SlideShare a Scribd company logo
STAY Protected
DID YOU KNOW??
GOOGLE BLACKLISTS
AROUND 20,000 WEBSITES FOR MALWARE
AND AROUND 50,000 FOR PHISHING
each week
So what can you do to be sure
you're not on that  blacklist?
Keep Your Site Updated
Plugins
Themes
Wordpress Version
(And only have current plugins and themes installed)
and optimize them for
your website!
INSTALL SECURITY
PLUGINS
Loginizer - Wordfence - Sucuri
Limit Login Attempts & Increase Lockout Time (for most businesses
who don't have need for customers to login to their site)
Use 2 Factor Authentication for Admin Logins
Setup Firewall
Block IP's
Change Default Settings
Block attempts of those using admin or your website as login name
Use Common Sense
STRONG PASSWORDS
This applies to not only your WP Login but
also FTP, Hosting, and emails. Be sure you
aren't using the same for all these areas!
UNCOMMON USERNAMES
Don't use Admin, or Your Website Name as Your
Username - make it unique and if possible, don't
connect it to your business email.
Hide Your Admin Login Page
Can you guess the login
page for friends website?
Most likely too many of you are using the standard
/wp-admin
login page - change it today!
Great Plugin for this is - WPS Hide Login
Hide your dashboard
from logged in users
Plugin by Yoast:
Hide Admin Bar From Non-admins
Add the following line at the end
of the .htaccess file (In Your
CPanel):
Options -Indexes
DISABLE
DIRECTORY
BROWSING
Run a malware
scan on your own
computer.
You might be the problem!
From your CPanel - Add this code to the
wp-config.php file:
define(‘DISALLOW_FILE_EDIT’, true);
Turn off File Editing
from the Dashboard
Change your display name from your username
WHEN YOU FIRST START YOUR SITE,
MAKE A BACKUP.
WHENEVER YOU MAKE MAJOR CHANGES,
BACKUP!
IF YOUR SITE ISN'T NEW BUT DOESN'T HAVE MALWARE -
BACKUP!
BACKUP MONTHLY.
BACKUP - BACKUP - BACKUP!!
HAVING CLEAN BACKUP FILES MEANS
YOU CAN RESTORE INSTEAD OF STARTING OVER IF YOU DO
GET MALWARE.
Be Sure You Are Backing Up!
BONUS
Pingbacks and trackbacks notify you that your content got linked
from another web page, sounds great right?
The Bad: Via trackbacks, hackers could cause massive distributed
denial-of-service attack (DDoS) attacks or could use other “clean”
WordPress sites to do their dirty work.
Turn off Trackbacks and Pings from other sites.
How Do I Know If My Website
Has Been Attacked?
If you have been hacked - you can clean it yourself or hire
others to do it for you. We recommend working with a
professional if you have never dealt with it before.
REFERENCE TO CLEAN SITE:
https://sucuri.net/guides/how-to-clean-hacked-wordpress/
If you are using a reputable hosting
company they will notify you when you
have malware or your security scanner will.
Questions?
Want To
Learn More? Call Us
480.241.7328
Email
megan@geekedoutmedia.com
On Social
@GEEKEDOUTMEDIA
geekedoutmedia.com
Our Website

More Related Content

What's hot

Domain mapping
Domain mappingDomain mapping
Domain mapping
Andrea Rennick
 
WordPress for beginners lesson 4 fall2015 JALC
WordPress for beginners lesson 4 fall2015 JALCWordPress for beginners lesson 4 fall2015 JALC
WordPress for beginners lesson 4 fall2015 JALC
Michele Butcher-Jones
 
Is your Wordpress safe enough?
Is your Wordpress safe enough? Is your Wordpress safe enough?
Is your Wordpress safe enough?
saidmurat
 
Your Site Has Been Hacked, Now What?
Your Site Has Been Hacked, Now What?Your Site Has Been Hacked, Now What?
Your Site Has Been Hacked, Now What?
Michele Butcher-Jones
 
How to in WPMU: Building a blog directory & Domain Mapping
How to in WPMU: Building a blog directory & Domain MappingHow to in WPMU: Building a blog directory & Domain Mapping
How to in WPMU: Building a blog directory & Domain Mapping
Andrea Rennick
 
Responsible [digital] Home Ownership
Responsible [digital] Home OwnershipResponsible [digital] Home Ownership
Responsible [digital] Home Ownership
Denise (Dee) Teal
 
Get Rid of Supra savings Pop-up Ads
Get Rid of Supra savings Pop-up AdsGet Rid of Supra savings Pop-up Ads
Get Rid of Supra savings Pop-up Ads
JeniferHuston
 
WordPress Troubleshooting Hacks.pdf
WordPress Troubleshooting Hacks.pdfWordPress Troubleshooting Hacks.pdf
WordPress Troubleshooting Hacks.pdf
Arthur Kasirye
 
Checkear si esta_inslatado_un_modulo_en_apache
Checkear si esta_inslatado_un_modulo_en_apacheCheckear si esta_inslatado_un_modulo_en_apache
Checkear si esta_inslatado_un_modulo_en_apache
James Jara
 
Don't let your WordPress site get hacked
Don't let your WordPress site get hackedDon't let your WordPress site get hacked
Don't let your WordPress site get hacked
Victoria Darling
 
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Vlad Lasky
 
Bảo Mật Website WordPress
Bảo Mật Website WordPressBảo Mật Website WordPress
Bảo Mật Website WordPress
Lê Quốc Toàn
 
WordPress Security Presentation
WordPress Security PresentationWordPress Security Presentation
WordPress Security Presentation
Andrew Paton
 
WordPress Security Essentials WordCamp Denver 2012
WordPress Security Essentials WordCamp Denver 2012WordPress Security Essentials WordCamp Denver 2012
WordPress Security Essentials WordCamp Denver 2012
Angela Bowman
 
Beginning WordPress Security WordCamp North Canton 2015
Beginning WordPress Security WordCamp North Canton 2015Beginning WordPress Security WordCamp North Canton 2015
Beginning WordPress Security WordCamp North Canton 2015
Michele Butcher-Jones
 
SettingUpRemoteAccess
SettingUpRemoteAccessSettingUpRemoteAccess
SettingUpRemoteAccess
webuploader
 
Silent install Adobe Reader DC
Silent install Adobe Reader DCSilent install Adobe Reader DC
Silent install Adobe Reader DC
Get It Solutions
 
Google chrome silent install
Google chrome silent installGoogle chrome silent install
Google chrome silent install
Get It Solutions
 
3 Ways to Setup a WordPress Testing Environment
3 Ways to Setup a WordPress Testing Environment 3 Ways to Setup a WordPress Testing Environment
3 Ways to Setup a WordPress Testing Environment
Arelthia Phillips
 
8 Simple Ways to Hack Your Joomla
8 Simple Ways to Hack Your Joomla8 Simple Ways to Hack Your Joomla
8 Simple Ways to Hack Your Joomla
SiteGround.com
 

What's hot (20)

Domain mapping
Domain mappingDomain mapping
Domain mapping
 
WordPress for beginners lesson 4 fall2015 JALC
WordPress for beginners lesson 4 fall2015 JALCWordPress for beginners lesson 4 fall2015 JALC
WordPress for beginners lesson 4 fall2015 JALC
 
Is your Wordpress safe enough?
Is your Wordpress safe enough? Is your Wordpress safe enough?
Is your Wordpress safe enough?
 
Your Site Has Been Hacked, Now What?
Your Site Has Been Hacked, Now What?Your Site Has Been Hacked, Now What?
Your Site Has Been Hacked, Now What?
 
How to in WPMU: Building a blog directory & Domain Mapping
How to in WPMU: Building a blog directory & Domain MappingHow to in WPMU: Building a blog directory & Domain Mapping
How to in WPMU: Building a blog directory & Domain Mapping
 
Responsible [digital] Home Ownership
Responsible [digital] Home OwnershipResponsible [digital] Home Ownership
Responsible [digital] Home Ownership
 
Get Rid of Supra savings Pop-up Ads
Get Rid of Supra savings Pop-up AdsGet Rid of Supra savings Pop-up Ads
Get Rid of Supra savings Pop-up Ads
 
WordPress Troubleshooting Hacks.pdf
WordPress Troubleshooting Hacks.pdfWordPress Troubleshooting Hacks.pdf
WordPress Troubleshooting Hacks.pdf
 
Checkear si esta_inslatado_un_modulo_en_apache
Checkear si esta_inslatado_un_modulo_en_apacheCheckear si esta_inslatado_un_modulo_en_apache
Checkear si esta_inslatado_un_modulo_en_apache
 
Don't let your WordPress site get hacked
Don't let your WordPress site get hackedDon't let your WordPress site get hacked
Don't let your WordPress site get hacked
 
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
 
Bảo Mật Website WordPress
Bảo Mật Website WordPressBảo Mật Website WordPress
Bảo Mật Website WordPress
 
WordPress Security Presentation
WordPress Security PresentationWordPress Security Presentation
WordPress Security Presentation
 
WordPress Security Essentials WordCamp Denver 2012
WordPress Security Essentials WordCamp Denver 2012WordPress Security Essentials WordCamp Denver 2012
WordPress Security Essentials WordCamp Denver 2012
 
Beginning WordPress Security WordCamp North Canton 2015
Beginning WordPress Security WordCamp North Canton 2015Beginning WordPress Security WordCamp North Canton 2015
Beginning WordPress Security WordCamp North Canton 2015
 
SettingUpRemoteAccess
SettingUpRemoteAccessSettingUpRemoteAccess
SettingUpRemoteAccess
 
Silent install Adobe Reader DC
Silent install Adobe Reader DCSilent install Adobe Reader DC
Silent install Adobe Reader DC
 
Google chrome silent install
Google chrome silent installGoogle chrome silent install
Google chrome silent install
 
3 Ways to Setup a WordPress Testing Environment
3 Ways to Setup a WordPress Testing Environment 3 Ways to Setup a WordPress Testing Environment
3 Ways to Setup a WordPress Testing Environment
 
8 Simple Ways to Hack Your Joomla
8 Simple Ways to Hack Your Joomla8 Simple Ways to Hack Your Joomla
8 Simple Ways to Hack Your Joomla
 

Similar to How to Increase Security on your Wordpress Website

Hardening WordPress - Friends of Search 2014 (WordPress Security)
Hardening WordPress - Friends of Search 2014 (WordPress Security)Hardening WordPress - Friends of Search 2014 (WordPress Security)
Hardening WordPress - Friends of Search 2014 (WordPress Security)
Bastian Grimm
 
Wordpress 101 Guide Ebook Free
Wordpress 101 Guide Ebook FreeWordpress 101 Guide Ebook Free
Wordpress 101 Guide Ebook Free
huutienmmo
 
Tips to improve word press security ppt
Tips to improve word press security pptTips to improve word press security ppt
Tips to improve word press security ppt
Cheap SSL Coupon Code
 
Protect Your WordPress From The Inside Out
Protect Your WordPress From The Inside OutProtect Your WordPress From The Inside Out
Protect Your WordPress From The Inside Out
SiteGround.com
 
Wordpress Security & Hardening Steps
Wordpress Security & Hardening StepsWordpress Security & Hardening Steps
Wordpress Security & Hardening Steps
Plasterdog Web Design
 
Word press security 101
Word press security 101  Word press security 101
Word press security 101
Kojac801
 
WordPress End-User Security
WordPress End-User SecurityWordPress End-User Security
WordPress End-User Security
Dre Armeda
 
WordPress security
WordPress securityWordPress security
WordPress security
Shelley Magnezi
 
Your WordPress Site is and is not Hacked - You don't know until you check
Your WordPress Site is and is not Hacked - You don't know until you checkYour WordPress Site is and is not Hacked - You don't know until you check
Your WordPress Site is and is not Hacked - You don't know until you check
Angela Bowman
 
Hardening WordPress - SAScon Manchester 2013 (WordPress Security)
Hardening WordPress - SAScon Manchester 2013 (WordPress Security)Hardening WordPress - SAScon Manchester 2013 (WordPress Security)
Hardening WordPress - SAScon Manchester 2013 (WordPress Security)
Bastian Grimm
 
Security Presentation for Boulder WordPress Meetup
Security Presentation for Boulder WordPress MeetupSecurity Presentation for Boulder WordPress Meetup
Security Presentation for Boulder WordPress Meetup
Angela Bowman
 
Website security
Website securityWebsite security
Website security
Akhilesh Kant
 
Introduction to WordPress Slides from WordCamp 2012 by Gary A. Bacon
Introduction to WordPress Slides from WordCamp 2012 by Gary A. BaconIntroduction to WordPress Slides from WordCamp 2012 by Gary A. Bacon
Introduction to WordPress Slides from WordCamp 2012 by Gary A. Bacon
Gary Bacon
 
Killer word press-checklist
Killer word press-checklistKiller word press-checklist
Killer word press-checklist
Connecticut SEO Experts
 
WordPress Security
WordPress SecurityWordPress Security
WordPress Security
Brad Williams
 
WordPress Security Guide
WordPress Security GuideWordPress Security Guide
WordPress Security Guide
Trainings Webversity
 
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITERUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
Acodez IT Solutions
 
WordPress Insider Meetup Group - Jan, 7, 2016 meeting
WordPress Insider Meetup Group - Jan, 7,  2016 meetingWordPress Insider Meetup Group - Jan, 7,  2016 meeting
WordPress Insider Meetup Group - Jan, 7, 2016 meeting
Michelle Castillo
 
WordPress Security
WordPress Security WordPress Security
WordPress Security
Christina Hawkins
 
Securing Your WordPress Website - WordCamp GC 2011
Securing Your WordPress Website - WordCamp GC 2011Securing Your WordPress Website - WordCamp GC 2011
Securing Your WordPress Website - WordCamp GC 2011
Vlad Lasky
 

Similar to How to Increase Security on your Wordpress Website (20)

Hardening WordPress - Friends of Search 2014 (WordPress Security)
Hardening WordPress - Friends of Search 2014 (WordPress Security)Hardening WordPress - Friends of Search 2014 (WordPress Security)
Hardening WordPress - Friends of Search 2014 (WordPress Security)
 
Wordpress 101 Guide Ebook Free
Wordpress 101 Guide Ebook FreeWordpress 101 Guide Ebook Free
Wordpress 101 Guide Ebook Free
 
Tips to improve word press security ppt
Tips to improve word press security pptTips to improve word press security ppt
Tips to improve word press security ppt
 
Protect Your WordPress From The Inside Out
Protect Your WordPress From The Inside OutProtect Your WordPress From The Inside Out
Protect Your WordPress From The Inside Out
 
Wordpress Security & Hardening Steps
Wordpress Security & Hardening StepsWordpress Security & Hardening Steps
Wordpress Security & Hardening Steps
 
Word press security 101
Word press security 101  Word press security 101
Word press security 101
 
WordPress End-User Security
WordPress End-User SecurityWordPress End-User Security
WordPress End-User Security
 
WordPress security
WordPress securityWordPress security
WordPress security
 
Your WordPress Site is and is not Hacked - You don't know until you check
Your WordPress Site is and is not Hacked - You don't know until you checkYour WordPress Site is and is not Hacked - You don't know until you check
Your WordPress Site is and is not Hacked - You don't know until you check
 
Hardening WordPress - SAScon Manchester 2013 (WordPress Security)
Hardening WordPress - SAScon Manchester 2013 (WordPress Security)Hardening WordPress - SAScon Manchester 2013 (WordPress Security)
Hardening WordPress - SAScon Manchester 2013 (WordPress Security)
 
Security Presentation for Boulder WordPress Meetup
Security Presentation for Boulder WordPress MeetupSecurity Presentation for Boulder WordPress Meetup
Security Presentation for Boulder WordPress Meetup
 
Website security
Website securityWebsite security
Website security
 
Introduction to WordPress Slides from WordCamp 2012 by Gary A. Bacon
Introduction to WordPress Slides from WordCamp 2012 by Gary A. BaconIntroduction to WordPress Slides from WordCamp 2012 by Gary A. Bacon
Introduction to WordPress Slides from WordCamp 2012 by Gary A. Bacon
 
Killer word press-checklist
Killer word press-checklistKiller word press-checklist
Killer word press-checklist
 
WordPress Security
WordPress SecurityWordPress Security
WordPress Security
 
WordPress Security Guide
WordPress Security GuideWordPress Security Guide
WordPress Security Guide
 
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITERUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
 
WordPress Insider Meetup Group - Jan, 7, 2016 meeting
WordPress Insider Meetup Group - Jan, 7,  2016 meetingWordPress Insider Meetup Group - Jan, 7,  2016 meeting
WordPress Insider Meetup Group - Jan, 7, 2016 meeting
 
WordPress Security
WordPress Security WordPress Security
WordPress Security
 
Securing Your WordPress Website - WordCamp GC 2011
Securing Your WordPress Website - WordCamp GC 2011Securing Your WordPress Website - WordCamp GC 2011
Securing Your WordPress Website - WordCamp GC 2011
 

How to Increase Security on your Wordpress Website

  • 2. DID YOU KNOW?? GOOGLE BLACKLISTS AROUND 20,000 WEBSITES FOR MALWARE AND AROUND 50,000 FOR PHISHING each week
  • 3. So what can you do to be sure you're not on that  blacklist?
  • 4. Keep Your Site Updated Plugins Themes Wordpress Version (And only have current plugins and themes installed)
  • 5. and optimize them for your website! INSTALL SECURITY PLUGINS
  • 6. Loginizer - Wordfence - Sucuri Limit Login Attempts & Increase Lockout Time (for most businesses who don't have need for customers to login to their site) Use 2 Factor Authentication for Admin Logins Setup Firewall Block IP's Change Default Settings Block attempts of those using admin or your website as login name
  • 7. Use Common Sense STRONG PASSWORDS This applies to not only your WP Login but also FTP, Hosting, and emails. Be sure you aren't using the same for all these areas! UNCOMMON USERNAMES Don't use Admin, or Your Website Name as Your Username - make it unique and if possible, don't connect it to your business email.
  • 8. Hide Your Admin Login Page Can you guess the login page for friends website? Most likely too many of you are using the standard /wp-admin login page - change it today! Great Plugin for this is - WPS Hide Login
  • 9. Hide your dashboard from logged in users Plugin by Yoast: Hide Admin Bar From Non-admins
  • 10. Add the following line at the end of the .htaccess file (In Your CPanel): Options -Indexes DISABLE DIRECTORY BROWSING
  • 11. Run a malware scan on your own computer. You might be the problem!
  • 12. From your CPanel - Add this code to the wp-config.php file: define(‘DISALLOW_FILE_EDIT’, true); Turn off File Editing from the Dashboard
  • 13. Change your display name from your username
  • 14. WHEN YOU FIRST START YOUR SITE, MAKE A BACKUP. WHENEVER YOU MAKE MAJOR CHANGES, BACKUP! IF YOUR SITE ISN'T NEW BUT DOESN'T HAVE MALWARE - BACKUP! BACKUP MONTHLY. BACKUP - BACKUP - BACKUP!! HAVING CLEAN BACKUP FILES MEANS YOU CAN RESTORE INSTEAD OF STARTING OVER IF YOU DO GET MALWARE. Be Sure You Are Backing Up!
  • 15. BONUS Pingbacks and trackbacks notify you that your content got linked from another web page, sounds great right? The Bad: Via trackbacks, hackers could cause massive distributed denial-of-service attack (DDoS) attacks or could use other “clean” WordPress sites to do their dirty work. Turn off Trackbacks and Pings from other sites.
  • 16. How Do I Know If My Website Has Been Attacked? If you have been hacked - you can clean it yourself or hire others to do it for you. We recommend working with a professional if you have never dealt with it before. REFERENCE TO CLEAN SITE: https://sucuri.net/guides/how-to-clean-hacked-wordpress/ If you are using a reputable hosting company they will notify you when you have malware or your security scanner will.
  • 17. Questions? Want To Learn More? Call Us 480.241.7328 Email megan@geekedoutmedia.com On Social @GEEKEDOUTMEDIA geekedoutmedia.com Our Website