Listly by Hans A van Putten
10 Steps to Avoid Your WordPress Site being Hacked includes security protocols, processes, programs and platforms we are using driven by experience and recommendations. It is important to know that although your websites may be hosted on a server, at home, in your office or remotely, the security of your desktop computers, laptops, tablets as well as your phones are just as important. Nowadays, more than ever, all devices are interconnected and as the saying goes "A chain is no stronger than its weakest link", it is crucial to keep ALL devices secure, not just the computers, or phones or websites. One device gets hacked, the risk that all other devices will be hacked is high.
The next steps outline a list of things to do to secure your WordPress Websites, computers and Phones.
Most suggestions are based on our experience with the WordPress sites, Windows Computers and Android and Iphone phones.
Should you need help with any of this feel free to contact us by clicking here.
Source: https://worldwidelocalconnect.com/uncategorized/10-steps-to-secure-your-wordpress-site-and-server/
If you want to ensure the traffic and communication from and to your website is secure and encrypted, you MUST install your Wordpress site using SSL. By installing your WordPress site on a secure server with an SSL certificate, you can show your website URL as "HTTPS:" instead of "HTTP:" signaling to your visitors that your website (communication) is safe. If you use Inmotionhosting as your web hosting platform your can click here to learn how to install your WordPress site on a secure server with SSL. If you are a BlueHost customer click here to do so.
To learn more details on how to install WordPress SSL on Inmotionhosting.com please click here. To learn more on how to install SSL on BlueHost hosted WordPress sites click here.
To secure your WordPress site and files (I'll talk more about your webhost's home directory safety later) I start by implementing and activating the following plugins:
See below for any full-blown security firm like Sucuri. If you start using a malware, ransomware, virus and hacking expert like Sucuri, some of the above plugins may be redundant or even conflicting.
To make sure your WordPress website, your files and your server upon which your website runs is safe, Cpanel has various areas to activate to make sure your environment is secure.
No matter whether it is for security reasons or for "version" reasons, it is good to create backups on a regular basis. Our sites are hosted by Inmotionhosting who offer various ways of backing up your sites.
No matter what your setting are with regard to backups and/or malware and virus security, it is always good to run the native CPanel virus scan. You can run the Virus Scanner manually or you can set up a Cron Job for the ClamV virus scanner. When running the virus scanner, you can set it to run just the Public_HTML folder, just the FTP Folder or the entire home directory. Any malware or viruses found can be quarantined and/or deleted.
Although our WordPress websites were well protected, one of our contacts was massively and extensively hacked. His mobile phone, laptop and desktop were all hacked and compromised. almost 8 weeks later he is still trying to recover. I will dedicate another blog post to explaining what happened and how we cleaned up, secured everything and planned for a secure WordPress future. The moment it happened, we did not know the full scope of the hack and with ID's and passwords on the devices that were hacked, we could not determine fast enough whether our CPanel and our WordPress websites were clean and safe.
Sucury Security partners with Inmotionhosting so we hired them to scan and clean up our sites if necessary. We also retained them on a monthly basis to continue to secure and scan all our sites on an ongoing basis. If you use BlueHost or any other web hosting platform they may use other website security firms.
By securing your computers you reduce the risk of being hacked, and thus the risk of any hacker using ID's and Passwords for your WordPress sites being used to hack those sites and install malware or ransomware. Your virtual world, or as Facebook's Mark Zuckerberg started calling it, "Meta" and Metaverse" is all interconnected. Which is both the good news and the bad news. Interconnection makes our lives easier on the one hand, and the process faster, but on the other hand the easy fast process can overwhelm us and once one section or device is hacked, can open the flood gates to the next device and next device until your ID has been stolen and all your important accounts are highjacked.
We cannot stress enough to have all devices that communicate with each other be tested for security.
As per the previous item on the list it is paramount that you secure all your devices. That includes your phone, which, so I've read and heard is the easiest to hack. Our contact who was hacked not only had his computers hacked but also his phone. That escalated into his ID being stolen and as of this writing, 8 weeks after the initial hack, him still trying to recover various accounts as well as getting a safe, new cell phone.
As we found out during this hack, if both your computers and your phone are hacked, incl. emails, you have a massive 2FA, 2 Factor Authorization problem. Which makes it 10+ times harder to recover any account, whether Amazon, your bank or credit card accounts. More on that in a future blog post.
Whether your websites are hosted on your own server or elsewhere, it is crucial, if you use one, to secure your wireless router with WPA or WPA2 WIFI Protected Access protocols. Additionally ensure your computer operating system is in sync with the wireless router settings and vice versa. If you are local and on your own network your operating system can be more open and share files. If you are in a public environment like an airport, your operating system settings should be more secure closing off the file sharing. If needed use a VPN.
Insurance
Although the list of measures suggested in this blog post is comprehensive it is by no means 100% complete. There are always extra measures that can be taken, but it is a good foundation. If, despite all the security measures you still get hacked it would be good to have insurance in place. ID Theft Insurance will be able to pay for cleanup of your sites, your computers and help with recovering your ID and accounts.
Disclaimer
The suggestions in this blog post are just that, merely suggestions, based on our own experience. The decision to use or not use any of these suggested platforms lies fully with you. WorldWide Local Connect Inc. and any of its associates cannot be held liable for any consequences resulting from the use of the suggested platforms, programs, protocols and services in this blog post.
Here is a list of recent client testimonials. Our Digital marketing Division also handles the WordPress Website Security:
You can see the latest reviews on Clutch.co by clicking here.
Here are a few:
“The knowledgeable suggestions made by WorldWide Local Connect Inc. have helped grow the client’s business, also improving the contracts and benefits their employees get.” Read more…
-Artful Life Counseling Center and Studio
“Exhibiting unmatched development skills, WorldWide Local Connect Inc. successfully created a functional website. As a result, the client generated traffic and orders in just a few months. Moreover, the end client also commended the site positively. The team was communicative, responsive, and skilled.” Read more…
-Babico's Cafe and Grill
“WorldWide Local Connect Inc.’ contributions have been integral to the client’s success. They continue to provide a ton of value to the partnership by remaining accessible, constantly bringing new ideas to the table, and helping the client resolve strategic issues beyond the scope.” Read more…
-Covalent Bonds
“Thanks to Worldwide Local Connect Inc.’s efforts, the traffic increased significantly. The team communicated excellently, keeping the client updated with the project’s progress. Overall, they were responsive and proactive.” Read more…
-Massage Visits