

allow from YOURIPADDRESSHERE<\/p>\n

deny from all<\/p>\n

7. Force HTTPS (SSL) in the Admin Area<\/h2>\n

To do this, simply create a new .htaccess file within the wp-admin folder, then paste in the following code:<\/p>\n

define(‘FORCE_SSL_ADMIN’, true);<\/p>\n

8. Only Install Well-Known and Secure Plugins<\/h2>\n

Since you’re installing WordPress plugins right into your core directories, it’s important that you can trust them. If there’s a brand new plugin that has very little ratinga<\/p>\n

Always look for plugins which have had plenty of reviews.<\/p>\n

9. Perform Regular Backups of your Website Files and Database<\/h2>\n

You have three options here.<\/p>\n

1. Manually create backups in your hosting account<\/h3>\n

The first being you manually create backups of your whole hosting account (if you use cPanel\/WHM, there’s a backup tool).<\/p>\n

2. Using a WordPress plugin<\/h3>\n

Alternatively, you can install a WordPress plugin such as Backup Buddy or VaultPress which makes the process as simple as possible for you.<\/p>\n

3. Automatic cloud backups<\/h3>\n

Alternatively (and my preferred option) is to use a cloud backup service such as CodeGuard, which runs nightly backups to the cloud for you.<\/p>\n

10. Pick a Reliable and Secure Hosting Provider<\/h2>\n

You should also consider support here. If your WordPress site does get hacked, you’ll probably want it back up and running again as soon as possible. So it’s important to choose a provider that offers 24\/7 support in case you need it.<\/p>\n","protected":false},"excerpt":{"rendered":"

Thanks to its established large developer community and offering two Beta releases before major versions are pushed out for use on production sites, WordPress is generally kept free of bugs; if site owners remember to update! One downside to using WordPress is that since 22.8% of websites use it, it has become a prime target […]<\/p>\n","protected":false},"author":913,"featured_media":3076,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[354],"tags":[],"yoast_head":"\n10 Tips for Securing Your WordPress Site - WebHostingBuzz US Blog<\/title>\n<link rel=\"canonical\" href=\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"10 Tips for Securing Your WordPress Site - WebHostingBuzz US Blog\" \/>\n<meta property=\"og:description\" content=\"Thanks to its established large developer community and offering two Beta releases before major versions are pushed out for use on production sites, WordPress is generally kept free of bugs; if site owners remember to update! One downside to using WordPress is that since 22.8% of websites use it, it has become a prime target […]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/\" \/>\n<meta property=\"og:site_name\" content=\"WebHostingBuzz US Blog\" \/>\n<meta property=\"article:published_time\" content=\"2014-08-11T07:05:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2015-08-07T23:11:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.webhostingbuzz.com\/wp-content\/uploads\/2014\/08\/wordpress-security.png\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data1\" content=\"3 minutes\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#website\",\"url\":\"https:\/\/www.webhostingbuzz.com\/blog\/\",\"name\":\"WebHostingBuzz US Blog\",\"description\":\"Hosting, hosting, more hosting and a little of everything else\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.webhostingbuzz.com\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/blog.webhostingbuzz.com\/wp-content\/uploads\/2014\/08\/wordpress-security.png\",\"contentUrl\":\"https:\/\/blog.webhostingbuzz.com\/wp-content\/uploads\/2014\/08\/wordpress-security.png\",\"width\":800,\"height\":400,\"caption\":\"wordpress security\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/#webpage\",\"url\":\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/\",\"name\":\"10 Tips for Securing Your WordPress Site - WebHostingBuzz US Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/#primaryimage\"},\"datePublished\":\"2014-08-11T07:05:55+00:00\",\"dateModified\":\"2015-08-07T23:11:06+00:00\",\"author\":{\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#\/schema\/person\/d56730c0ad0802b84f8caa335ac9e87f\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/\",\"url\":\"https:\/\/www.webhostingbuzz.com\/blog\/2014\/08\/11\/10-tips-securing-wordpress-site\/\",\"name\":\"10 Tips for Securing Your WordPress Site\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#\/schema\/person\/d56730c0ad0802b84f8caa335ac9e87f\",\"name\":\"Adam\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/457a2842ccd294191c84a4c7ade89057?s=96&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/457a2842ccd294191c84a4c7ade89057?s=96&r=g\",\"caption\":\"Adam\"},\"description\":\"Marketing Manager @ WebHostingBuzz. Heading up a few new and exciting projects - watch this space!\",\"sameAs\":[\"https:\/\/adamowen.co.uk\",\"https:\/\/twitter.com\/adamowenit\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/posts\/2713"}],"collection":[{"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/users\/913"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/comments?post=2713"}],"version-history":[{"count":9,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/posts\/2713\/revisions"}],"predecessor-version":[{"id":3077,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/posts\/2713\/revisions\/3077"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/media\/3076"}],"wp:attachment":[{"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/media?parent=2713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/categories?post=2713"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/tags?post=2713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}