Wordpress Security and Alternatives
-
No matter how secure we try to make our wordpress blogs they still got hacked. We recently got hacked(server level hacking, javascript insertion that took our server down, through the askimet plugin), anyway there was nothing really showing in the front end, no inserted links and nothing suspicious looking code.
Oh well we are changing the passwords now and going through and deleting the javascript.
The problem im facing is that i am handling over 100 blogs, so its very time consuming to do this. I know that once or twice a year everyone goes through a wordpress crisis but we really cant afford nor have the resources to fix it all the time.
Are there any alternatives to wordpress blogs(as good as wordpress). Wordpress has been showing good results so far so it works as far as SEO goes, but we are trying to figure out what to do in order to not get hacked. Besides alternatives id like to know if there are any work arrounds to not get hacked with little maintenance needed. Any tips?
-
What kind of hosting plan are you on (shared, dedicated, etc)? There are a lot of annoying hacks going around affecting WP based sites on shared servers.
-
Website security is a very deep topic. I will jump to the end and share if someone wants to break into your website they can do so and there is nothing you can do about it. There is a balance between accessibility (all your site's users need to access the site) and security (keeping the bad guys out).
The largest companies in the world such as Sony have experienced break-ins. The official websites of various countries experience security issues. If a hacker wakes up one day and decides to focus your site and is willing to focus on doing such as a full-time job, he will likely succeed.
With the above understood, there are many steps you can take to maximize your security:
-
ensure you always use the latest version of your CMS software
-
when a new software update is released ensure your site is promptly updated. Waiting 60+ days to update your software is too long.
-
the same applies to any extensions used on your site. Any extension is a possible security issue.
-
have your htaccess file professionally reviewed by a security expert. There are numerous modifications which can be made to the file which prevents various types of security holes.
-
have your server setup reviewed by a security expert. There are literally hundreds of possible security holes which can be left open due to various settings.
WordPress is the #1 blog software in the world. It is a big step down to #2 in terms of popularity. If you change software you will be making sacrifices.
There are tools like McAfee which scan your site daily for a very wide range of issues, and alerts you to vulnerabilities. Otherwise you can Google "Website security testing" and begin learning more about your site's vulnerabilities.
-
-
we have actualy changed the admin profile...all our blogs had very secure paswords and did not use the admin profile
thats why i am kind of bummed too
-
From our experience we noticed that Drupal does not work as well for SEO as wordpress does
so since we tested it Drupal wont be an option for us...Joomla either...but thank you for the tip ill try the website defender url for now...im looking for something that i wont have to manage every couple of months for technical purposes...so if there are any methods i hope we will both find out
-
My hosting administrator Chad has some good Ideas. chad@cisaz.net - He has been having me remove the administrator profile, and installed an Administrative plug in as well. I am forwarding your questions, and concerns and see if he can give me more information on Server side securities he added on his end.
Have you tried deactivating the administrator profile, and adding more securities for the new content management contributes?
-
I'm interested in this topic also. I wonder if Drupal is a better option in terms of security.
I have installed the Website Defender plugin in one of my Wordpress websites and it notifies me of security related issues. Since you are managing 100 sites, this might be a service that could streamline that process, I don't know. Anyway, perhaps worth a look:
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
How do I fix a broken link to a product category page in wordpress?
We are building a new site currently at http://67.222.109.48/~cheapnan/ I started doing some SEO after the developer I hired failed to do it even though it was in the agreement. I did our old site so I should be able to do this but I am new to wordpress. Now when i go to the products tab at the top of the page the first 2 have broken links, I checked the rest and there are 3 total that I need to fix. I am unsure how to access the navigation so I can fix the links. Please tell me where to look.
Content Development | | cheaptubes0 -
Wordpress Overly Dynamic URLs
Moz is giving me an overly dynamic URL warning for around 30 or so of these on our blog. http://blog.domain.com/?page=products&do=domain-com-looks-like-a-blog-title I have no idea what's causing this, we have the permalinks set up for category/post and are running yoast. Anyone have any idea what it is? And how can I stop them being crawled. They link to the blog homepage when clicked, which is set to canonical in the head so it shouldn't do any harm - but i'd like to remove them all the same. Will /Disallow /?=page work in robots.txt?
Content Development | | SolopressPrint0 -
Blogger to Wordpress guide on moving
Hi does anyone know a good guide for moving from blogger to wp, without losing rankings and moving over content and comments? I also want to change from a .blogspot addres to my own .com any help?
Content Development | | xoffie0 -
What are the best wordpress theme clubs
Hi, i am looking for the best theme clubs out there for wordpress, i am looking for clubs that offer support and also ones that have a forum that you can share ideas as well as get support. any suggestions would be great
Content Development | | ClaireH-1848861 -
How to sort out 4XX (Client Error) in wordpress
I have 1787 4XX (Client Error) in my wordpress blog and I have no idea how to get rid of them ? Can someone please help
Content Development | | afrika1110 -
Wordpress hacked. Entire content wiped out
Someone hacked my Wordpress site, wiped out all my content and changed my login status to a subscriber. Years of hard work gone, I can't log in to fix anything. Is there anything I can do. Is there a way to prevent this from happening ever again. Is there a way to catch these people?
Content Development | | ArenaS0 -
Where in my wordpress admin panel do I add the .
Having read Rand's post about the canonical tag I very much wish to use it to advise Google that the duplicates created during archiving (due to the fact that the posts have multiple categories) are just copies. I understand the theory, but can't transfer it into practice! Could someone give me an idiots guide as to how to add the tag and to where. My site produces approx 10 - 20 blog posts per week. Each has at least 2-4 categories applied to it. They are archived each month, at which point I have a big jump in duplicates in my campaign panel. Help! C:\Users\Catherine\Desktop\me_small.gif
Content Development | | catherine-2793881 -
Duplicate Content on WordPress Blogs?
We are getting ready to add a WordPress blog to our established website. Our plans are to place it in a subfolder on our website to maximize rank. My question is...Do we need to utilize a Meta Robots WordPress plugin by Yoast or similar so that noindex,follow robots meta tags will prevent search engine indexing of search result pages, subpages and category archives? We want to avoid the dreaded Duplicate Content Error and penalty. Any other great SEO WordPress plugins? Thank you for your time. Brian
Content Development | | gw3seo0