Four Security Tips To Keep Your WordPress Blog From Being Hacked
Online forums have been swamped with stories of blogs being broken into and then blocked by Google for spreading badware. You should always adhere to these WordPress security tips to avoid your blog being hacked and having to face that kind of situation.
Update to get the current version that’s secure
The latest WordPress version, 2.3.3, is the most secure and effective version you can get right now. All software contains bugs and security vulnerabilities. Having the latest version of a product reduces potential issues.
Since WordPress gives plugins and themes full access to your blog, you also need to keep your plugins up-to-date. With the latest 2.3 series of WordPress you are notified in the admin screen when the plugins that you have installed are released in new versions.
Disable and remove themes and plugins that you are not using
The majority of users that create web logs will look at alternative design styles before deciding on one. Similarly, they will try several additional pieces of software that they decide against using, but do not remove.
Each installed theme and plugin is a potential security hole. Keeping unused themes and plugins up-to-date is a waste of time. Instead, deactivate all plugins that you don’t need or use. Remove the files for unused themes and plugins from the server.
Removing the files from the server is the last step. It is extremely important. Add-ons, plug-ins and themes are generally stored in standardized, well known directories. This is both good and bad. It is good because they are easy to find and remove; it is bad because they are easy to find and exploit by attackers. Be safe and remove the unused ones.
Never download and install codes that aren’t from a trusted source
Just like you shouldn’t click on email attachments coming from people you don’t trust, you shouldn’t install software on your blog from untrusted sources. Only download code from the authors’ web site.
Wordpress, themes, and plugins are released as Open Source. Open Source allows anyone to modify the code, even if they have malicious intent. Any person with malicious intent can put up badware for downloading to unsuspecting web surfers.
There is a penalty for being an early adopter! Allow other people to work through the holes and security issues before you attempt to use the package.
Watch out for JavaScript includes
A lot of web analytics services and advertising networks have a requirement that you add JavaScript to your blog, which frequently comes in the form of a JavaScript include. This gives the JavaScript authors an almost wholesale permission to change your web page. Essentially, you must trust your Web site’s security to the third-party service.
With regard to Google AdSense, Google Analytics, or other respected advertising networks and web analytics services, you shouldn’t be concerned. However, if a relatively new firm asks to put JavaScript on your web site, you should quickly run the other way.
An added drawback to advertising nets is the lack of controls as to which outfits can put ads on your net. With Google, there is an implied guiltiness here. In the event that you have unsavory ads on your website, you run the risk of being on the same blacklist.
Nick Dalton is a WordPress security expert who regularly writes articles for Internet business entrepreneurs and bloggers at TipsTricksToolsTechniques.com.
- Nick Dalton
Popularity: 37% [?]
Tags: Adsense, Advertising, article, articles, blog, blogs, Business, forum, forums, google adsense, Internet, Marketing, web site, website, wordpress
Related posts
Tags: Adsense, Advertising, article, articles, blog, blogs, Business, forum, forums, google adsense, Internet, web site, website, wordpress
