Sorry to break it to you, but your website is not safe. That’s not necessarily because of something you did but simply because nothing on the Internet is ever completely secure. Every single website faces security threats that can take them down, damage them, or worse. That’s the bad news. The silver lining is, there are many things you can do to tackle these threats and the first step is to be aware they exist. After all, you can only protect yourself from something that you know could pose a risk. To help you do exactly that, this article will […]
7 WordPress Security Myths: Completely Busted and Debunked
Despite being the most popular content management system in the world, myths about the security of the WordPress platform continue to circulate. Due to its open-source nature, inexperienced users might view it as less secure than a commercial product. Plus, they may be unnerved by reports of WordPress security problems in the news. Myth #1: Security is the Job of Your Hosting Provider As a beginner or first-time website owner, you might think that keeping your website secure is the domain of the people you pay to keep it online. And that is true in a way; your web hosting […]
Doc Pop’s News Drop: WordPress 5.2 is here
Doc Pop’s WordPress News Drop is a weekly report on the most pressing WordPress news. When the news drops, I will pick it up and deliver it right to you. WordPress 5.2 is here and full of new features. In this week’s News Drop we talk about Site Health, Fatal Error Recovery Mode, and support for cryptographically-signed updates. Love WordPress News but hate reading? My name is Doc and this is Doc Pop’s News Drop. Site Health section of the admin panel, support for a modern cryptography library, and support for cryptographically-signed updates. WordPress 5.2 launches today, May 7th and […]
How to Enforce Secure Passwords on Your WordPress Website
We’re willing to bet that you probably know all about using secure passwords for your WordPress admin account. However, you can’t take for granted that other users will do the same. To make sure your site remains safe, you’ll want to ensure all passwords are secure. While WordPress includes a function to create a secure password, it’s completely optional. As with many WordPress tasks, the answer lies in using a plugin to enforce users to use strong passwords on WordPress’ back end. In this article, we’ll discuss the importance of password security. We’ll then show you what features WordPress offers […]
The Best WordPress Security Plugins Compared
Nowadays, if your WordPress security approach is passive you are inadvertently playing with fire. All your hard work could turn to dust in the blink of an eye with just one security attack. As a website development tool, WordPress plugins are popular for a great number of reasons. They extend a website’s functionality and flexibility. However, they can also be a route for malicious attackers to reach your site. If a plugin isn’t updated properly, it can leave a door right open, making you vulnerable. Adding certain security improvements are definitely not a waste of time. You will be assured […]
Doc Pop’s News Drop: Flipping the Script on Hackers with the Coin Auth Plugin
Doc’s WordPress News Drop is a weekly report on the most pressing WordPress news. When the news drops, I will pick it up and deliver it right to you. Wouldn’t it be nice to be able to flip the script on hackers and run cryptomining software on their computers? In this week’s video we talk about an app called Coin Auth which does just that. We also talk about WordPress version 4.9.5 and we hear some great news about WordCamp Europe. Love WordPress news, but hate reading? My name is Doc and this is Doc Pop’s News Drop. This week […]
Torque Toons: Supply Chain Attack
After reading Wordfence’s great articles about the rise of “supply chain attacks” in WordPress plugins, I’ve decided to try using the term as often as possible in everyday conversation.
Doc Pop’s News Drop: National Cyber Security Awareness Month
Doc’s WordPress News Drop is a weekly report on the most pressing WordPress news. When the news drops, I will pick it up and deliver it right to you. Since it’s National Cyber Security Awareness Month (NCSAM), we figured it would be a great time to talk about 4 easy ways to keep your WordPress site secure. If you are interested in learning more about protecting your personal cybersecurity, I’d recommend https://staysafeonline.org/ncsam/. Love WordPress News but hate reading? My name is Doc and you’re watching Doc Pop’s News Drop. October is National Cyber Security Awareness Month. Which is mostly focused […]
Doc Pop’s News Drop: How Hackers Can Find New Sites Within 30 Minutes
Doc’s WordPress News Drop is a weekly report on the most pressing WordPress news. When the news drops, I will pick it up and deliver it right to you. At this year’s DefCon, Hanno Böck described how hackers can find a fresh new WordPress install within 30-60 minutes of going live. Don’t be nervous though, in this week’s video we talk about how you can protect a fresh WordPress install. WordFence shared an excellent write up of Hanno’s presentation, which you can read here, as well as another article on how hackers can take advantage of WordPress sites that have […]
An Introduction to Baseline Security for WordPress Theme Developers
If you publish WordPress themes, it’s important to develop them with the security of your users in mind. However, the WordPress Theme Review Team recently showed that many theme authors eschew this at an alarming frequency. We understand: getting a theme and its elements to simply work is much easier than worrying about any security aspects. Even so, themes can be a huge security risk, so this is something you must concern yourself with. In fact, there are a number of security mistakes that crop up time and time again, and the good news is that fixing them in your own code […]
No Comments