• I trusted them and my site was hacked successfully by some hackers. BlackHeart using a fake google bot.

Viewing 2 replies - 1 through 2 (of 2 total)
  • barnez

    (@pidengmor)

    No system can be 100% secure, and installing a security plugin such as Wordfence should only represent one strand of your security policy, which should also include:

    • keeping you local computer secure
    • enforcing strong unique passwords that are regularly updated and securely stored
    • using a responsible host
    • understanding the inherent risks of shared hosting
    • using well-maintained and well-coded plugins/themes
    • updating all themes/plugins/core in a timely manner
    • ensuring FTP connections are encrypted
    • reviewing all file/folder permissions
    • leveraging the .htaccess file
    • disabling file editing in the WP dashboard
    • taking regular backups
    • monitoring your installation for changes

    Even by implementing the above sometimes hacks will still occur, and in this case having a good backup will allow for a clean restore, while being able to monitor file changes and logs will help you to understand the attack vector.

    Really, any installation is only as secure as the weakest link.

    Useful links
    http://codex.wordpress.org/Hardening_WordPress
    http://wpsecure.net/secure-wordpress-advanced/
    https://moz.com/blog/the-definitive-guide-to-wordpress-security

    Good luck!

    barnez, I am impressed with the information you share, the way you explain the issues, additional links with pertinent information, ending with the knowledge that we are responsible ourselves.
    Kuddos

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘free version is useless.’ is closed to new replies.