WordPress Security: The First Thing You Should Understand

Wed, May 6, 2009

WordPress

. . . is that people are looking to hack your site.

It doesn’t matter if your site is about how to make cookies or if it’s about blogging, if they can find your blog and you keep it easy for them to gain access, it’s only a matter of time.

Not convinced hacking is a real issue? Try this search (opens in a new window). Look at how many returned results Google found.

Most new bloggers have a lot to learn when it comes to blogging. The typical beginner’s learning process starts with learning about hosting a blog, how to use WordPress, how to write blog articles, and other things bloggers typically do, like social networking.

What they don’t realize is blog security is a big issue. No one ever thinks their blog will be hijacked. I’ve spent quite a bit of time in the WordPress Forums and I can’t tell you how many people come there with requests for help because their blog had been hacked.

There are ways to better protect your blog, but realize this: Nothing is full-proof. The best we can do is create a series of road blocks, U-turns, and immediate notifications that something has changed on our blogs.

Why is WordPress widely targeted?

Because out of the box each WordPress installation looks exactly the same and because it’s open source, would-be intruders can then get to know the program really well and test it for security holes. Now don’t be worried that WordPress is not a secure blogging platform – it is.

But there are two things you absolutely must do. You must create yourself a strong password and as soon as WordPress comes out with a new release, you need to upgrade immediately.

This article is not meant to scare you, but rather meant to try and open people’s eyes to the fact that this is an every day problem and with a little knowledge, you can limit the chances your blog will one day be hacked.

I plan to write more articles on this subject. If you’re interested in this subject, click on the blog security tag in the sidebar’s tag cloud to view related articles, or even better, subscribe to our blog.

If you clicked the blog security link above (or here), you’ll see that WP Blog Host offers blog security upgrades. Contact us today and let us help you add layers of security to your blog. The contact form is sent directly to me.

Related posts:
  1. 2 Killer WordPress Security Plugins You Probably Don’t Know About
  2. Increase Your WordPress Blog’s Security By Running It Through SSL
  3. 2 Easy Ways To Set Up A WordPress Firewall
  4. 6 Things I Tell People Who Are Looking To Start A Blog
  5. How To Install WordPress Manually and Why Beginners Should Do It

, ,

Want to say thank you? View my Wish List...

9 Responses to “WordPress Security: The First Thing You Should Understand”

  1. Cath Lawson Says:

    Hi John – that is scary. I noticed on the front page of that search that Matt Cutts was even hacked.

    When I first started blogging I didn’t have a clue how easy it was for someone to hack a blog. I guess that because the basics seemed so complicated, I just didn’t think anything that complicated was possible.

  2. John Hoff Says:

    Hi Cath. Yeah pretty bad when even the big guy over at Google gets his blog hacked.

  3. Jim Gaudet Says:

    This advice should go for your computer as well. KEEP IT UPDATED!!

    I can tell you that I spend most of my time updating my clients computers (or installing WUS if they will let me).

    Jim Gaudet’s last blog post..Tuts Plus – Mad Skills

  4. John Hoff Says:

    Good point, Jim – especially if your computer is connected to the Internet whenever it’s turned on (like on a cable modem).

  5. Jim Gaudet Says:

    Ok John, do you know anyone who isn’t connected to the ‘net nowadays?

    Cath, nice to see you somewhere besides your blog or mine. :)

    The thing about Cutts is; You have to understand that if someone/some group is after you, you will be hacked… Unless you do nothing but security.

    Most people, including me sometimes (really only WP, my network and systems are pretty secure, don’t test me :) ), tend to not think about security the way it should be. We think that the software will take care of us, but then we don’t upgrade our software.

    It’s a world built for hackers!

    Jim Gaudet’s last blog post..UC Berkeley Computers Hacked, 160,000 at Risk

  6. John Hoff Says:

    You’re right, Jim. Nothing is 100% full proof. Luckily most hackers are simply looking for easy targets. Most of those hackers are just kids at home with a few things they’ve learned along the way.

    The key there is for us to try and hide our login pages from view of search engines and other users. Also, we need to customize our cookie-cutter blogs some so hacks that work on other blogs won’t work on ours. (like I’m sure you already know)

    But yep, if someone is a real pro and dedicated to this, no where really is safe.


Trackbacks/Pingbacks

  1. [...] I mentioned in my article, WordPress Security: The First Thing You Should Understand, a simple Google search for “My Blog Was Hacked” will (now) return 716,000 results. [...]

  2. [...] you think your blog isn’t important enough to be hacked, you need to check out Wordpress Security – The First Thing You Should Understand. And if you don’t have time to protect your blog from hackers, or you’re too lazy, John [...]

Leave a Reply

CommentLuv Enabled
PHVsPjxsaT48c3Ryb25nPndvb19hZHNfcm90YXRlPC9zdHJvbmc+IC0gdHJ1ZTwvbGk+PGxpPjxzdHJvbmc+d29vX2FkXzMwMF9hZHNlbnNlPC9zdHJvbmc+IC0gPC9saT48bGk+PHN0cm9uZz53b29fYWRfMzAwX2ltYWdlPC9zdHJvbmc+IC0gaHR0cDovL3dwYmxvZ2hvc3QuY29tL2Jsb2cvd3AtZmlsZXMtZ3JlZW5ibG9nL3dwLWNvbnRlbnQvdGhlbWVzL2ZyZXNobmV3cy9pbWFnZXMvZWluc3RlaW5zaG93LWFib3V0LXdwYmxvZ2hvc3QzMDB4MjUwLmpwZzwvbGk+PGxpPjxzdHJvbmc+d29vX2FkXzMwMF91cmw8L3N0cm9uZz4gLSBodHRwOi8vd3d3Lndvb3RoZW1lcy5jb208L2xpPjxsaT48c3Ryb25nPndvb19hZF9pbWFnZV8xPC9zdHJvbmc+IC0gaHR0cDovL3d3dy53b290aGVtZXMuY29tL2Fkcy93b290aGVtZXMtMTI1eDEyNS0xLmdpZjwvbGk+PGxpPjxzdHJvbmc+d29vX2FkX2ltYWdlXzI8L3N0cm9uZz4gLSBodHRwOi8vd3d3Lndvb3RoZW1lcy5jb20vYWRzL3dvb3RoZW1lcy0xMjV4MTI1LTIuZ2lmPC9saT48bGk+PHN0cm9uZz53b29fYWRfaW1hZ2VfMzwvc3Ryb25nPiAtIGh0dHA6Ly93d3cud29vdGhlbWVzLmNvbS9hZHMvd29vdGhlbWVzLTEyNXgxMjUtMy5naWY8L2xpPjxsaT48c3Ryb25nPndvb19hZF9pbWFnZV80PC9zdHJvbmc+IC0gaHR0cDovL3d3dy53b290aGVtZXMuY29tL2Fkcy93b290aGVtZXMtMTI1eDEyNS00LmdpZjwvbGk+PGxpPjxzdHJvbmc+d29vX2FkX2ltYWdlXzU8L3N0cm9uZz4gLSBodHRwOi8vd3d3Lndvb3RoZW1lcy5jb20vYWRzL3dvb3RoZW1lcy0xMjV4MTI1LTQuZ2lmPC9saT48bGk+PHN0cm9uZz53b29fYWRfaW1hZ2VfNjwvc3Ryb25nPiAtIGh0dHA6Ly93d3cud29vdGhlbWVzLmNvbS9hZHMvd29vdGhlbWVzLTEyNXgxMjUtNC5naWY8L2xpPjxsaT48c3Ryb25nPndvb19hZF91cmxfMTwvc3Ryb25nPiAtIGh0dHA6Ly93d3cud29vdGhlbWVzLmNvbTwvbGk+PGxpPjxzdHJvbmc+d29vX2FkX3VybF8yPC9zdHJvbmc+IC0gaHR0cDovL3d3dy53b290aGVtZXMuY29tPC9saT48bGk+PHN0cm9uZz53b29fYWRfdXJsXzM8L3N0cm9uZz4gLSBodHRwOi8vd3d3Lndvb3RoZW1lcy5jb208L2xpPjxsaT48c3Ryb25nPndvb19hZF91cmxfNDwvc3Ryb25nPiAtIGh0dHA6Ly93d3cud29vdGhlbWVzLmNvbTwvbGk+PGxpPjxzdHJvbmc+d29vX2FkX3VybF81PC9zdHJvbmc+IC0gaHR0cDovL3d3dy53b290aGVtZXMuY29tPC9saT48bGk+PHN0cm9uZz53b29fYWRfdXJsXzY8L3N0cm9uZz4gLSBodHRwOi8vd3d3Lndvb3RoZW1lcy5jb208L2xpPjxsaT48c3Ryb25nPndvb19hbHRfc3R5bGVzaGVldDwvc3Ryb25nPiAtIDEwLWdydW5nZWZsb3JhbC5jc3M8L2xpPjxsaT48c3Ryb25nPndvb19hc2lkZXNfY2F0ZWdvcnk8L3N0cm9uZz4gLSBTZWxlY3QgYSBjYXRlZ29yeTo8L2xpPjxsaT48c3Ryb25nPndvb19hdXRob3I8L3N0cm9uZz4gLSBmYWxzZTwvbGk+PGxpPjxzdHJvbmc+d29vX2F1dG9faW1nPC9zdHJvbmc+IC0gZmFsc2U8L2xpPjxsaT48c3Ryb25nPndvb19jb250ZW50PC9zdHJvbmc+IC0gZmFsc2U8L2xpPjxsaT48c3Ryb25nPndvb19jb250ZW50X2ZlYXQ8L3N0cm9uZz4gLSBmYWxzZTwvbGk+PGxpPjxzdHJvbmc+d29vX2N1c3RvbV9mYXZpY29uPC9zdHJvbmc+IC0gPC9saT48bGk+PHN0cm9uZz53b29fZmVhdHVyZWRfcG9zdHM8L3N0cm9uZz4gLSAxPC9saT48bGk+PHN0cm9uZz53b29fZmVhdF9pbWFnZV9oZWlnaHQ8L3N0cm9uZz4gLSAxOTU8L2xpPjxsaT48c3Ryb25nPndvb19mZWF0X2ltYWdlX3dpZHRoPC9zdHJvbmc+IC0gNTQwPC9saT48bGk+PHN0cm9uZz53b29fZmVlZGJ1cm5lcl9pZDwvc3Ryb25nPiAtIGh0dHA6Ly9mZWVkYnVybmVyLmdvb2dsZS5jb20vZmIvYS9tYWlsdmVyaWZ5P3VyaT13cGJsb2dob3N0JmxvYz1lbl9VUzwvbGk+PGxpPjxzdHJvbmc+d29vX2ZlZWRidXJuZXJfdXJsPC9zdHJvbmc+IC0gaHR0cDovL2ZlZWRzLmZlZWRidXJuZXIuY29tL3dwYmxvZ2hvc3Q8L2xpPjxsaT48c3Ryb25nPndvb19nb29nbGVfYW5hbHl0aWNzPC9zdHJvbmc+IC0gPC9saT48bGk+PHN0cm9uZz53b29faG9tZV9vbmVfY29sPC9zdHJvbmc+IC0gZmFsc2U8L2xpPjxsaT48c3Ryb25nPndvb19pbWFnZV9zaW5nbGU8L3N0cm9uZz4gLSBmYWxzZTwvbGk+PGxpPjxzdHJvbmc+d29vX2xvZ288L3N0cm9uZz4gLSA8L2xpPjxsaT48c3Ryb25nPndvb19tYW51YWw8L3N0cm9uZz4gLSBodHRwOi8vd3d3Lndvb3RoZW1lcy5jb20vc3VwcG9ydC90aGVtZS1kb2N1bWVudGF0aW9uL2ZyZXNoLW5ld3MvPC9saT48bGk+PHN0cm9uZz53b29fcmVzaXplPC9zdHJvbmc+IC0gdHJ1ZTwvbGk+PGxpPjxzdHJvbmc+d29vX3Nob3J0bmFtZTwvc3Ryb25nPiAtIHdvbzwvbGk+PGxpPjxzdHJvbmc+d29vX3NpbmdsZV9pbWFnZV9oZWlnaHQ8L3N0cm9uZz4gLSAxMDA8L2xpPjxsaT48c3Ryb25nPndvb19zaW5nbGVfaW1hZ2Vfd2lkdGg8L3N0cm9uZz4gLSAxMDA8L2xpPjxsaT48c3Ryb25nPndvb190YWJzPC9zdHJvbmc+IC0gdHJ1ZTwvbGk+PGxpPjxzdHJvbmc+d29vX3RoZW1lbmFtZTwvc3Ryb25nPiAtIEZyZXNoIE5ld3M8L2xpPjxsaT48c3Ryb25nPndvb190aHVtYl9pbWFnZV9oZWlnaHQ8L3N0cm9uZz4gLSA3NTwvbGk+PGxpPjxzdHJvbmc+d29vX3RodW1iX2ltYWdlX3dpZHRoPC9zdHJvbmc+IC0gNzU8L2xpPjxsaT48c3Ryb25nPndvb192aWRlb19jYXRlZ29yeTwvc3Ryb25nPiAtIFNlbGVjdCBhIGNhdGVnb3J5OjwvbGk+PC91bD4=