Businesses are now done online. Even before this lockdown, many business have adopted using online to leverage their opportunity to increase their income.
With lockdown, it means things are now done online even more than they were before the lockdown. This means people are more open to threat and there is a need for them to adopt stricter measure to meet the demand of cyber safety out there.
Outline:
- WordPress
- Plugin
- Theme
- WordPress Security
- How to prevent hackers
- Conclusion.
Let's look at WordPress, what it entails, how vulnerable it is and how you can secure your website if you are using WordPress.
WordPress is one of the most used and popular free open-source content management system out there which is written in PHP. For a short form, WordPress is CMS - Content Management System. WordPress is paired with MySQL or MariaDB database.
Millions of site owners prefer WordPress to other CMS like Joomla, Serendipity, Drupal, Dotclear, Typo3, etc,.
The reason for this is simple, WordPress is the most easiest CMS to tweak for many non developers. It makes life easy for all, has free hosting, and has all that you need to have a beautiful website.
Another good thing about WordPress is, it is easy to manage. You do not need any web manager to manage your site for you.
While WordPress is promising and easy to use, there are certain features it has that makes it easy for people to find their ways around it.
They are:
Plugin
Theme.
Plugin: It's software or applications grouped into one function but contains group of functions. A plugin can be added to a WordPress site to extend it functionality, add new features and beautify your WordPress site. Like WordPress, plugins are also written in PHP.
Themes: Themes are collection of templates and stylesheets used to display WordPress website. Theme defines the appearance of your WordPress site. It is the main foundation and what people see when they visit your site. A theme can be gotten for free or with money for more features.
WordPress Security
Being the most used CMS out there, it makes WordPress very vulnerable. In fact, there are hackers out there who do nothing other than try to hack every WordPress website out there.
How did i know this? Well, the site i managed was hacked back in 2019. It was my first experience after managing website for 4 years.
I worked on the site that same day and after hours, i discovered the site was redirecting to many sites. We tried to discover the problem and saw that the hacker was able attack the site through the site theme. From there, he downloaded cookies malware that changes almost every minute.
It was a hell of a day for me. I became aware of some of the lapses on the site and tried to adopt another method to solve the problem.
We were unable to recover the site immediately. What we did was, we moved the site database out, deleted the theme, deleted the WordPress downloaded on the domain.
After that, we downloaded a new WordPress file and theme. Moved the database there. Rolled out a testing sub domain for few hours to see how it works. After normalcy have been restored, we reverted to original domain name and everything was normal again.
In the process we discovered that bots are constantly being sent to the site. These bot access the site WP-ADMIN login page and also send unsolicited traffic to the admin page. A very huge traffic which eat up the site resources in few minutes. Once this resources are eating up, the site returns an error or 'Limited Resources' which was frustrating.
That experience taught me lot of things and i developed a new strategies on how to protect future websites.
How to Prevent Hackers from Hacking your WordPress site
There are many ways to prevent your site from being hacked. They are manual and plugins.
- Manual: By manual, there are things you must do to make sure your site is secured.
Always update your plugins. I discovered i had some plugins i didn't update. Outdated plugins are easy to manipulate. These plugins are updated once the developer sees a bug. So it is in your best interest to update immediately it becomes outdated.
Change your WP-ADMIN login page to something else. Hackers visit your admin page with different passwords in an attempt to break in. The more the traffic sent to your admin page the more resources you will lose. So changing the url to something else makes the page unavailable.
Once that happens, your site is free from hackers trying to access that page. This gives you relief and opportunity to focus on something else.
- Stop bots from accessing your site. We always accept bots to easily craw our sites but this is being manipulated by bad bots and hackers. If you allow this, many bad bots would be sent to your website. Their aim is to make your site inaccessible to your readers.
If you must accept google bot, stop it from accessing all pages, also give it time it must access your site. These Google bots check for new posts. So set it to check your site once 3-5hours depending on how often you update your site. With this, your resources wont be eaten up by these bots.
To do this, edit your .htaccess. This is where all the bots (good ones) get their information from. A bot visit your .htaccess to know the rules you set there. Many ignore this rules and go ahead to access your site. It is important you set the rule and make sure your .htaccess is set to deny editing from remote places. This will help keep the bad ones from accessing your site.
Update your theme always. For many who are using free themes, it is hard to get update sometimes but you need to monitor your theme and update as soon as new one is out. Updated version will give you an edge over the hackers because like i said, updated version correct bugs.
Update JavaScript, PHP version and WordPress. The JavaScript, PHP and WordPress versions are always updated. While you can know that of your WordPress from your backend, the rest could be monitored from your Cpanel. So make sure you check your Cpanel always to know if you are running the latest version of JavaScript and PHP. Older version means vulnerability.
Use Cloudflare. Register your site with Cloudflare. This will give you new DNS to use in your domain. Once you activate Cloudflare DNS, your site weight (resources) is loaded on Cloudflare. This help reduce the resources of your site as Cloudflare caches and loads the cached file to users.
- Plugin: There are plugins that you can use to secure your website. These plugins are called Web Application Firewall (WAF).
As a firewall, these plugins block all malicious traffic, bots before they reach your website.
What these plugins do is that they route your website Domain Name System (DNS) traffic through their cloud proxy.
I have used different plugins after being hacked. Some of the firewall plugins i have used are:
All In One WP Security & Firewall
Sucuri
Wordfence Security - This also consumes resources so use it if you have good resources.
BulletProof Security
Cache - There are many plugins that can help you cache your site. A cache site loads the cached instead of the real site. This helps your site to load faster. Instead of loading your site, the cache would be loaded instead.
Another good thing about these plugins is that they show live view which shows you you attempt by hackers to access your site. This will leave you surprised knowing that thousands of people try to access your site daily with bots.
Conclusion
If you can update your plugins, themes, WordPress, change admin url, update JavaScript, PHP versions, cache your site, use cloudflare, and some of the plugins listed above, your WordPress site would do just fine.
Before i forget, try to SSL certificate for your site. SSL means Secure Sockets Layer. It secures your site by establishing an encrypted link between the server and the website.
Google mark SSL site as secured because information entered in then are protected while non SSL sites are marked non-secure. SSL site are with https while non-SSL are just http.
Your site should have a confirmed SSL certificate. It will give you an edge and a good night sleep.
I hope the information above is helpful to you all and especially WordPress users.
Thanks for your time. I am @smyle.