{"id":4342,"date":"2019-04-17T12:08:20","date_gmt":"2019-04-17T12:08:20","guid":{"rendered":"https:\/\/www.icdsoft.com\/blog\/?p=4342"},"modified":"2024-02-20T20:24:46","modified_gmt":"2024-02-20T20:24:46","slug":"how-to-improve-the-security-of-your-wordpress-website","status":"publish","type":"post","link":"https:\/\/www.icdsoft.com\/blog\/how-to-improve-the-security-of-your-wordpress-website\/","title":{"rendered":"How to Improve The Security Of Your WordPress Website"},"content":{"rendered":"\n<p>If your website is built with WordPress, you have a huge target on your back, and that's why we will show you how to improve the security of your WordPress website.<\/p>\n\n\n\n<p>Picture this - you've invested loads of time, money, and effort into building and developing your website, traffic has started to rise, and all of a sudden, you get slapped with a \"<strong><em>Deceptive site ahead<\/em><\/strong>\" message in your browser. Actually, in most cases we've seen, regular website visitors are the first to report such issues, and that's definitely bad for any business. You are not only losing money due to the downtime that you'd experience while fixing the damage, but your company's reputation takes a hit as well. And even if you are not running a super-important website, it's still not cool to have your account breached. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter is-resized\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/deceptive-site-ahead.png\"><img decoding=\"async\" width=\"1000\" height=\"507\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/deceptive-site-ahead.png\" alt=\"wordpress security\" class=\"wp-image-4675 lazyload\" style=\"--smush-placeholder-width: 1000px; --smush-placeholder-aspect-ratio: 1000\/507;width:600px;height:304px\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/deceptive-site-ahead.png 1000w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/deceptive-site-ahead-300x152.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/deceptive-site-ahead-768x389.png 768w\" data-sizes=\"(max-width: 1000px) 100vw, 1000px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><\/a><figcaption class=\"wp-element-caption\">The&nbsp;<a href=\"https:\/\/support.google.com\/chrome\/answer\/99020?co=GENIE.Platform%3DDesktop&amp;hl=en\" target=\"_blank\" rel=\"noopener\">warning shown by Google Chrome<\/a>&nbsp;when accessing a website infected with malware. If you are the webmaster of such a website, you can request a review&nbsp;<a href=\"https:\/\/developers.google.com\/webmasters\/hacked\/docs\/request_review\" target=\"_blank\" rel=\"noopener\">here<\/a>.<br><\/figcaption><\/figure>\n<\/div>\n\n\n<p>And you might be surprised how often WordPress-based websites get hacked. <strong>In most cases we see, the hacked application in question is WordPress, usually an outdated version.<\/strong> In fairness, we seem to stick to the latest industry trends showing that WordPress accounts for nearly 90% of all hacked CMS websites. Here are the exact numbers from <a href=\"https:\/\/blog.sucuri.net\/2019\/03\/hacked-website-trend-report-2018.html\" target=\"_blank\" rel=\"noopener\">Sucuri's official report for 2018:<\/a><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/Sucuri-2018-hacked-report-infected-website-platform.png\"><img decoding=\"async\" width=\"655\" height=\"411\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/Sucuri-2018-hacked-report-infected-website-platform.png\" alt=\"wordpress security\" class=\"wp-image-4546 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/Sucuri-2018-hacked-report-infected-website-platform.png 655w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/Sucuri-2018-hacked-report-infected-website-platform-300x188.png 300w\" data-sizes=\"(max-width: 655px) 100vw, 655px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 655px; --smush-placeholder-aspect-ratio: 655\/411;\" \/><\/a><figcaption class=\"wp-element-caption\">Comparisson chart from <a href=\"https:\/\/blog.sucuri.net\/2019\/03\/hacked-website-trend-report-2018.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Sucuri<\/a> showing the infected websites distribution per CMS<\/figcaption><\/figure>\n<\/div>\n\n\n<p>You can find more information about Sucuri in the <a href=\"https:\/\/hostingpill.com\/sucuri-review\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Sucuri Review (opens in a new tab)\">Sucuri Review<\/a> by HostingPill.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Does WordPress Have Security Issues?<\/h2>\n\n\n\n<p>Don't get me wrong. These percentages don't mean that WordPress is more vulnerable compared to other CMSes. Every sufficiently large piece of software is bound to have security issues. This is just the nature of software development. These numbers are a direct reflection of just how popular each product is. WordPress has been the most dominant CMS by far over the last eight years, and that's why it accounts for nearly 90% of all hacks. And while for example OpenCart accounted for just 0.4% of hacked CMSes, that certainly does not mean it's the safest one. <\/p>\n\n\n\n<p>The popularity of WordPress is the biggest factor here. Hackers like to go after widely used software applications for one very simple reason - it allows them to go after a large number of systems at the same time and thus increase the impact of their attacks. More targets means higher chances of success. Quite often, our Incident Response Team has to work on mass-hack cases where a vulnerability in a popular plugin or theme leads to hundreds of hacked customer websites.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Whenever we deal with mass-hacks, we first run a scan to identify all hacked and vulnerable (but not hacked yet) installations. After that, we password-protect the hacked ones to prevent further damage and we notify the owners of the bad news. Whenever possible, we try to protect the clean but vulnerable ones from serious and easily exploitable vulnerabilities in advance in order to reduce the likelihood of the sites getting hacked. <\/p>\n<cite>ICDSoft's Incident Response Team<\/cite><\/blockquote>\n\n\n\n<p><strong>The fact that there are thousands of plugins and themes for WordPress also works in favor of the hackers as it gives them as many attack vectors.<\/strong> In fact, these extensible parts of WordPress are its most vulnerable side. Many web developers are not well-versed in security, so they are very likely to make unintentional mistakes while writing code that end up being security vulnerabilities. Afterwards, they plug these security holes by releasing updates, and that's why it's crucial that you don't fall behind on updates. <\/p>\n\n\n\n<p>So now that you are aware of the risks, let's find out how you can improve the security of your WordPress installation. <strong>Note that we will focus on using tools that are freely available in the ICDSoft Control Panel, so you won't have to spend any money or install additional plugins.<\/strong> These are all effective methods that are easy to implement. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1. Keep Your WordPress Installation Up-to-Date<\/h2>\n\n\n\n<p>You might have heard this a thousand times, but people still underestimate the importance of updating their software. According to <a href=\"https:\/\/blog.sucuri.net\/2019\/03\/hacked-website-trend-report-2018.html\" target=\"_blank\" rel=\"noopener\">Sucuri's report<\/a> mentioned above, \"a total of&nbsp;<strong>36.7% of WordPress clean up requests had an outdated version<\/strong>.\" <\/p>\n\n\n\n<p>The primary attack vectors continue to be the extensions of the CMS, such as the themes and plugins. Therefore, it's crucial that you not only update the version of your WordPress installation, but also all the different extensions that have been added, without any exception. <\/p>\n\n\n\n<p>Some users are wary of updating as that could \"break\" their website. While the possibility certainly exists, with ICDSoft you don't need to keep your fingers crossed when pressing the \"Update\" button. If something goes wrong, you can always \"undo\" the update and restore your website back to a working state from one of our <em><a href=\"https:\/\/www.icdsoft.com\/en\/hosting\/backup#\/sharedplans\">system backups<\/a><\/em>. You can also opt to create a personal backup before you proceed with such tasks.<\/p>\n\n\n\n<div style=\"background-color:#0693e3;text-align:center\" class=\"wp-block-atomic-blocks-ab-cta ab-block-cta\"><div class=\"ab-cta-content\"><h2 class=\"ab-cta-title ab-font-size-32\" style=\"color:#eeeeee\">Don\u2019t Worry - We got your back(up)<br><br><\/h2><div class=\"ab-cta-text ab-font-size-32\" style=\"color:#eeeeee\"><p>Our system makes automated daily backups of your entire account on a different machine, including files, databases, and email messages. For accounts on shared servers, the System Backups go seven days back, while System Backups on the VPS (First Class and Ultimate) and WebApps plans are kept for 15 days.<\/p><\/div><\/div><div class=\"ab-cta-button\"><a href=\"https:\/\/www.icdsoft.com\/en\/hosting\/backup#\/sharedplans\" target=\"_self\" rel=\"noopener noreferrer\" class=\"ab-button ab-button-shape-rounded ab-button-size-medium\" style=\"color:#ffffff;background-color:#3373dc\">Restore Now<\/a><\/div><\/div>\n\n\n\n<p>To sum up, it's important to update, and if you are hosted here, it's perfectly safe. And in the case of WordPress, it's really simple to apply updates. The easiest way to do it is via the Dashboard, but with the SSH access available on all ICDSoft hosting accounts, you can also apply updates through shell commands using WP-CLI. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.1 Updating via the WordPress Dashboard<\/h3>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wordpress-security.png\"><img decoding=\"async\" width=\"1024\" height=\"457\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wordpress-security-1024x457.png\" alt=\"WordPress dashboard interface displaying menu options, updates, and customization links for site management.\" class=\"wp-image-4573 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wordpress-security-1024x457.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wordpress-security-300x134.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wordpress-security-768x343.png 768w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/457;\" \/><\/a><figcaption class=\"wp-element-caption\">The Weclome screen of the WordPress Dashboard informing you that an update is available<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>If there are pending updates for your core WordPress version or for one (or several) extensions, you will get a notification as soon as you log into your Dashboard. Typically, you should be able to access the Dashboard by appending <strong>\/wp-admin<\/strong> to the URL where you have installed it, e.g. <strong>http:\/\/example.com\/wp-admin<\/strong>.<\/p>\n<\/div>\n<\/div>\n\n\n\n<p>You can check the video below for a summary of the process - there is an update available for our WordPress installation and one of the plugins (Elementor). <\/p>\n\n\n\n<figure class=\"wp-block-video\"><video height=\"1440\" style=\"aspect-ratio: 2560 \/ 1440;\" width=\"2560\" controls src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wordpress-update.webm\"><\/video><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">1.2 Updating with WP CLI<\/h3>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-cli-update.png\"><img decoding=\"async\" width=\"1024\" height=\"493\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-cli-update-1024x493.png\" alt=\"wordpress security updates wp-cli\" class=\"wp-image-4580 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-cli-update-1024x493.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-cli-update-300x144.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-cli-update-768x370.png 768w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/493;\" \/><\/a><figcaption class=\"wp-element-caption\">Highlighted in red are commands for updating the WordPress core and extensions via WP-CLI<\/figcaption><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>WP-CLI is the command line interface for WordPress, allowing you to manage all aspects of the application from the command prompt, without having to use a web browser. WP-CLI is available on all servers, but it requires SSH access.<\/p>\n<\/div>\n<\/div>\n\n\n\n<p>You can enable it through the SSH Access section of the hosting Control Panel. Once logged into your account over SSH, you will need to navigate to the location of your WordPress site. Now, you are ready to run the WP-CLI commands below to perform WordPress update-related tasks:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>wp core check-update <\/strong>- checks for available updates for the WordPress core<\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>wp core update<\/strong> - updates the WordPress core<\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>wp plugin list<\/strong> - shows a list of installed plugins, their current status (active\/inactive), and whether an update is available<\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>wp plugin update plugin-name<\/strong> - updates the specified plugin<\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>wp theme list<\/strong> - shows a list of installed themes, their current status (active\/inactive), and whether an update is available<\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong>wp theme update theme-name <\/strong>- updates the specified theme.<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">2. Password-protect the WordPress Dashboard<\/h2>\n\n\n\n<p>According to a <a href=\"https:\/\/www.pandasecurity.com\/mediacenter\/adaptive-defense\/most-common-tactics-among-cybercriminals\/\" target=\"_blank\" rel=\"noopener\">report from Panda Security<\/a>, 81% of all hacks are based on insecure or stolen login credentials. Our experience with hacked WordPress installations shows a lot of cases where the attacker was able to directly log into the Dashboard with administrator credentials. The login credentials (of a user with admin role) are usually obtained through a virus running on the user's compromised computer, but there are a number of other possibilities. For example, the credentials could have been sniffed while accessing the Dashboard over a public WiFi, or they could have been obtained via <a href=\"https:\/\/tickets.suresupport.com\/topics\/bruteforce-attacks\" target=\"_blank\" rel=\"noopener\">brute-force attack<\/a>. Bottom line is that once logged in, hackers typically proceed to install a malicious script as a plugin, or inject malicious code directly using WordPress' build-in theme or plugin editors. <\/p>\n\n\n\n<p>A very effective way to guard your WordPress installation against such unauthorized access to the administrative panel is to add a second layer of protection to it. That way, even if the bad guys have your WordPress credentials, they won't be able to access the Dashboard as that second layer would stand in their way. In addition, it keeps you safe from brute-force attacks. <\/p>\n\n\n\n<p>To set it up, you just need to password-protect the application's wp-login.php script. Our Control Panel allows you to do it in just a few simple steps:<\/p>\n\n\n\n<p>1) Log into the hosting account Control Panel -&gt; Protection -&gt; Web Access Protection section.<\/p>\n\n\n\n<p>2) Navigate to the folder where WordPress is installed. The interface should list the subfolders (wp-admin, wp-content, etc.) as well as the wp-login.php file.<\/p>\n\n\n\n<p>3) Use the Plain or Digest buttons next to the wp-login.php file, and add a user for it.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/cp-protect-wp-login.png\"><img decoding=\"async\" width=\"1024\" height=\"401\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/cp-protect-wp-login-1024x401.png\" alt=\"Server directory security settings overview for location \/home\/example\/www\/www, showing password protection and hotlinking prevention options.\" class=\"wp-image-4615 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/cp-protect-wp-login-1024x401.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/cp-protect-wp-login-300x118.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/cp-protect-wp-login-768x301.png 768w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/cp-protect-wp-login.png 1544w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/401;\" \/><\/a><figcaption class=\"wp-element-caption\">Click the Plain or Digest button for wp-login.php and set a username with password.<\/figcaption><\/figure>\n\n\n\n<p>We would recommend using the Digest method. This way, the credentials will be transmitted by the browser encrypted. The Plain method will have the browser submit the credentials unencrypted. This method can be used when the site is accessed over HTTPS. <\/p>\n\n\n\n<p>Note that if you password-protect the wp-login.php script, all users who have registered on your website and need to log in would have to enter the credentials for that extra layer of protection. Otherwise, they would not be able to reach the WordPress admin login page at all. This could be tricky for WordPress installations with many users. In such cases, you can just give all the registered users the same username and password for the password protection. Although they will have the same credentials for the additional protection layer, they will still keep their own separate login credentials for the actual WP Dashboard.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. Install an SSL Certificate on Your WordPress Website<\/h2>\n\n\n\n<p>We have an extensive <a href=\"https:\/\/www.icdsoft.com\/blog\/should-you-get-an-ssl-certificate\/\">blog post<\/a> on what SSL certificates are and how they work.  Basically, an SSL certificate encrypts the communication between the computer of your website visitor and the server. Now, you may wonder, just how exactly is this related to your overall WordPress security? The aforementioned blog post on SSL certificates shows how easy it is to sniff network traffic when a plain HTTP connection is used. If you access your Dashboard login page via HTTP, an attacker that's on the same WiFi network as you can capture your login credentials using a tool like Wireshark. <\/p>\n\n\n\n<p>If you install an SSL certificate on your website and force HTTPS connections, these login credentials would no longer be transmitted in plain text. They would be encrypted. That's how an SSL certificate improves your WP security. <\/p>\n\n\n\n<p>You can order a commercial SSL certificate from our website at <a rel=\"noreferrer noopener\" href=\"https:\/\/www.icdsoft.com\/en\/ssl\" target=\"_blank\">https:\/\/www.icdsoft.com\/en\/ssl<\/a>, or through the <a href=\"https:\/\/reseller.icdsoft.com\/\" target=\"_blank\" rel=\"noopener\">Reseller Panel<\/a>. We will install it on the server for you without any intervention required on your side. You will just have to approve the order via email. <\/p>\n\n\n\n<p>Alternatively, you can use a free SSL certificate from Let's Encrypt. Let's Encrypt certificates adhere to the same security standards and provide the same level of encryption. You can install a Let's Encrypt certificate from the Control Panel -&gt; SSL\/HTTP -&gt; Let's Encrypt certificates -&gt; select the subdomain in question (e.g. \"www.example.com \/ example.com\") -&gt; Enable.  <\/p>\n\n\n\n<p>Once you have an SSL certificate installed, you can force HTTPS connections to your website from the SSL\/HTTPS section in the Control Panel. Unless you have customized the appearance of your WordPress login form, this should be enough to ensure a fully secured HTTPS connection to it. However, your website might start throwing mixed-content errors. We have a <a href=\"https:\/\/tickets.suresupport.com\/faq\/article-1864\/en\/switch_a_wordpress_site_to_https\" target=\"_blank\" rel=\"noopener\">FAQ article<\/a> covering that topic, but you could also <a href=\"https:\/\/www.icdsoft.com\/en\/support\">ask our support team<\/a> to apply the necessary changes for you. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">4. Limit Your Hosting Account's FTP Service<\/h2>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/limit-ftp-ip.png\"><img decoding=\"async\" width=\"1024\" height=\"520\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/limit-ftp-ip-1024x520.png\" alt=\"FTP access protection settings with options to disable service or allow specific IP address range for access.\" class=\"wp-image-4627 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/limit-ftp-ip-1024x520.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/limit-ftp-ip-300x152.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/limit-ftp-ip-768x390.png 768w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/limit-ftp-ip.png 1549w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/520;\" \/><\/a><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>The FTP service is another common entry point for hackers. Quite often, we would see security incidents where a malicious script is uploaded to the web root folder (\/www\/www) over FTP and later accessed over HTTP to upload additional back doors and other malware. <\/p>\n<\/div>\n<\/div>\n\n\n\n<p>The most effective defense against this particular threat is to limit your account's FTP service only to your IP(s) or disable it completely. This is easily done from the Control Panel -&gt; Protection -&gt; FTP access protection. The interface will automatically pick up your current IP address and prefill it under the allowed IP address\/network section, so you can quickly add it.  <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">5. Improve the Security of Core WordPress Files\/Folders<\/h2>\n\n\n\n<p>This part focuses on several security improvements to the core WordPress infrastructure. Note that they come with some \"side effects\" that you need to be wary of, because they could break your website. That's why we strongly recommend that you test your site after applying each change to make sure everything works as expected. In case something goes wrong, you can easily revert the change. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5.1 Disable Execution of PHP Scripts in the \/wp-content\/ and \/wp-includes\/ Directories<\/h3>\n\n\n\n<p>This technique reduces the impact of a successful attack by disabling the execution PHP scripts inside the \/wp-content\/ and \/wp-includes\/ directories of WordPress. Typically, when hackers gain access to a website, they proceed to upload malicious files, and they often go to one of these folders or subfolders. <\/p>\n\n\n\n<p>You can apply this particular WordPress security improvement directly through the Control Panel. There, you should access the <strong>WordPress Manager<\/strong> -&gt; <strong>List WordPress Installations<\/strong> -&gt; <strong>Manage<\/strong> -&gt; <strong>Secure content directories<\/strong> -&gt; <strong>Apply<\/strong>. In case your WordPress installation is not listed there, you should go back to the <strong>Scan for WordPress installations<\/strong> menu, and Import it manually. <\/p>\n\n\n\n<figure class=\"wp-block-video\"><video controls src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/WordPress-Secure-Directories.webm\"><\/video><\/figure>\n\n\n\n<p>This tool will add the following code to the .htaccess file under the \/wp-content\/ and \/wp-includes\/ directories:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>### BEGIN PHP Security rules enabled via Control Panel &gt; WordPress ###\nOptions -Indexes\n# Execution prevention\n&lt;Files ~ \"\\.ph(?:p&#91;345]?|t|tml)$\"&gt;\n   deny from all\n&lt;\/Files&gt;\n#### END PHP Security rules enabled via Control Panel &gt; WordPress ####<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">5.2 Disable Access to Scripts In \/wp-includes\/<\/h3>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-includes-htaccess.png\"><img decoding=\"async\" width=\"1024\" height=\"549\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-includes-htaccess-1024x549.png\" alt=\"File manager displaying .htaccess configuration for WordPress rewrite rules in a web hosting environment.\" class=\"wp-image-4658 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-includes-htaccess-1024x549.png 1024w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-includes-htaccess-300x161.png 300w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/wp-includes-htaccess-768x412.png 768w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/549;\" \/><\/a><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>We will add a code to your WordPress' .htaccess file that  disables the direct access to scripts in the wp-includes folder. Adding that code should not cause any issues with your website, because scripts in that folder are not meant to be accessed directly by users in the first place. <\/p>\n<\/div>\n<\/div>\n\n\n\n<p>Here is the code you should add to the .htaccess file under the folder where WordPress is installed (you should have that file by default):<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"># Block the include-only files. \n&lt;IfModule mod_rewrite.c> \nRewriteEngine On \nRewriteBase \/ \nRewriteRule ^wp-admin\/includes\/ - [F,L] \nRewriteRule\u00a0!^wp-includes\/ - [S=3] \nRewriteRule ^wp-includes\/[^\/]+\\.php$ - [F,L] \nRewriteRule ^wp-includes\/js\/tinymce\/langs\/.+\\.php - [F,L] \nRewriteRule ^wp-includes\/theme-compat\/ - [F,L] \n&lt;\/IfModule> \n<\/pre>\n\n\n\n<p>You can add the code using the File Manager in the Control Panel. Make sure to add it outside the # BEGIN WordPress and # END WordPress tags. Otherwise, it could get overwritten. If you are using a WordPress Multisite installation, you should remove the line <em>RewriteRule ^wp-includes\/[^\/]+\\.php$ - [F,L] <\/em>as it prevents the execution of ms-files.php, which generates images. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5.3 Disable File Editing<\/h3>\n\n\n\n<p>As noted, hackers often use the WordPress Dashboard to upload malicious plugins or inject code in existing plugins or themes. That's why it's a good idea to completely disable the file editing via the Dashboard. You can do this by adding the following lines in the wp-config.php file using the File Manager:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">## Disable Editing in Dashboard <br>define('DISALLOW_FILE_EDIT', true);<\/pre>\n\n\n\n<p>These lines should be added in the middle of the file along with the other defines. Note that once added, you will no longer see the Theme Editor under the Appearance menu of the Dashboard. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>If your website is built with WordPress, you have a huge target on your back, and that&#8217;s why we will show you how to improve the security of your WordPress website. Picture this &#8211; you&#8217;ve invested loads of time, money, and effort into building and developing your website, traffic has started to rise, and all<\/p>\n","protected":false},"author":1,"featured_media":4360,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","footnotes":""},"categories":[11,6],"tags":[14,8],"class_list":{"0":"post-4342","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-wordpress","8":"category-security","9":"tag-security","10":"tag-wordpress"},"author_meta":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"featured_img":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/03\/wp-sec-300x162.png","featured_image_src":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/03\/wp-sec.png","featured_image_src_square":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/03\/wp-sec.png","author_info":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"coauthors":[],"tax_additional":{"categories":{"linked":["<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/wordpress\/\" class=\"advgb-post-tax-term\">WordPress<\/a>","<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/security\/\" class=\"advgb-post-tax-term\">Security<\/a>"],"unlinked":["<span class=\"advgb-post-tax-term\">WordPress<\/span>","<span class=\"advgb-post-tax-term\">Security<\/span>"]},"tags":{"linked":["<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/security\/\" class=\"advgb-post-tax-term\">security<\/a>","<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/security\/\" class=\"advgb-post-tax-term\">WordPress<\/a>"],"unlinked":["<span class=\"advgb-post-tax-term\">security<\/span>","<span class=\"advgb-post-tax-term\">WordPress<\/span>"]}},"comment_count":"0","relative_dates":{"created":"Posted 7 years ago","modified":"Updated 2 years ago"},"absolute_dates":{"created":"Posted on April 17, 2019","modified":"Updated on February 20, 2024"},"absolute_dates_time":{"created":"Posted on April 17, 2019 12:08 pm","modified":"Updated on February 20, 2024 8:24 pm"},"featured_img_caption":"","series_order":"","_links":{"self":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/4342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/comments?post=4342"}],"version-history":[{"count":118,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/4342\/revisions"}],"predecessor-version":[{"id":14305,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/4342\/revisions\/14305"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media\/4360"}],"wp:attachment":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media?parent=4342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/categories?post=4342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/tags?post=4342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}