{"id":3351,"date":"2015-11-24T14:00:46","date_gmt":"2015-11-24T12:00:46","guid":{"rendered":"https:\/\/www.reliablesoft.net\/?p=3351"},"modified":"2021-06-28T22:20:25","modified_gmt":"2021-06-28T19:20:25","slug":"how-to-protect-your-wordpress-website-from-hackers","status":"publish","type":"post","link":"https:\/\/www.reliablesoft.net\/how-to-protect-your-wordpress-website-from-hackers\/","title":{"rendered":"How to Protect Your WordPress Website From Hackers"},"content":{"rendered":"
The growing popularity of WordPress has also created more interest among hackers. Statistics show that out of the 80 million websites powered by WordPress, a large portion of them (70%+) \u00a0are vulnerable to attacks.<\/p>\n
If you think that your website is not part of the 70%, you are wrong. If you also think that nobody cares about your small business website or blog, you are again wrong. Attacks can happen because your site is vulnerable to attacks and not because a hacker decided to \u2018break-into\u2019 your business.<\/p>\n
When your website is hacked, a lot of bad things can happen besides damaging your website\u2019s reputation. You can lose customers, traffic, money, confidential information and not to mention the time, stress and effort that it will take to clean your website and get it back to a normal state.<\/p>\n
Those that experienced this at least once, know exactly what I mean. It\u2019s those times that you wished you have taken preventive measures instead of trying later to recover from the damage, especially when your income and business depends on your website.<\/p>\n
To tell you truth, I didn\u2019t bother about security, I was thinking like most people that this would never happened to my websites. But it did. And it was a terrible experience.<\/p>\n
A few of my clients had faced similar issues and they lost money and business but at least we all now learned our lesson. When it comes to security issues, \u201cPrevention is the best cure\u201d.<\/p>\n
If you have a WordPress website but did not take any measures to improve security, it\u2019s now the right time to take action. Don\u2019t delay it any longer but set this as your first priority above SEO or anything else you might be doing.<\/p>\n
It won\u2019t take you a lot of time but it can save you a lot of time, money and frustration in the future.<\/p>\n
#1 – Install Sucuri<\/b> \u00a0– I know that this may sound overly promotional for some but those following my articles know that I don\u2019t recommend something (especially if it\u2019s a third party service), unless it is very important and useful and sucuri<\/a><\/strong> is one of them.<\/p>\n In a few words, sucuri is a company that offers security services to websites (not only WordPress). They help you ‘clean’ and recover your website in case it is affected by malware but at the same time they offer a number of tools for securing and hardening your website so as not to get into trouble in the first place.<\/p>\n I have used sucuri a number of times for both my website\u2019s and also my clients . One of the things I really like is that in case your website is compromised and affected by malware, all you have to do is register an account with them, submit a malware request and they take care of the rest in a reasonable amount of time.<\/p>\n Instead of spending time wondering what happened and searching the Internet to find ways to clean your website and recover your business, leave this to sucuri and spend your time following the prevention measures explained below to avoid having to deal with the same situation again.<\/p>\n A final note before getting into the features of sucuri and how to use them, is that Google in their guide for\u00a0hacked sites<\/a><\/b>\u00a0are also recommending sucuri for prevention and protection and so does the official WordPress website in their hacked sites FAQ<\/b><\/a>.<\/p>\n Which package to use? <\/b>They have 3 packages but for most of the cases you only need to register for the BASIC plan<\/a><\/strong> which is less than $18 per month.<\/p>\n This will give you access to their malware removal service in case you need it and also their website antivirus prevention tools.<\/p>\n Follow the simple steps below to activate sucuri on your WordPress website:<\/p>\n The first step is to register for the basic plan<\/a><\/strong> and then ‘Add your website’ to the dashboard.<\/p>\n <\/p>\n Next,\u00a0you need to configure the \u2018Server Side\u2019 Scanner by giving them access via FTP to your website files and directories. The server side scanner is what will monitor your website (several times per day),\u00a0identify\u00a0affected files and also perform cleanup actions if needed.<\/p>\n <\/p>\n You can either enter your FTP credentials in the ‘Enable Via FTP’ option or use the ‘Enable Manually’ by downloading the file provided and uploading it to your root folder.<\/p>\n The file method is better in case you decide to change your FTP credentials, you won’t break the functionality.<\/p>\n Install and configure their WordPress Plugin. Install the sucuri plugin from here<\/a><\/strong> (like you do with a normal WordPress plugin) and then go to dashboard and connect it with your sucuri account.<\/p>\n <\/p>\n Once you perform the above steps successfully, sucuri is actively protecting your website.<\/p>\n What you can \u00a0do now is click the SETTINGS<\/strong> (under Sucuri Security) and configure your settings as shown in the screenshot below.<\/p>\n <\/p>\n This will ensure that you will get notified by email for any changes to your website files\u00a0or\u00a0any\u00a0failed login attempts. In addition, it will also activate the web firewall feature that automatically blocks suspicious IP addresses from attempting to login to\u00a0Wordpress.<\/p>\n Go to Dashboard<\/strong> (under Sucuri Security) and you will be amazed how many bots try to gain access to your website.<\/p>\n There are many other settings you can review (under Sucuri Security) but the above in combination with the steps described below will dramatically improve the security of your WordPress Website.<\/p>\n #2 – Use strong passwords<\/b> – One of the things you definitely need to check right now is your wordpress passwords and especially the password you use for the administrator.<\/p>\n Don\u2019t use simple, letter only passwords, but create strong passwords that include letters, numbers and symbols.<\/p>\n Here are a few examples of simple and strong passwords:<\/p>\n