Monday, February 11, 2013

Improve your WordPress security with this checklist + Download

WordPress-Logo WordPress to be one of the most popular CMS for new sites. Not only is it easy to use, it also comes with lots of plugins and themes for you to choose, so it is very customizable. However, like all other popular platforms are also more vulnerable to hacking. For those who are not sure how to strengthen the security of your WordPress, here is a checklist for you to follow to keep your site safe.


1. Secure connection

best way to stop hackers is to prevent their entry into your site. You can use the plugin Lockdown connect simple locks may limit the number of login attempts from different IP within a certain time. This will help prevent hackers from brute force attacks. You can also add two-factor authentication, which prompts you to insert additional code to connect. For those who feel uncomfortable with the user name, you can login with your e-mail address, which may be more difficult for a hacker to guess

.

WordPress word

For the most extreme, changing the name of” wp-login.php “file to something else (like” log-in.php “) to hackers do not know the correct login URL. You can change this via an FTP client.


2. connect Remove link from theme

.

Some WordPress themes have link connection on the theme of easy access to the login page. No need to advertise your login page and invite everyone, especially hackers to access it. Either remove link connection from the subject, or if you can not delete, move to another theme

3 .. Add password authentication in the file wp-admin. this is something that many the most popular sites are made. Add a password to the file “wp-admin.” Anyone who has access to this folder will need to enter the username and password are correct (other than connection user)

. easiest way to add

authentication password is CPanel. Login to your CPanel and select “Password Protect Directories” option

. wp-security-password-protect-directory

4. Do not use themes from untrusted sources. There are a lot of really great and interesting themes out there, and you can access it from any Google search simple. The problem is not all the themes that are safe to use, and some are not good code

To find a topic worthy of confidence.

1. Search from the WordPress theme repository. All subjects in the repository are carefully checked by a team of WordPress, so they will be safe to use.

2. Search through a market leader like ThemeForest

3 .. Buying a premium theme like Genesis, Catalyst, etc. This theme is well supported by developers and has a great community to help you

.
5. Updates WordPress themes and plugins to the latest version

Tim and WordPress plugin developers. Work hard to ensure their safety and WordPress plugin, but you can reap the rewards of their hard work if you continue to upgrade to the latest version. If you are in an old building or WordPress plugins or themes, there may be a security hole waiting to be exploited.

Update WordPress

6. Changing the default prefix table in the WordPress database

.

WordPress using a prefix that has been assigned to your database so that it can differentiate itself from the database. Default prefix is ​​”wp_.” The best way is to change to a different prefix so that hackers can not hack your database easily.

For the installation of a new WP, you can change the table prefix in the file “wp-config.php” (you need to change it before installing WordPress)

. wp-security-change-table-prefix

For WordPress existing user, you can follow the instructions here to change your table prefix

.
7. Change the default administrator account

If you have been using WordPress since the beginning, chances are you still using the administrator account is “admin” user name. One way to protect yourself is to create an additional account with username admin and delete the default “admin”. Use the new administrator account for administrative work and never publish the article with your account (you can set up accounts Editor for this). It is more difficult for a hacker to get your hands on your administrator user name.


8. Implementing SSL for WordPress Admin

.

SSL connection is used to prevent others from listening to your login and access your data over the network. You can connect your host and get them to implement SSL for WordPress admin area

.
9. Analyze your site regularly for viruses and malware

Anti-virus for WordPress plugin can scan your site for viruses and malware. Plugins like WordFence, Sucuri, WP Security Scan, VIP and Exploit Scanner Scanner scanner all useful plugins

.
10. Use passwords

same old rule applies: choose a password with uppercase and lowercase letters, numbers and special characters. It also had nothing to do with the anniversary, birthday, address, etc. must also be changed often

.
11. Perform regular backups of WordPress

.

This is a precaution so that if your site is hacked and destroyed, you can always restore from backup

. WordPress Plugins-

A plugin is a useful BackWPup backup allows you to save your site to various cloud services

.
12. Uninstall and remove unnecessary plugins and themes

If something becomes obsolete on your site, such as themes or plugins, make sure to remove them immediately. They are old plugins and themes are not as safe as newer. Also, make sure you do not leave files around which could provide relevant information

.
13. Check your hosting

.

It is not part of WordPress, but the server that hosts your website can help with WordPress security. Make sure your web host worth his salt. Some hosts offer hosting packages cheap for a reason, and you often have to pay for it by other means (eg, a slow network, the time spent fixing hacked websites etc). . Make sure to read reviews and check depth of the host (and make sure they implement all necessary safety measures) before committing your money to

Above all, do not forget three rules proposed by WordPress – restrict access , detention , and preparation and knowledge . If you keep the basic rules and run through this list, your efforts on WordPress security and protect your site from hackers succeed

.
Download

We have compiled this list in a PDF file so that you can easily store and access. Download here

What other ways that you use to protect your WordPress site.?



Improve WordPress Security With this checklist Download +

……….

0 comments: