WordPress security has been a hot topic for years. As the most popular CMS in the world – it has a fairly large target on its back. But it’s not just WordPress you need to focus on when mitigating website security. Hosting, plugins, user role management are just a few area’s where vulnerabilities can be exploited. Your site’s security is as strong as its weakest link. Your developer and host provider should offer the best advice when it comes to site security. Below are some simple ways you as a site owner can manage:
- Backups! – OK so this isn’t technically going to keep your site secure but it’s going to be the first thing you’ll need should anything go wrong – and that’s why it’s top of the list. Ideally, your host provider will be backing up your site every day and storing those backups for at least 30 days. Also – check on what the recovery process is. Will they roll the site back for you? do you need to download the backups yourself? There’s no point in having backups if you can’t easily restore them. If you arent confident about your host providers backups – use a plugin. Blogvault and UpdraftPlus are great options
- Update update update – Regularly updating WordPress, plugins and themes has become much easier to do in recent years. There are also some great tools to manage this with less risk – such as WPengine’s Smart Plugin Manager. Updates are released frequently by WordPress and plugin developers to enhance features, performance and security. At the very least enable auto-updates for plugins to keep on top of new releases. Just make sure you have backups available in case you encounter a conflict with any new updates.
- Harden security with plugins – There are quite a few security plugins to choose from these days. WordFence is our go-to for most WordPress sites. But every site is different with its own set of issues and restrictions to consider. However, there are some common things we want in a security plugin:
- Basic Firewall protection
- Ongoing monitoring/scanning for malware and irregular file changes
- Blacklist monitoring against dodgy IP behaviour
- User Roles. How many administrators have you got lurking in your list of users? Ask yourself: does everyone on this list need access to everything in the admin area? In most cases no. Commonly only the site owner and developer should have full access to the admin area. WordPress comes with different user roles already available. When adding someone to the admin area – start them off on a low privileges role and promote up when necessary. You can find a list of the roles on wordpress.org. If you do need a lot of administrators consider implementing two-factor authentication.
- Amp it up with Cloudflare – What is Cloudflare? – The really short version – it’s a service providing features to harden security and improve site performance. Long version – read here. We recommend Cloudflare for all sites – not just WordPress. Even the free version comes with a great Firewall to help protect your site. The Pro version takes it a few steps further where you can also benefit from performance features to speed up your site. Think of it as an accessory to your hosting solution.
The security of your site is an ongoing exercise, it’s never done. If you want to keep strong you have to maintain it regularly.