outsourcewebdesign.in

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 5 July 2012

How to secure your WordPress Website

Posted on 02:07 by Unknown

Running a website based on WordPress is often a pleasure, enabling you to focus on content and building relationships with readers and other websites. However, not everyone on the web is as friendly as you. Somewhere out there is a list with your blog’s name on it, where it sits, waiting to be targeted by hackers. When they get around to your blog, they’ll try various tactics to gain access to it, perhaps with the aim of selling illegal drugs or infecting your visitor’s computers with malware.

Fortunately, there are various ways in which you can protect your WordPress blog from hackers.

Regularly Update WordPress

One of the most powerful but oft-overlooked solutions for keeping WordPress safe from hackers is to make sure it is regularly updated.
Obviously there is a down-side to this – some of your plugins might stop working if WordPress is updated – but at the same time it should be looked upon as an opportunity to refresh your plugins, find replacements that are secure and reliable and basically tighten up your website or blog. Sticking to plugins that are found in the WordPress directory is also a good way to keep things under control.
Updating WordPress is possible from within the Dashboard, but always take a backup of your database before doing so.

Keep Regular Backups

An important procedure for all WordPress blog owners is to ensure that backups are taken regularly and that they can easily be restored should the worse happen.
Solutions are plentiful, but Cloudsafe365 is one of the most powerful, combining cloud backup (Dropbox can be used) with various secure protection tools against techniques such as cross site scripting, SQL injection, and even monitors content theft.

Install an Encrypted Login Plugin

 

Protecting the actual act of logging on to your WordPress website is best effected by using an encrypted login plugin, as the website software doesn’t have this facility by default. Probably the best solution for this – perfect for protecting your blog login details from packet sniffers on wireless networks – is Chap Secure Login, which uses the SHA-256 algorithm to protect your username and password.
Meanwhile the Login Lockdown plugin is an useful way of blocking IPs that record repeated failed attempts to access your site.
Other login protection steps you can take includes installing a strong CAPTCHA  plugin. RetinaPost is a particularly impressive plugin, requiring users to enter highlighted characters from a phrase rather than try and decipher screwed up text images or do Maths challenges. Any attempts to disrupt your blog using the comments system can be markedly reduced using this plugin.

Hide “Powered by WordPress”

 

Hackers have a different tactic for each of the various types of website software that is in use, but you can make things tougher for them by not advertising the fact that your website is “Powered by WordPress”.
By default this information can be found in the footer.php file, reached by entering your blog’s Dashboard, selecting Appearance > Editor to edit within the browser window. Different themes will require different methods for removing this text, so you should check online to find the best approach (if plain text is used to display the legend, then delete this; if PHP code is used, tread carefully unless you know what you’re doing).

Change Admin Username

 

One way in which hackers can find a way into your site is by using brute force software that will attempt multiple logins using common words and phrases as passwords, coupled with a selection of obvious usernames.
The administrator username in WordPress can be selected when the software is setup, but in the rush to get things done many users leave it at the default choice of “admin”. As obvious usernames go, this comes at the top of the list, which is why changing it is important.
Two ways exist for changing the admin username. First, you can create a second administrator account with a username which isn’t obvious, and then delete the original user. Note, however, that this might have an effect on any articles written under the administrator account (they’ll perhaps be unpublished until a new name is set, or display an error on the post page).
Probably the most effective way to do this is to access your site’s phpMyAdmin, select the WordPress database, find the wp_users table (“wp_”is a default prefix which may have been changed at installation) and use the Browse icon to find the “admin” username.
Once discovered, find the user_login column, click the edit button on the appropriate row and then change “admin” to your preferred administrator account login name, clicking Go when you’re done.

Move the wp-config File

 

A glaring issue with WordPress is that the key security details are stored in a single, unencrypted file that can be hacked and used to take control of your blog. The wp-config.php file contains the admin login details as well as the username and password for the MySQL database.
Therefore, securing this file is paramount if you wish to protect the site from hackers.
One thing you shouldn’t do, however, is delete wp-config – this would leave your site unusable (and rather blank).

Conclusion

 

Regardless of how technical or non-technical you are, if you run a WordPress blog there is no excuse not to implement any or all of these tools to protect your website from hackers.
After all, what is the point in putting in all of that hard work only to find that someone has taken over the site and is now costing you your regular visitors by advertising Viagra?
These steps can be implemented in just a couple of hours – perhaps a single weekend morning if you’re pressed for time – so don’t ignore, act now.

Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Open Source E-commerce Solution – Is it the right choice?
    This is the age of technology and technology has made inroads in almost every aspect of our lives. Technological advancements have certain...
  • Responsive Web Design
    Desktop, Smartphone, Tablet, today we’re designing for more de­vices, input types and resolutions than ever before. Determining which device...
  • Requirements and Specifications - Part III
    Flow or Logic Diagram Flow diagrams   define the end-user’s paths through the site and site functionality. A flow diagram for an e-commerce ...
  • Some Tips before you venture out to develop a Travel Portal
    Portal Development is a system containing web functionality which provides features so as to authenticate, rectify and identify the person u...
  • Outsource Web Design services
    You have finished dreaming and thinking about your website and have it all planned but are unsure of your next steps. This is the time when ...
  • Landing Page Optimization For Google Adwords
    Having a good quality score is very important for Google Adwords. You might not know it but, your landing page could be lowering your qualit...
  • Pointers for a successful company strategy
    Strategy is the art of doing the  right things  at the  right moment . Do you have a written company strategy? No? This is disastrous: Only ...
  • WordPress Plugins for Directory
    WordPress is a highly customizable CMS. Using a plugin, you can easily turn your website to a directory system. Take look at a few WordPress...
  • Static Website or Dynamic Website - Which one should you choose?
    Websites are built for different purposes, one could be to sell a business’ products online, or simply as a brochure to show potential custo...
  • Why is Social Media Important?
    Social media is now a part of everyday life. Some statistics suggest that over 20% of adults visit a social website every day, and business ...

Categories

  • Graphic Design
  • Logo Design
  • Magento
  • Open Source
  • Open Source Customization
  • OsCommerce
  • Web Design
  • Web Development

Blog Archive

  • ►  2013 (8)
    • ►  August (1)
    • ►  July (4)
    • ►  May (1)
    • ►  March (2)
  • ▼  2012 (54)
    • ►  September (2)
    • ►  August (6)
    • ▼  July (20)
      • Requirements and Specifications - Part III
      • Requirements & Specifications - Part II
      • Requirements & Specifications - Part I
      • Having a Proper Search Engine Strategy is very imp...
      • WordPress Plugins for Directory
      • Why you should Hire a Web Design Company from India
      • How to build great client relationships
      • How to hire the best web design company in India
      • The Evolution of High Position
      • How to plan and build a Responsive Website
      • Introducing EMR solutions from AMS Technologies
      • Why is Quality Assurance Important?
      • Why is Positive Company Culture so Important?
      • Why is discipline important to succeed in business?
      • How to secure your WordPress Website
      • Start Innovating To leave the competition behind
      • Knowing your competitor
      • Choosing the best CMS
      • Money Back Guarantee - Why is it so important?
      • Responsive Web Design
    • ►  June (16)
    • ►  April (5)
    • ►  March (2)
    • ►  February (2)
    • ►  January (1)
  • ►  2011 (4)
    • ►  May (2)
    • ►  April (2)
  • ►  2009 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile