wordpress safety

How secure is your WordPress site?
Hackers are constantly looking for, and discovering, vulnerabilities in WordPress and in the plugins that are used to extend functionality in WordPress. Any out-dated plugin or version of WordPress is a potential vulnerability. So what can you do to ensure your WordPress website is kept secure?

wordpress safety

1. Always update your version of WordPress as soon as a new version is released.
If you log into your admin panel you will see an alert if your version of the software needs an update. Clicking the “update Now” button will update for you… simple!
We do, however, recommend backing up your files and database before you do this, just as a precaution. Sometimes plugins do not keep pace with new versions of WordPress and an update could mean they stop working.

2. Always update all plugins as soon as you see the update warnings. Again, this is really simple to do – just click the “Update Now” link under each plugin listing. You should check that they are compatible with the latest version of WordPress. If not, you may need to find an alternative.

3. Uninstall any plugins that your site is not using. These will be a potential vulnerability if not kept up to date along with those your site IS using. Why keep them if they are unsed?

4. Only ever install plugins that are listed on the WordPress.org Directory. The Directory blocks plugins that are found to distribute spam and warns of vulnerabilities that are found in any of their listed plugins. Vulnerable plugins are removed from their listing until the weakness is patched.

5. Always update themes when they are flagged for updating. New WordPress one-click installations come with up to 3 standard themes. There is no benefit to keeping all these on the site, so uninstall at least 2 of them. Make sure you update any themes whenever a new version is released.

6. Don’t download and install “premium wordpress themes” for free. It is easy to find links allowing the download of themes that should be paid for, but are being offered for free. Apart from the fact that it is dishonest to do this, it is a dangerous thing to do. This is a way for hackers distibute malicious code, malware and spam links.

7. Only install free themes listed on the WordPress.org directory for the same reason as plugins from their directory.

6. Install the security plugin “Wordfence”. This is a superb plugin which will email you alerts when there is any activity on the admin panel of your site. It scans Core, Theme & Plugin files looking for malware and if it finds a vulnerability, it emails to let you know. It also alerts you to  attempts to log into the admin panel.  In the event of you being attacked, you can even use Wordfence to help find and eradicate the hacked files. You can find out about the features on the free and premium versions of Wordfence here.

7. Hide your admin-login panel. The plugin “Lockdown WP Admin” By Sean Fisher allows you to change the url of your login panel.