WP Plugin to Prevent Hackers?

10 replies
  • WEB DESIGN
  • |
just want to know what plugin will you recommend to avoid hackers hacking WP sites? thanks
#hackers #plugin #prevent
  • Profile picture of the author DJL
    I use and recommend Wordfence. It's free at WordPress.org.
    Signature

    None are more hopelessly enslaved than those who falsely believe they are free.
    --Johann Wolfgang von Goethe, Elective Affinities (1809)

    {{ DiscussionBoard.errors[7035238].message }}
  • Profile picture of the author dwoods
    DJL's suggestion is good.

    Here's another that l've heard great things about:
    WordPress - Security Ninja | CodeCanyon
    Good addon for it too: WordPress - Core Scanner add-on for Security Ninja | CodeCanyon

    It's important to note that these are reactive solutions; so if the "hackers" come up with a new attack method these won't protect you until they've been coded into the plugins and are being monitored (just like anti-virus on your computer).

    There are things you can do at the server level that would really help prevent these types of malicious attacks, not just on wordpress but on any script(s) running on your site.
    {{ DiscussionBoard.errors[7035325].message }}
  • {{ DiscussionBoard.errors[7035332].message }}
  • Profile picture of the author rhinocl
    Beware of going to heavy on security. You can drive yourself nuts.A simple lockout plugin, not using admin as a password, keeping your own machine free of viruses and a decent password, keeping Wordpress and plugins up to date and deleting unused plugins should be enough IF you also practice good off site backup. (1 copy on the web and 1 local -database and everything else).
    {{ DiscussionBoard.errors[7036737].message }}
  • Profile picture of the author addlinkweb
    i use "login lockdown" for login security and "better WP security" which provides a bunch of security features in it and it is probably the most secured plugin i found on WP.
    {{ DiscussionBoard.errors[7037191].message }}
  • Profile picture of the author SShip
    I have been using Login Lockdown. Has worked like a charm and have had to ban a couple of ip's as well as countries from my sites.
    {{ DiscussionBoard.errors[7037208].message }}
  • Profile picture of the author blogfreakz
    1+ for lockdown, but it's only tested in version of 2.8.6.. not sure if this plugin work in higher version of wordpress
    {{ DiscussionBoard.errors[7549112].message }}
    • Originally Posted by blogfreakz View Post

      1+ for lockdown, but it's only tested in version of 2.8.6.. not sure if this plugin work in higher version of wordpress
      I've got it on 3.5, as far as I can tell it still works.

      In addition, I have taken a whole range of measures based on products and training about WordPress security.

      Some are very simple and easy to do yourself, others require spending some time with certain plugins and then making changes based on their findings and recommendations.

      I got into this AFTER some sites were hacked.

      Actually, two sites had been hacked originally, both addon domains.

      I made a note to go back to other sites on the same server and e.g. change the user name from "admin" where I had not already done so (i.e. older blogs), but "didn't get around to it".

      Then one day I discovered that the same hackers had defaced almost every domain on that account.

      Even now I'm not 100% certain the sites are secure, but they are definitely a heck of a lot better than they were.

      (Oh, and by the way, fortunately I had done backups just in case - highly recommended.

      Paul
      {{ DiscussionBoard.errors[7550770].message }}
  • Profile picture of the author kreitje
    Ive been using WP Firewall 2. I periodically get emails where they caught someone trying to push an upload on a plugin that doesn't exist.

    It will email you on quite a few hacking attempts.

    If you plan on making changes to your theme via wp-admin temporarily disable the plugin first. It may not like some of the content in the file and will block it. If you disable it first then make changes all will be good. Don't forget to re-enable it though.
    Signature
    HitMyServer.com - Web, Email, Development
    HitMyServer.net - Web/Server Posts
    Do you have premium WordPress Plugins. Checkout my WordPress Plugin Manager for providing updates to your clients.
    {{ DiscussionBoard.errors[7558915].message }}
  • {{ DiscussionBoard.errors[7559387].message }}

Trending Topics