{"id":46408,"date":"2016-01-12T05:35:00","date_gmt":"2016-01-12T05:35:00","guid":{"rendered":"https:\/\/www.crazydomains.com\/learn\/how-safe-is-your-wordpress-site-from-hackers-6-ways-to-protect-yourself\/"},"modified":"2020-08-05T14:11:17","modified_gmt":"2020-08-05T06:11:17","slug":"website-security","status":"publish","type":"post","link":"https:\/\/www.crazydomains.com\/learn\/website-security\/","title":{"rendered":"How safe is your WordPress site from hackers? 6 ways to protect yourself"},"content":{"rendered":"<p>The Internet can be a scary place.<\/p>\n<p>It seems like every day we&#8217;re reading about some new weakness (<a href=\"http:\/\/blog.crazydomains.com\/2015\/07\/android-stagefright.html\" target=\"blank\" rel=\"noopener noreferrer\">Stagefright<\/a>, anyone?) that, once you cut through the technical jargon, means that none of us are safe. As one of the most popular platforms for website creation, <a href=\"https:\/\/www.crazydomains.com.au\/wordpress-hosting\/\" target=\"_blank\" rel=\"noopener noreferrer\">WordPress<\/a> is a common target for hackers and often features in stories like this.<\/p>\n<p>Even if we allow that some of the hype is media scaremongering, it&#8217;s still a sobering thought that the sites you work so hard on can be taken away, broken, or used to distribute malware.<\/p>\n<p>It&#8217;s frustrating when your hard work gets stolen or ripped off. That&#8217;s why we decided to write a quick tutorial on the common threats that WordPress sites face and some easy ways that you can reduce the threats to them. We tried to make this as easy as we could without too much technical mumbo-jumbo.<\/p>\n<p>First we&#8217;ll go over six of the most common threats to WordPress sites and how to fix them. At the end we have some suggestions on software and plugins to use when securing your site.<\/p>\n<h2 style=\"font-size: x-large;\">Threat #1: Brute Force Password Attacks<\/h2>\n<p>Brute force password attacks are when a computer tries to guess your login information by trying every combination of numbers and letters it knows. For a person, this could take years, but for a computer it could guess a relatively short password <a href=\"http:\/\/www.bloomberg.com\/bw\/magazine\/content\/11_06\/b4214036460585.htm\" target=\"blank\" rel=\"nofollow noopener noreferrer\">in minutes<\/a>.<\/p>\n<p>This is especially dangerous if the attacker already knows your username. It&#8217;s just one fewer thing they have to guess.<\/p>\n<p>But hang on, how could they know your username? Well, if you left it as \u201cadmin\u201d then they already do.<\/p>\n<p>Even if you&#8217;ve changed the username from \u201cadmin\u201d (and you really should), there are still ways of finding it out.<\/p>\n<p>Type in your browser window \u201cmy-site.com\/?author=1\u201d (replace my-site with your domain name and add your WordPress subdirectory if it&#8217;s not on your main domain, so this could be example.com\/blog\/?author=1).<\/p>\n<p>Most often, you&#8217;ll see your username come up. If not, try typing the same thing again with 2 at the end, and keep going until 10. You&#8217;ll see your username soon enough.<\/p>\n<p>Once an attacker has your username, they can try to brute force your password.<\/p>\n<p>If you have an easy password, then believe me \u2013 the only reason your site hasn&#8217;t been hacked yet is that nobody has really tried to.<\/p>\n<h2 style=\"font-size: x-large;\">Solution: Strengthen Passwords and Limit Login Attempts:<\/h2>\n<p>There are plugins out there to prevent user enumeration, but the best ways to prevent brute-force password attacks are to choose a strong password and limit login attempts.<\/p>\n<h3 style=\"font-size: large; margin-bottom: 20px;\">Strong Passwords<\/h3>\n<p>It goes without saying that \u201cadmin\/123456\u201d is not a good username\/password combination (although it is distressingly common). A strong password is long, not a word from the dictionary or Wikipedia (in any language), and contains a variety of symbols.<\/p>\n<p>CLU is the acronym to remember: Complex, Long, and Unique.<\/p>\n<p>That, unfortunately, also makes your passwords almost impossible to remember.<\/p>\n<p>One option is to use a pass phrase instead of a single word. A computer is going to take a long time guessing a 25-character phrase (assuming 1000 guesses per second, that&#8217;s 550 years &#8211; <a href=\"http:\/\/security.stackexchange.com\/questions\/6095\/xkcd-936-short-complex-password-or-long-dictionary-passphrase\/6096#6096\" target=\"blank\" rel=\"nofollow noopener noreferrer\">source<\/a>) that&#8217;s comparatively easy for a person to remember \u2013 it&#8217;s harder for a computer to guess a random phrase than it is to guess just one word. A password like &#8220;B0ndfriskingmaniacvillain&#8221; can be easy to remember, but very hard for a computer to brute-force.<\/p>\n<p>Just remember &#8211; if your attempts to make a secure password lead you to writing it down and sticking it onto your monitor, then that&#8217;s already a bad password.<\/p>\n<p>If you prefer even more secure passwords, or want a way to avoid having to remember them, there are some resources you can use for that. We&#8217;ll include a couple in our list at the end of this article.<\/p>\n<p>You can also enable multi-factor authentication, and there are great programs in our list that let you do that as well. It can seem like a pain, but effective security measures often mean that we need to change our habits just a little bit.<\/p>\n<h3 style=\"font-size: large; margin-bottom: 20px;\">Limit Login Attempts<\/h3>\n<p>No matter how strong your password is, if someone has an infinite number of attempts to guess it, they eventually will. On the other hand, even a relatively weak password can&#8217;t be guessed in just a couple of tries.<\/p>\n<p>Good security plugins and software (you can skip to the end of the article for our suggestions) will limit the number of unsuccessful login attempts and block IP addresses that try to brute-force your passwords.<\/p>\n<h2 style=\"font-size: x-large;\">Threat #2: Plugins, WordPress Version, and Themes<\/h2>\n<p>Remember that no reputable developers try to make software with security flaws. That means that when <a href=\"http:\/\/blog.akismet.com\/2015\/10\/13\/akismet-3-1-5-wordpress\/\" target=\"blank\" rel=\"nofollow noopener noreferrer\">something comes up<\/a>, developers stay up all hours patching their software and fixing the code.<\/p>\n<p>Imagine their disappointment when people don&#8217;t update their sites. A new version of the code isn&#8217;t going to help if you&#8217;ve still got the old version on your site because clicking the &#8220;update&#8221; button was too hard.<\/p>\n<p>Check your plugins and themes regularly to make sure that they aren&#8217;t out of date and that they don&#8217;t have serious security risks. It also makes the developers happy that people value their work.<\/p>\n<p>Another important thing to remember here \u2013 people who crack and distribute free versions of WordPress themes? They&#8217;re usually including some of their own code in there. And when we say \u201ccode\u201d, we mean \u201cviruses, Trojans, and backdoors\u201d that they can use to damage your site.<\/p>\n<h2 style=\"font-size: x-large;\">Solution: Update Your Plugins, WordPress Version, and Themes<\/h2>\n<p>Enough said. The latest versions are the versions with problems that nobody knows yet. In the world of information security that&#8217;s as good as it gets.<\/p>\n<p>Also, don&#8217;t try to pirate themes. It&#8217;s just not worth it. Only download themes from sources that you can trust, and if someone has created a great theme, just buy it. It saves time and trouble in the long run.<\/p>\n<h2 style=\"font-size: x-large;\">Threat #3: Table Access<\/h2>\n<p>Here&#8217;s where we get into a little bit of code \u2013 but don&#8217;t worry, it&#8217;s very simple code.<\/p>\n<p>The first of the two files we&#8217;ll be looking at is wp-config.php. This is a very important file that WordPress uses to communicate with databases.<\/p>\n<p>The databases are where posts, settings, and users are all stored. You want to make sure that nobody can access this file other than you.<\/p>\n<p>The second is the .htaccess file. This is a file that Apache (the software that web servers use, not the tribe) uses to decide how to retrieve files.<\/p>\n<p>It&#8217;s also a very important potential vulnerability. The good news is, it can be used to close down access to both itself and to the wp-config.php file.<\/p>\n<p>Just by seeing these files, attackers can gain valuable information about how your site is configured, which can lead them to discovering vulnerabilities. Obviously you don&#8217;t want this to happen.<\/p>\n<h2 style=\"font-size: x-large;\">Solution: Your Own Coding<\/h2>\n<p>Here is the code you need to put into your .htaccess file:<\/p>\n<pre>&lt;Files wp-config.php&gt;\r\norder allow,deny\r\ndeny from all\r\n&lt;\/Files&gt;\r\n\r\n&lt;Files .htaccess&gt;\r\norder allow,deny\r\ndeny from all\r\n&lt;\/Files&gt;<\/pre>\n<p>Just go to your .htaccess file and put that code in there. If you need help finding your .htaccess file, check out our Support articles for an explanation.<\/p>\n<p>This code will tell your server not to let anyone access those files, but won&#8217;t stop you from getting to them with local access.<\/p>\n<h2 style=\"font-size: x-large;\">Threat #4: Phishing<\/h2>\n<p><img decoding=\"async\" src=\"http:\/\/1.bp.blogspot.com\/-CesQ_D28S5I\/Vnpb3Ybq4nI\/AAAAAAAAAd8\/JFw1ey3qaL0\/s1600\/153175439.png\" border=\"0\" \/><\/p>\n<p>This isn&#8217;t so much a specific WordPress problem as it is a general security problem, but it&#8217;s such an important one that it deserves a mention here.<\/p>\n<p>Phishing, as <a href=\"http:\/\/blog.crazydomains.com\/2015\/10\/domain-phishing-attacks-have-you-been.html\" target=\"blank\" rel=\"noopener noreferrer\">we reported earlier<\/a> can take many forms \u2013 it can come as spam emails that directly ask you for your passwords, as faked sites that ask for login details \u2013 basically, any way you can think of for someone to try and steal your username and password.<\/p>\n<h2 style=\"font-size: x-large;\">The Solution: Be Suspicious<\/h2>\n<p>Now, being suspicious is normally not a good thing. But online it can save you.<\/p>\n<p>Don&#8217;t use links that you get in emails to log onto sites. Log on in a separate window by navigating to the site as you normally would.<\/p>\n<p>Also, never tell anyone your login details over email. No matter who they claim to be.<\/p>\n<h2 style=\"font-size: x-large;\">Threat #5: Cross-Site Scripting (XSS)<\/h2>\n<p>This is the most common threat to WordPress sites, and almost deserves an article to itself. It&#8217;s a way that attackers can put their own code into your site. Let&#8217;s look at how that&#8217;s possible.<\/p>\n<p>HTML is the language used to create web pages, and it&#8217;s what is called a <strong>tag-based<\/strong> language.<\/p>\n<p>For example, if I want to create <strong>bold text<\/strong>, I use a <i>tag<\/i> that is placed around the text that I want to make bold &#8211; like this: &lt;strong&gt;text that I want to make bold&lt;\/strong&gt;. The tags aren&#8217;t shown to the person visiting the page, instead they change how the text inside them is displayed.<\/p>\n<p>Note &#8211; I&#8217;m describing HTML in a really over-simplified way, but it works for the example I&#8217;m trying to make.<\/p>\n<p>Almost all tags in HTML function like the &lt;strong&gt; tag, with one exception. That tag is &lt;script&gt;.<\/p>\n<p>&lt;script&gt; says to the browser,<\/p>\n<p>&#8220;Hey, what&#8217;s written inside this isn&#8217;t text, so don&#8217;t show it to the user. Instead, it&#8217;s a piece of code.&#8221;<\/p>\n<p>This is really useful for creating interactive sites, but it can lead to some big problems if it&#8217;s misused.<\/p>\n<p>Now, some fields in a site allow use of HTML &#8211; sometimes you want your visitors to be able to put a link in a comment, or make their text bold. That&#8217;s fine, and it usually doesn&#8217;t hurt anything (unless it&#8217;s a spam link).<\/p>\n<p>However, if they can put &lt;script&gt; in your pages, then that&#8217;s a disaster waiting to happen. They use that vulnerability to change the way your site works, which is never good. Forget what you learned at nursery school &#8211; not everything needs to be shared, especially control over your site.<\/p>\n<p>For example, if you have a page that prints the most recent search that a user has made (something that reads: &#8220;You searched for X&#8221;, for example), then this is a sort of pseudo-code that might be what your server says (note: this is not real server code):<\/p>\n<pre>print \"&lt;html&gt;\"\r\nprint \"&lt;h1&gt;You searched for&lt;\/h1&gt;\"\r\nprint database.latestSearch\r\nprint \"&lt;\/html&gt;\"<\/pre>\n<p>This lets an attacker search for<\/p>\n<pre>&lt;script&gt;doSomethingTerrible();&lt;\/script&gt;<\/pre>\n<p>When the page loads, that script will execute because the page will read:<\/p>\n<pre>&lt;html&gt;\r\n&lt;h1&gt;You searched for:&lt;\/h1&gt;\r\n&lt;script&gt;doSomethingTerrible();&lt;\/script&gt;\r\n&lt;\/html&gt;<\/pre>\n<p>Because the page loads user input as HTML without blocking the &lt;script&gt; tag, the attacker is able to add this script to a page.<\/p>\n<p>That&#8217;s XSS in a nutshell, and while there are more complex ways of doing it (hence all the vulnerabilities related to it) that&#8217;s the basic way that XSS works.<\/p>\n<h2 style=\"font-size: x-large;\">The Solution: Approve User Input<\/h2>\n<p><a style=\"margin-left: 1em; margin-right: 1em;\" href=\"http:\/\/3.bp.blogspot.com\/-ML7CGtM4hcs\/VnpQH9jCDhI\/AAAAAAAAAdE\/TESWBjvtOgA\/s1600\/xss%2Bscreenshot.png\"><img fetchpriority=\"high\" decoding=\"async\" style=\"width: 320px !important; height: 300px !important;\" src=\"http:\/\/3.bp.blogspot.com\/-ML7CGtM4hcs\/VnpQH9jCDhI\/AAAAAAAAAdE\/TESWBjvtOgA\/s320\/xss%2Bscreenshot.png\" width=\"320\" height=\"300\" border=\"0\" \/><\/a><\/p>\n<p>But hang on, you might think, there&#8217;s nowhere that people can create user input on my blog. Why should I be scared of some script tag?<\/p>\n<p>What about the comment section? The same place where people tell you how much your posts rock can also be the place that attackers inject code into your site.<\/p>\n<p>This is how most XSS attacks are made, so protect yourself by manually approving comments. It may seem like a lot of work, but it can save your site.<\/p>\n<p><a href=\"http:\/\/akismet.com\/\" target=\"blank\" rel=\"nofollow noopener noreferrer\">Akismet<\/a> is one of the most common ways of securing comments &#8211; it also helps you eliminate spam. No WordPress site should leave home without it.<\/p>\n<p>You should <strong>never<\/strong> allow comments that have a bunch of what looks like nonsense in them &#8211; this is probably obfuscated (hidden or disguised) code, and you should delete those comments with extreme prejudice.<\/p>\n<p>Apply this principle to all user input on your site, and again, make sure that you update your plugins as soon as new versions come out, as new XSS attack methods get found very often.<\/p>\n<h2 style=\"font-size: x-large;\">Threat #6: Using Poor Software<\/h2>\n<p>There is so much software out there that you can use to harden your WordPress site that there is no excuse not to use the very best. These are just some programs that you can use to improve your security, categorized by the threat they cover. Using substandard software will bring you substandard results, so accept no substitutes.<\/p>\n<h2 style=\"font-size: x-large;\">Solution: The Crazy Easy Security Software List!<\/h2>\n<p>Now what you&#8217;ve all been waiting for \u2013 here&#8217;s our Crazy Easy software list, solutions that you can use so you don&#8217;t have to worry about your WordPress site getting hacked. We&#8217;ve divided it into solutions based on what problems they solve.<\/p>\n<h3 style=\"font-size: large; margin-bottom: 20px;\">Password solutions:<\/h3>\n<p><a href=\"https:\/\/lastpass.com\/\" target=\"blank\" rel=\"nofollow noopener noreferrer\">LastPass<\/a> is a service that remembers your passwords for you.<\/p>\n<p><a href=\"http:\/\/www.passwordcard.org\/en\" target=\"blank\" rel=\"nofollow noopener noreferrer\">Passwordcard<\/a> is a free resource that lets you create a card that generates and stores your passwords. It&#8217;s a great, comparatively low-tech solution to the problem of creating and remembering effective passwords.<\/p>\n<p><a href=\"https:\/\/agilebits.com\/onepassword\" target=\"blank\" rel=\"nofollow noopener noreferrer\">1password<\/a> is similar to LastPass \u2013 it creates strong, unique passwords for you and remembers them for all your accounts.<\/p>\n<p><a href=\"https:\/\/wordpress.org\/plugins\/wpclef\/\" target=\"blank\" rel=\"nofollow noopener noreferrer\">Clef<\/a> is an app for two-factor authentication. It uses your smartphone as a sort of digital key and is very easy to use.<\/p>\n<p><a href=\"https:\/\/wordpress.org\/plugins\/stop-user-enumeration\/\" target=\"blank\" rel=\"nofollow noopener noreferrer\">The Stop User Enumeration plugin<\/a> makes it impossible for attackers to find out your admin username.<\/p>\n<h3 style=\"font-size: large; margin-bottom: 20px;\">Theme, Plugin, and Version Checking Solutions<\/h3>\n<p><a href=\"https:\/\/hackertarget.com\/wordpress-security-scan\/\" target=\"blank\" rel=\"nofollow noopener noreferrer\">The WordPress security scan<\/a> is a simple testing tool that will find many of the vulnerabilities that we discussed in this article. It works as a good checklist to make sure that you have implemented your security correctly.<\/p>\n<p><a href=\"http:\/\/wpscan.org\/\" target=\"blank\" rel=\"nofollow noopener noreferrer\">wpscan.org<\/a> is a black box WordPress vulnerability scanner. It takes a little bit of technical know-how to use and install, but is very effective. It gives you a full understanding of your site&#8217;s vulnerabilities.<\/p>\n<h3 style=\"font-size: large; margin-bottom: 20px;\">General WordPress Security solutions<\/h3>\n<p><a href=\"https:\/\/wordpress.org\/plugins\/wordfence\/\" target=\"blank\" rel=\"nofollow noopener noreferrer\">The WordFence plugin<\/a> is one of the most popular security plugins for WordPress and its advantages are enjoyed by literally millions of site users.<\/p>\n<p><a href=\"https:\/\/wordpress.org\/plugins\/bulletproof-security\/\" target=\"blank\" rel=\"nofollow noopener noreferrer\">The BulletProof Security plugin<\/a> is another very highly-rated security plugin and works as a general security solution with many interesting features. This one is great for the more technically-minded site owner.<\/p>\n<p><a href=\"https:\/\/www.crazydomains.com.au\/website-protection\/\" target=\"blank\" rel=\"noopener noreferrer\">The Crazy Domains All-in-one Site Protection and Scanner<\/a> will monitor any site (not just WordPress) with daily site scans, malware and hacker protection, blacklist protection, and expert guidance. It&#8217;s really Crazy Easy site protection.<\/p>\n<p>One thing to remember is that WordPress security is not static \u2013 it&#8217;s not something that you do once and forget about forever. Hacking is like all software development. It exists in a constantly changing world that now, more than ever, refuses to stand still. Make sure you&#8217;re checking frequently. Even if you have software that checks frequently for you, it&#8217;s always good to be sure.<\/p>\n<p>We hope that you found this guide useful \u2013 make sure to share it with your friends if they also have WordPress sites. Together we can help each other make our sites more secure so that we can spend more time making them the best they can be.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Internet can be a scary place. It seems like every day we&#8217;re reading about some new weakness (Stagefright, anyone?) that, once you cut through the technical jargon, means that none of us are safe. As one of the most popular platforms for website creation, WordPress is a common target for hackers and often features [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":1427,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[1001],"tags":[251],"coauthors":[1119],"class_list":["post-46408","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-website","tag-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Is Your WordPress Site Safe from Hackers? | Crazy Domains AU<\/title>\n<meta name=\"description\" content=\"Wordpress threats are inevitable but you can always protect your website with the right plugins &amp; software. Find out the needed Wordpress plugins to secure it.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.crazydomains.com\/learn\/website-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Is Your WordPress Site Safe from Hackers? | Crazy Domains AU\" \/>\n<meta property=\"og:description\" content=\"Wordpress threats are inevitable but you can always protect your website with the right plugins &amp; software. Find out the needed Wordpress plugins to secure it.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.crazydomains.com\/learn\/website-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Crazy Domains Learn\" \/>\n<meta property=\"article:published_time\" content=\"2016-01-12T05:35:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-08-05T06:11:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"950\" \/>\n\t<meta property=\"og:image:height\" content=\"534\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Anand Dibble\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Anand Dibble\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/\"},\"author\":{\"name\":\"Anand Dibble\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#\/schema\/person\/a84922d0aa86b782382f193534073416\"},\"headline\":\"How safe is your WordPress site from hackers? 6 ways to protect yourself\",\"datePublished\":\"2016-01-12T05:35:00+00:00\",\"dateModified\":\"2020-08-05T06:11:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/\"},\"wordCount\":2530,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg\",\"keywords\":[\"Security\"],\"articleSection\":[\"Website - Learn\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.crazydomains.com\/learn\/website-security\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/\",\"url\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/\",\"name\":\"Is Your WordPress Site Safe from Hackers? | Crazy Domains AU\",\"isPartOf\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg\",\"datePublished\":\"2016-01-12T05:35:00+00:00\",\"dateModified\":\"2020-08-05T06:11:17+00:00\",\"description\":\"Wordpress threats are inevitable but you can always protect your website with the right plugins & software. Find out the needed Wordpress plugins to secure it.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.crazydomains.com\/learn\/website-security\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/#primaryimage\",\"url\":\"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg\",\"contentUrl\":\"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg\",\"width\":\"950\",\"height\":\"534\",\"caption\":\"Website security - wordpress logo with codes in the background\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/website-security\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.crazydomains.com.au\/learn\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How safe is your WordPress site from hackers? 6 ways to protect yourself\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#website\",\"url\":\"https:\/\/www.crazydomains.com\/learn\/\",\"name\":\"Crazy Domains Learn\",\"description\":\"Resources to help you excel online\",\"publisher\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.crazydomains.com\/learn\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#organization\",\"name\":\"Crazy Domains Learn\",\"url\":\"https:\/\/www.crazydomains.com\/learn\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2021\/02\/learn-dash-blue-logo-2.svg\",\"contentUrl\":\"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2021\/02\/learn-dash-blue-logo-2.svg\",\"width\":147,\"height\":43,\"caption\":\"Crazy Domains Learn\"},\"image\":{\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#\/schema\/person\/a84922d0aa86b782382f193534073416\",\"name\":\"Anand Dibble\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.crazydomains.com\/learn\/#\/schema\/person\/image\/8843dd29f6544a81e29c05114b7ea3b8\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a1ce2ba71a221bafe6e5b94f3ef1c489?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a1ce2ba71a221bafe6e5b94f3ef1c489?s=96&d=mm&r=g\",\"caption\":\"Anand Dibble\"},\"url\":\"https:\/\/www.crazydomains.com\/learn\/author\/anand-dibble\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Is Your WordPress Site Safe from Hackers? | Crazy Domains AU","description":"Wordpress threats are inevitable but you can always protect your website with the right plugins & software. Find out the needed Wordpress plugins to secure it.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.crazydomains.com\/learn\/website-security\/","og_locale":"en_US","og_type":"article","og_title":"Is Your WordPress Site Safe from Hackers? | Crazy Domains AU","og_description":"Wordpress threats are inevitable but you can always protect your website with the right plugins & software. Find out the needed Wordpress plugins to secure it.","og_url":"https:\/\/www.crazydomains.com\/learn\/website-security\/","og_site_name":"Crazy Domains Learn","article_published_time":"2016-01-12T05:35:00+00:00","article_modified_time":"2020-08-05T06:11:17+00:00","og_image":[{"width":950,"height":534,"url":"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg","type":"image\/jpeg"}],"author":"Anand Dibble","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Anand Dibble","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/#article","isPartOf":{"@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/"},"author":{"name":"Anand Dibble","@id":"https:\/\/www.crazydomains.com\/learn\/#\/schema\/person\/a84922d0aa86b782382f193534073416"},"headline":"How safe is your WordPress site from hackers? 6 ways to protect yourself","datePublished":"2016-01-12T05:35:00+00:00","dateModified":"2020-08-05T06:11:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/"},"wordCount":2530,"commentCount":0,"publisher":{"@id":"https:\/\/www.crazydomains.com\/learn\/#organization"},"image":{"@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg","keywords":["Security"],"articleSection":["Website - Learn"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.crazydomains.com\/learn\/website-security\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/","url":"https:\/\/www.crazydomains.com\/learn\/website-security\/","name":"Is Your WordPress Site Safe from Hackers? | Crazy Domains AU","isPartOf":{"@id":"https:\/\/www.crazydomains.com\/learn\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/#primaryimage"},"image":{"@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg","datePublished":"2016-01-12T05:35:00+00:00","dateModified":"2020-08-05T06:11:17+00:00","description":"Wordpress threats are inevitable but you can always protect your website with the right plugins & software. Find out the needed Wordpress plugins to secure it.","breadcrumb":{"@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.crazydomains.com\/learn\/website-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/#primaryimage","url":"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg","contentUrl":"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2016\/01\/wordpress-code-image.jpg","width":"950","height":"534","caption":"Website security - wordpress logo with codes in the background"},{"@type":"BreadcrumbList","@id":"https:\/\/www.crazydomains.com\/learn\/website-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.crazydomains.com.au\/learn\/"},{"@type":"ListItem","position":2,"name":"How safe is your WordPress site from hackers? 6 ways to protect yourself"}]},{"@type":"WebSite","@id":"https:\/\/www.crazydomains.com\/learn\/#website","url":"https:\/\/www.crazydomains.com\/learn\/","name":"Crazy Domains Learn","description":"Resources to help you excel online","publisher":{"@id":"https:\/\/www.crazydomains.com\/learn\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.crazydomains.com\/learn\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.crazydomains.com\/learn\/#organization","name":"Crazy Domains Learn","url":"https:\/\/www.crazydomains.com\/learn\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.crazydomains.com\/learn\/#\/schema\/logo\/image\/","url":"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2021\/02\/learn-dash-blue-logo-2.svg","contentUrl":"https:\/\/www.crazydomains.com\/learn\/wp-content\/uploads\/2021\/02\/learn-dash-blue-logo-2.svg","width":147,"height":43,"caption":"Crazy Domains Learn"},"image":{"@id":"https:\/\/www.crazydomains.com\/learn\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.crazydomains.com\/learn\/#\/schema\/person\/a84922d0aa86b782382f193534073416","name":"Anand Dibble","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.crazydomains.com\/learn\/#\/schema\/person\/image\/8843dd29f6544a81e29c05114b7ea3b8","url":"https:\/\/secure.gravatar.com\/avatar\/a1ce2ba71a221bafe6e5b94f3ef1c489?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a1ce2ba71a221bafe6e5b94f3ef1c489?s=96&d=mm&r=g","caption":"Anand Dibble"},"url":"https:\/\/www.crazydomains.com\/learn\/author\/anand-dibble\/"}]}},"lang":"us","translations":{"us":46408,"au":4235,"sg":4249,"uk":4237,"zh":4239,"in":4241,"my":4245,"ph":4247,"ae":4251,"nz":4253,"id":4243},"pll_sync_post":[],"_links":{"self":[{"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/posts\/46408"}],"collection":[{"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/comments?post=46408"}],"version-history":[{"count":0,"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/posts\/46408\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/media\/1427"}],"wp:attachment":[{"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/media?parent=46408"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/categories?post=46408"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/tags?post=46408"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.crazydomains.com\/learn\/wp-json\/wp\/v2\/coauthors?post=46408"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}