Title: WordPress Sites Hacking Issue?
Last modified: August 20, 2016

---

# WordPress Sites Hacking Issue?

 *  [nehaseo](https://wordpress.org/support/users/nehaseo/)
 * (@nehaseo)
 * [14 years, 9 months ago](https://wordpress.org/support/topic/wordpress-sites-hacking-issue/)
 * Hi All
 * Can anyone help me how to avoid wordpress site hacking by SQL injection, index.
   php file replacements, while I use all securities like strong passwords etc.

Viewing 1 replies (of 1 total)

 *  [Roy](https://wordpress.org/support/users/gangleri/)
 * (@gangleri)
 * [14 years, 9 months ago](https://wordpress.org/support/topic/wordpress-sites-hacking-issue/#post-2260117)
 * Yes, by not connecting the website to the internet.
 * Frankly, when a website can be accessed from any place in the world, it can be
   hacked. Of course you can try to make this as unlikely as possible, but there
   can never be a guarantee “to avoid” it.
 * Of course it’s not just WP either. You have to mind themes, more particularly
   plugins, but there is always a risk that your host has outdated server software,
   that you share a server with someone with a stoneage WP or Joomla (or else) that
   give hackers access to the server that your website is on, that sort of stuff.
 * Not to make you overly scared, just cautious. In my 4 years with WP I have never
   been hacked, even though I’m on a shared server with a few hundred other websites(
   fingers crossed 🙂 ).
 * Well then, start here for tips to make your WP as save as possible:
    [http://codex.wordpress.org/Hardening_WordPress](http://codex.wordpress.org/Hardening_WordPress)
   I personally have wp-admin, wp-includes and the login/logout screens behind htaccess
   passwords, my table prefix is not wp_ and my admin username is not “admin”. I
   have Bad Behavior running to hold off bots. This did the trick over the last 
   years. Btw, the numbers of security patches for WP because some vulnerability
   has been discovered has greatly DEcreased over the years. This means that WP 
   itself is getting safer and safer too. When you look back at the most recent “
   hacked” threads on this forum, since the last year (or so) this have always been
   server side hacks of websites on some particular host. There hasn’t been a widespread
   WP hack for a long time. Of course there are always boneheads with old versions,
   but even those hacked seems to become rarer. There’s is almost nothing that hackers
   discover these days that they can make use of and when they do, WP is updated
   and we all upgrade to the latest version asap. Staying up to date is crucial.

Viewing 1 replies (of 1 total)

The topic ‘WordPress Sites Hacking Issue?’ is closed to new replies.

## Tags

 * [Wordpress Hacking](https://wordpress.org/support/topic-tag/wordpress-hacking/)

 * In: [Hacks](https://wordpress.org/support/forum/plugins-and-hacks/hacks/)
 * 1 reply
 * 2 participants
 * Last reply from: [Roy](https://wordpress.org/support/users/gangleri/)
 * Last activity: [14 years, 9 months ago](https://wordpress.org/support/topic/wordpress-sites-hacking-issue/#post-2260117)
 * Status: not resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
