{"id":3954,"date":"2014-06-08T09:10:09","date_gmt":"2014-06-08T14:10:09","guid":{"rendered":"http:\/\/www.killersites.com\/blog\/?p=3954"},"modified":"2014-06-08T09:21:07","modified_gmt":"2014-06-08T14:21:07","slug":"how-to-make-wordpress-more-secure","status":"publish","type":"post","link":"https:\/\/www.killersites.com\/blog\/2014\/how-to-make-wordpress-more-secure\/","title":{"rendered":"How to make WordPress More Secure"},"content":{"rendered":"<p>A lot of people use WordPress and WordPress is hacked all the time. How do you prevent WordPress from being hacked? My top 4 things to do:<\/p>\n<ol>\n<li>Great passwords that contain both upper and lower case letters, numbers and a symbol or two like underscores, dashes etc.<\/li>\n<li>Keep WordPress up to date! Fortunately in 2014, WordPress can be set to auto update. Do it and save yourself headaches.<\/li>\n<li>Don&#8217;t use plug-ins unless you absolutely have to. Do some research to be sure that they are safe and secure. <\/li>\n<li>Delete any unused themes. WordPress comes installed with a few themes &#8230; delete them because they could be a place for hackers to drop in malicious PHP files. <\/li>\n<\/ol>\n<p>I recently had an old WordPress based site hacked and though I had updated it to the latest version of WordPress, will still found a malicious PHP file in this folder:<\/p>\n<p><code>\/wp-includes\/images\/smilies\/ajax.php<\/code><\/p>\n<p>&#8230; Yes, inside the images folder. That&#8217;s one example of where these bastards will stick their malicious code. Remember, they don&#8217;t want you to find it. We don&#8217;t know for sure but I am guessing they got in the file BEFORE I updated WordPress. <\/p>\n<p><strong>Final Comments<\/strong><br \/>\nI have to tell you that over the years, the few times we&#8217;ve been hacked &#8230; it&#8217;s always been via WordPress. <\/p>\n<p>We are really reconsidering our use of WordPress, since it can be such a liability. We are asking ourselves, how much does WordPress really bring to the table(?) and weighing that against the risks. <\/p>\n<p>BTW, I am not picking on WordPress, all the major CMS&#8217; out there (Drupal, Joomla) are major points of attack. The open nature of these products, makes them that much easier to hack than closed-sourced (code is not public) private software. <\/p>\n<p>For our new projects, we are rolling out our own blog tool &#8211; with all the advanced PHP frameworks out there and given that our needs are fairly simple, it makes sense to us.<\/p>\n<p>If you do end up using WordPress, be sure to follow the above steps. <\/p>\n<p>I hope that helps,<\/p>\n<p>Stefan Mischook<br \/>\nkillerSites.com<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A lot of people use WordPress and WordPress is hacked all the time. How do you prevent WordPress from being hacked? My top 4 things to do: Great passwords that contain both upper and lower case letters, numbers and a symbol or two like underscores, dashes etc. Keep WordPress up to date! Fortunately in 2014, &hellip; <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33,34],"tags":[],"_links":{"self":[{"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/posts\/3954"}],"collection":[{"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/comments?post=3954"}],"version-history":[{"count":11,"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/posts\/3954\/revisions"}],"predecessor-version":[{"id":3965,"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/posts\/3954\/revisions\/3965"}],"wp:attachment":[{"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/media?parent=3954"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/categories?post=3954"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.killersites.com\/blog\/wp-json\/wp\/v2\/tags?post=3954"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}