Monday, March 1, 2010

WordPress Security Plugins - Half the Battle

You might think that installing a few WordPress security plugins does the entire job of protecting your site. Security plugins can help make your site safer (i.e. database backups, login lockouts). Most people don't realize that there's much more involved in order to protect a WordPress blog.

WordPress is an application powered by PHP and MySQL. Many high-traffic websites use MySQL and PHP for large-volume data storage. If you are a WordPress user, anytime you create a post or page, the information gets stored on your database. Even though there are WordPress plugins out there that can help backup your database in case of disaster, you always want to take all necessary precautions to prevent your site from being hacked.

WordPress developers release a security update when a known vulnerability needs to be addressed, but it's impossible to seal every loophole. In the world of cyber crime, someone will always find a way around it -- it's inevitable. Even with the addition of plugins being installed to "beef up" your security, your WordPress site is still at risk. You can, for example, protect your site from brute force password attacks for your WP admin area. However, this does not protect your database nor does it prevent unwanted visitors from entering your server via FTP. Remember, when it comes to securing your WordPress site, you have to make sure you cover all angles.

Every time a user installs WordPress, it will always install the default folders and directories. Since many people don't bother configuring the back-end, they don't realize that they end up leaving the doors wide open, making them vulnerable for a malicious attack.

With that said, it's important to make sure that you secure all areas of your website, including your server, database, logins, comments, files/directories, and wp-admin. If you're looking for help in securing your blog or website or would like a WordPress security audit, let us know. Just remember, installing a few security plugins is only half the battle.

