Subscribe to our RSS feed RSS
November 10, 2009

Share Your Favorite WordPress Security Tips!

No matter how awesome content on your blog is, how properly SEOed your site may be or how much work you put into promoting it, one day all your efforts may fall short all at once because your Wordpress-run blog has been hacked. What may follow is quite a depressining time actually:

  • Your website might lose credibility and trust;
  • Google may put that “This site may harm your computer” notice on your site SERPs listings which affects your clickthrough as well as reputation;
  • Important data may get lost;
  • It may take quite a long time to get everything in order (cleaning your site and filing a “malware review” and waiting for Google to figure everything out).

Anyway, it is absolutely clear that it is better to stay away from that negative experience even if you hope that won’t ever happen to your site. So let’s share our favorite tips to secure our Wordpress blogs, shall we?

I’ll start and please share your tips in the comments!

So would you share your favorite Wordpress security guides, plugins and tips?

Feed for this Entry | Trackback Address
Daily SEO Tip on Facebook

16 comments already

  1. shivseo (Shiva Purohith) on 12.31.1969 at 11:59 pm | permalink
  2. Share Your Favorite WordPress Security Tips! http://tinyurl.com/yjl9u48

    [Reply]

  3. Xtend2india on 11.11.2009 at 10:40 am | permalink
  4. what i believe is 1) file scan is essential before uploading file into wordpress through http://ftp.

    2) install some plug-ins which are providing security against hack and attacks

    3) Never share and your ftp password to any one.
    4) Remove version of wordpress from head of index page.

    [Reply]

  5. Martijn Couprie on 11.11.2009 at 2:41 pm | permalink
  6. Lovin’ the WP DB Backup extension. It mails me a backup of the database every friday.

    [Reply]

  7. Senthil Ramesh on 11.12.2009 at 7:59 am | permalink
  8. I am new to wordpress and I have not though of securing it. I will sometimes follow the tips said at Wordpress dashboard.

    [Reply]

  9. Jaydip Parikh on 11.12.2009 at 11:15 am | permalink
  10. I wrote an Article about Wordpress security just after hack attempt to my site. It’s bunch of tips Just visit http://bit.ly/2CNd34

    [Reply]

  11. Case de Vacanta on 11.12.2009 at 11:43 am | permalink
  12. better safe than sorry, right? :)

    [Reply]

  13. Families House on 11.12.2009 at 12:42 pm | permalink
  14. Loving the plugin ‘Login Lockdown’ which you can get here http://wordpress.org/extend/plugins/login-lockdown/

    [Reply]

  15. seojoe on 11.13.2009 at 7:55 pm | permalink
  16. Best tip is to keep the darn thing updated. It’s amazing how often blog’s get hacked and 9 times out of 10 the blog was woefully behind on software updates.

    [Reply]

  17. Keith Davis on 11.16.2009 at 8:31 pm | permalink
  18. Hi Ann
    Looks as though you have already picked the best links to security tips and plugins LOL.

    I’m new to Wordpress and have been made aware of all the security issues by all the upgrades to Wordpress 2.8, currently standing at 2.8.6 and counting.
    So I stopped working on uploading my theme and making my blog look pretty and started looking at security. Both things you can do and plugins you can upload.

    First thing is keep up to date with the latest Wordpress release.

    Second thing is remove the default admin user and create a new admin with secure username and even more secure password, try this site for details http://www.clickonf5.org/wordpress/delete-wordpress-default-admin-user/5447

    Then start looking at plugins…
    Try this one http://devel.kostdoktorn.se/limit-login-attempts
    I think that it is better than login lockdown.

    That’s as far as I’ve gone but I will add a few more security measures before starting to pretty up the site.

    Well done on starting the ball rolling.

    [Reply]

  19. Smoke and Mirrors on 11.17.2009 at 8:49 am | permalink
  20. WP Security Scan is another good one. It scans your site to tell you what security loopholes you have and how to fix them!

    [Reply]

  21. Chiropractic Care St Petersburg on 11.17.2009 at 12:34 pm | permalink
  22. Thanks for share very helpful wordpress plugins and tips. I’ll read it and download this plugin.

    [Reply]

  23. Gerald Weber on 11.19.2009 at 2:20 pm | permalink
  24. I like to IP restrict the WP-admin folder. It is explained how to do this in How to Make WordPress More Secure from Hackers & Robots

    [Reply]

  25. John S. Britsios (aka Webnauts) on 12.06.2009 at 12:52 am | permalink
  26. On my blog searcheditors.com I use the following security plugins:

    Askimet
    Bad Behaviour
    http:BL WordPress Plugin
    Invisible Defender
    Limit Login Attempts
    Spam Karma
    WP Scanner
    Wordpress Firewall Plugin

    I also restrict IP for my WP-Admin folder as Gerald mentioned above. And I also have a lot of additional security rules in my .htaccess.

    [Reply]

  27. Keith Davis on 12.06.2009 at 8:52 am | permalink
  28. @John
    Thanks for sharing your list.
    I recognise most of the plugins but there are a few there that I have not heard of and will certainly take a look at.

    [Reply]

  29. Vinish on 12.07.2009 at 2:10 pm | permalink
  30. Login Lockdown plugin is missing from the above list. It is very useful in Bruce force attacks.

    [Reply]

    Vinish Reply:

    Or rather to avoid Bruce force attacks.

    [Reply]

Leave a Comment

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Bad Behavior has blocked 2349 access attempts in the last 7 days.