[big]WordPress websites account for nearly 20% of ALL websites on the internet. While there are many Content Management Systems to build a site on (and no cms at all), WordPress is the big dog for a reason. It’s easy to get up and running, there is a huge eco-system of themes and plugins, and website owners find it extremely easy to use.[/big]
WordPress is almost always a fine choice of CMS for your next website; but it’s important to understand how to keep your website safe from malicious attacks.
Because WordPress is so popular, many black-hatted shady individuals target the platform for ways to exploit it. Many attacks on your site fall into these main categories:
The good news is you can mitigate ALL of these strategies with some smart planning, strong theme and plugin development practices, and some common sense.
Brute Force attacks are typically handled on the server itself – all servers should have a firewall (ours do!) that will identify multiple, repeated login attempts for a given username, or originating from a similar place. The firewall will throttle these attempts, or even block them for a period of time, and reduce the overall sluggishness caused by your website having to deal with so many login attempts. While that’s good news, it’s still important as a website owner to ensure your website is un-brute-forceable! Some easy things for you to do:
First of all, don’t panic. Hacks happen, and it does suck – a lot. But if you’re hosted with Eggplant on our Managed Hosting plan we’ll take care of it for you, and restore your website back to its original state as best we can. If you’re not on the plan, don’t fret either – we’ll still help you out. Just Contact Us!