Following on from my previous post on WordPress still being relevant, I wanted to focus on WordPress security, especially after all the doom and gloom being spread on social media about hacks and bugs. This article is aimed at SMEs.
No website is completely secure, and that’s where your security thinking should start
No website is fully secure, and that should be your starting point. Financial institutions spend millions on security and still get hacked, so my first piece of advice is always the same: don’t put anything sensitive online, and if you have to, think carefully about what its exposure would actually mean.
Generally speaking, you’re looking at two types of attack, your site being taken over or data being stolen from it, and prevention for both is largely the same.
Lock down the basics: login, 2FA, admin path
First, address the obvious. Setting your admin username to “admin” and your password to “password” still leaves the door wide open. Beyond that, changing your admin path is another simple but effective measure, along with enabling 2FA (two factor authorisation). These are straightforward precautions every site owner should take.
Keep WordPress, plugins and your host updated
Keeping your WordPress installation up to date is vital. Recent versions allow for auto updates, and it’s an option well worth enabling if you haven’t already. The WordPress team constantly monitor security and release patches, so it’s worth also keeping an eye on your host to make sure their servers stay up to date.
Beyond the WordPress core, your plugins need to be kept updated too, and again these can often be set to auto update. Old or no longer supported plugins are a risk in themselves. If your site has these, look at replacing them. The installation panel shows you the number of installs, rating and last updated date for each one, which makes it easy to spot the ones worth dropping.
Add a proactive layer: Wordfence and Patchstack
Once your login is secure and you’re keeping on top of updates, there are proactive steps worth taking. Wordfence is a solid security plugin and one I’d always recommend, with several price points, though even the free version is well worth having. The setup can look a little daunting at first but follows a logical path. Signing up to their newsletter gives you useful updates on vulnerabilities, which matters most if you don’t have a maintenance agreement and you’re managing the site yourself.
Patchstack is another resource worth looking at. Once set up, it actively patches vulnerabilities as they occur, which is exactly what the name suggests. It’s subscription based, but worth the outlay.
Always backup
Make sure your host is taking regular backups of your site. If the worst happens, that backup is what gets you back up and running.
This is a general article offering simple advice, guidance and awareness raising. Other security plugins are available and may suit your setup better. If you have concerns, speak to your developer or hosting company.