Connect with us

Tech

10 WordPress security best practices you need to implement — right now 

Published

on

Get up to 30%* off! Get going with GoDaddy!

Lock it down

WordPress is a powerful web application and is used by up to 43% of the internet, to date. But with great popularity comes great threats. With numbers like these, many would-be attackers are constantly on the lookout for weaknesses in your site — a good reason to implement these WordPress security best practices, right now.

WordPress security best practices

Sans the usual best practices — like keeping your core files, theme(s) and plugins up to date — there are also many other factors to take into consideration. File and directory permissions, and more are necessary to keep safe that which you’ve worked hard on and treasure.

1. Update file permissions

The default file permissions for all files on a WordPress site are typically set to 644. The default directory permissions are set at 755. There are scenarios that warrant differences.

For instance, it is a good idea to have your wp-config.php file set to permissions stronger than 644.

I know of folks who set that file’s permissions to 440. This helps make it harder for the riff raff to access the file. Some people set theirs to 600. That’s fine too.

You can change the file and directory’s permissions via File Manager, in your hosting plan. You can also alter these permissions in your favorite FTP program.

2. Disable the xmlrpc.php File

What is this file? Well, simply put, the XMLRPC is a system that allows for remote updates to WordPress from other applications. To make sure your site stays secure, it’s a good idea to disable xmlrpc.php completely.

However, if you need some of the functions necessary for remote publishing and the Jetpack plugin (for instance), you should use a workaround plugin that allows for these features while still fixing all the security gaps.

One plugin that comes to mind is called Disable XML-RPC. This plugin uses the built-in WordPress filter xmlrpc_enabled to simply disable the XML-RPC API on a WordPress site. This renders it unobtainable by someone looking to compromise your site.

Another plugin that comes to mind is the Disable XML-RPC Pingback plugin, which lets you disable just the pingback functionality. This means that you will still have access to other features of XML-RPC if you need happen to need them — for instance, if you’re running Jetpack. There are other plugins that will also disable this file. See below for more details on that plugin.

Both plugins are easy to use. You just have to install and activate them. They do the rest for you.

In the event that you want to have more control over how the XMLRPC plugin works, you can instead install the REST XML-RPC Data Checker plugin. Once installed and activated, you would just need to go to Settings > REST XML-RPC Data Checker, and then click the XML-RPC tab.

Once there, you will be able to navigate through the interface to better control the xmlrpc.php file and what it does.

If you already have a ton of plugins and want to avoid installing yet another, you can control the xmlrpc.php file via the .htaccess file by adding this line to it:

add_filter( ‘xmlrpc_enabled’, ‘__return_false’ );

That will just turn it off altogether.

You can also edit the .htaccess file with this command:

<Files xmlrpc.php>

Order Allow, Deny

Deny from all

</Files>

Or have your hosting provider disable the file itself.

3. Hide your sensitive details

Once you’ve got your site all dialed in and live, hide certain details from the public eye that might lure someone towards wanting to compromise all your arduous work. A nice plugin for this is called Hide My WP Ghost. This plugin is a paid plugin, but it’s worth the coin, and it’s on sale now for a 5-pack license.

This plugin does a fantastic job of hiding your core files, file paths, login page, and more. It performs the following functions, to name just a few:

  • Change the wp-admin and wp-login URLs
  • Change lost password URL
  • Hide /wp-login path
  • Disable XML-RPC access
  • Change URLs using URL Mapping
  • Weekly security checks and reports
  • Email support, and more

4. WAF/CDN protection

A big step towards protection is blocking people you don’t want to have access to your site, altogether. This can be accomplished via a WAF (web application firewall) combined with a CDN (content delivery network).

Fortunately, GoDaddy offers this type of protection through Sucuri. Once purchased and set up, you can go into the firewall settings and enable GeoBlocking, if you so desire, and block entire countries from accessing your site.

The WAF will also help to speed up your site, since it does a wonderful job of blocking the known bad IPs and allowing the good ones to access your site.

5. Combat comment Spam

Another nuisance is comment form spam. There is a great way to limit or prevent this type of problem. The method I like is to utilize the plugin called wpDiscuz.

With this plugin, wpDiscuz will take over your site’s commenting and check against a host of bad actors, filtering out bad or malicious comments by forcing the commenter to enter credentials to comment. You get an email sent to you with each successful comment on your site, so you can then moderate further, if needed.

6. Enable CAPTCHA

It is highly recommended that you also enable CAPTCHA on all forms on your site(s). This will aid in the prevention of form spam. There are several types of CAPTCHA additions out there. Some ask the user to solve a math equation, some have a puzzle to solve, others have you select a series of pictures, and there are more variations.

7. Enable 2-factor authentication (2FA)

A tried-and-true way of keeping out the knuckleheads out there who would seek to do your site harm is to enable 2-factor authentication on every user of your site. If you are on your site all the time, it can be a mild inconvenience to have to enter the 2FA each time you log in. But that is a small price to pay for the security of your site.

A good plugin that can be used to enable 2FA is Wordfence. Just install the plugin and go to this article to see how to enable it.

8. Change the WP-admin URL

The default admin URL has been the same, on WordPress, for years. All bad actors know it and routinely attempt to gain access to your site via said URL. The above mentioned Hide My WP Ghost plugin does a great job of obscuring this URL by simply changing it.

9. Add server-level protection

If your WordPress site is hosted on a server, you can enable other security features that will help keep your site safe. One such feature is in WHM. You can help prevent or limit the possibility of an AnonymousFox compromise by simply turning off Reset Password for cPanel Accounts and Reset Password for Subaccounts.

Simply go to WHM > Tweak Settings > search for password. From there, for the Reset Password for cPanel Accounts and Reset Password for Subaccounts features, select Off. This will help in preventing a bad actor from accessing — and then changing — the cPanel and subaccounts passwords.

The second thing you’ll want to do, if your site is hosted on a server, is to disable shell access to all your cPanel accounts. Just go to WHM > Manage Shell Access > Disable Shell for all cPanel accounts.

10. Strong login credentials

Last among our WordPress security best practices, but certainly not least, always use strong passwords and obscure usernames. I can’t tell you how many times I’ve come across passwords like Password123!. Another common mistake is making the username something relative to the site itself.

If you want to get compromised, that is a sure-fire way to do it.

Long and randomly generated passwords, in conjunction with usernames that have nothing to do with the site, are always your best combo.

Another great idea is to continually change your passwords. It might seem like a pain, but that pales in comparison to getting hacked. How often you change your passwords is up to your discretion. — just as long as you do. (You’ll be glad you did.)

Closing thoughts on WordPress security best practices

All in all, you have worked so hard for your intellectual property (or your client’s). Why not keep it safe? These few, but helpful, WordPress security best practices can go a long way toward a successful and compromise-free website for years to come.



Get Hosting for $1.00*/mo with GoDaddy!

This post was originally published on this site

Continue Reading

AI

Revolutionizing Marketing: The Power of AI in the Digital Age

Published

on

Embracing AI-Powered Marketing: Transforming Brands in the Digital Marketplace

In the crowded digital marketplace, standing out is challenging. Enter AI-powered marketing, a revolutionary upgrade transforming brands into digital powerhouses.

Hyper-Personalized Campaigns: Beyond Basic Personalization

Gone are the days of generic marketing. Today’s gold standard is AI-driven hyper-personalization. This approach uses customer data analysis to create deeply resonant, individualized marketing campaigns. With AI’s ability to segment audiences based on intricate criteria, including purchasing history and browsing behavior, your messages can hit the mark every time.

Enhanced Customer Journey Mapping

AI’s capabilities extend to mapping the entire customer journey. By predicting needs and preferences at each stage, AI aids in crafting narratives that guide customers from discovery to purchase, integrating your brand into their personal stories.

SEO Wizardry: Mastering Search Engine Dynamics

With ever-changing algorithms, SEO is a complex puzzle. AI serves as a sophisticated navigator, deciphering these changes through machine learning. It aids in keyword optimization, understanding search intent, and aligning content with search trends.

Predictive SEO

AI tools offer predictive SEO, anticipating search engine and user behavior changes. This proactive stance ensures your brand’s prominent visibility in search results, capturing the right audience at the right time.

Social Media Mastery: Crafting a Digital Narrative

AI transforms social media strategies from uncertain to precise. By analyzing vast social data, AI provides insights into resonating content.

Content Optimization

AI analyzes performance data to recommend effective content types. This data-driven approach refines your social media content strategy.

Engagement Analysis

AI examines user interaction nuances, understanding engagement patterns. It helps tailor interactions for maximum impact, including adjusting posting schedules and messaging for increased relevance.

Conclusion: Navigating the AI-Driven Marketing Landscape

AI-powered marketing is essential for thriving in the digital age, offering precision and personalization beyond traditional methods. For small businesses, it’s a chance to leverage AI for impactful, data-driven strategies.

As we embrace the AI revolution, the future of marketing is not just bright but intelligently radiant. With AI as your digital ally, your brand is equipped for a successful journey, making every marketing effort and customer interaction count.

Continue Reading

AI

AI: Your Small Business Ally in a Digital Age

Published

on

In the ever-evolving landscape of modern commerce, small business owners find themselves at a crossroads of opportunity and obsolescence. Enter Artificial Intelligence (AI) – once the exclusive domain of tech behemoths, it now stands as the great equalizer, offering small businesses a competitive edge previously unthinkable. The emergence of AI as a wingman for small businesses is not just a fleeting trend but a fundamental shift in how entrepreneurs can leverage technology to revolutionize their operations.

The 24/7 Customer Service Hero: Chatbots

In the digital storefront, customer service is the heartbeat of business survival and success. Chatbots emerge as the indefatigable heroes of this domain. Envision a customer service agent that never clocks out an entity that requires no sleep or sustenance yet delivers consistently and instantaneously. These AI-driven chat interfaces embody the essence of your brand’s voice, capable of handling a barrage of customer queries with a speed that outpaces the swiftest of typists. They are the embodiment of efficiency – ensuring that customer satisfaction is not just met but exceeded around the clock.

Unearthing Market Treasures: Data Dive

AI’s prowess in pattern recognition has catapulted data analytics into a realm once considered the stuff of science fiction. Small business owners armed with AI tools can sift through vast swathes of data to extract actionable insights. These algorithms act as modern-day oracles, predicting market trends, discerning customer behaviors, and offering sales forecasts with remarkable accuracy. Equipped with: this knowledge, small businesses, can navigate the market with the foresight and precision of an experienced captain steering through foggy seas.

Personalization at Scale: Customize Like a Boss

The age-old business mantra of the customer is king is given new potency with AI’s personalization capabilities. Tailoring the customer experience is no longer a luxury but a necessity. AI enables small businesses to offer bespoke experiences to consumers, making them feel like the sole focus of their attention. It’s personalization executed with such finesse that customers are left marveling at the thoughtfulness and individual attention, fostering loyalty and establishing deep-rooted brand connections.

Offloading the Mundane: Task Slayers

Repetitive tasks are the bane of creativity and innovation. AI steps in as the ultimate task slayer, automating routine chores that once consumed disproportionate amounts of time. From scheduling appointments to managing inventory, AI liberates entrepreneurs from the drudgery of administrative duties, freeing them to refocus on the creative and strategic endeavors that propel business growth.

Mastering Social Media: Social Savants

Social media – the pulsing vein of modern marketing – demands astuteness and agility. AI emerges as the savant of social media, capable of demystifying platform algorithms to optimize content delivery. It knows the optimal times to post, the types of content that resonate with audiences, and the strategies that convert passive scrollers into engaged customers. By automating your social media presence, AI transforms your brand into an online sensation, cultivating a digital community of brand ambassadors.

The Verdict: Embracing AI

For a small business owner, AI is not about an overnight overhaul but strategic integration. The goal is to start small, allowing AI to shoulder incremental aspects of your business, learning and scaling as you witness tangible benefits. The transition to AI-enablement does not necessitate a background in technology; it requires a willingness to embrace change and a vision for the future.

In summary, as the digital revolution marches forward, AI stands ready to partner with small businesses, providing them with tools once deemed the province of giants. This partnership promises to elevate the small business landscape, ushering in an era of democratized technology where every entrepreneur can harness the power of AI to write their own David vs. Goliath success story. AI, the once-distant dream, is now the most loyal wingman a small business can enlist in its quest for growth and innovation.

Continue Reading

Tech

Apple’s October Scary Fast Event: Everything revealed about the new MacBook Pro, iMac and M3 chips

Published

on

It’s time for another Apple event, with a spooky twist. The company announced a surprise “Scary Fast” event last week, prompting the rumor mill to speculate that Apple would be revealing new chips to power a new lineup of Macs.

As our resident Apple expert Brian Heater wrote, a new 24-inch iMac and a MacBook Pro refresh would be the most likely new announcements to expect from the October event, and as it turns out, he was spot-on. Apple’s new M3 chip lineup was the focal point of the event, powering each of the devices Apple showcased in their half-hour prerecorded event that had some fog, some bats and ominous choir music…but no big surprises for those following the rumor mill.

Since the event kicked off off at the uncharacteristically late time of 8pm ET / 5pm PT, so you might have missed out out on the reveals while putting the finishing touches on your Halloween decorating, or watching Monday Night Football. No judgement, we’re here to recap everything the October Apple event showcased in one spot.

New M3 chips

Credit: Apple

The “scary fast” part of the Apple event, as expected, are the new M3 chips. Apple has announce a M3, M3 Pro and M3 Max, which will be included in Apple’s new 24-inch iMac, MacBook Pros.

This time around, Apple has placed an emphasis on graphical horsepower, with hardware-accelerated ray tracing, mesh shading and Dynamic Caching, which Apple claims “dramatically increases the average utilization of the GPU” by allotting exact amount of local memory to given tasks. These new chips were frequently benchmarked against their M1 predecessor, with Apple claiming the M3 renders at 2.5x the speed of the M1 and its CPU is 30% faster than the M1.

Check out the full rundown of the three M3 chips right here.

New MacBook Pro models

Apple MacBook Pro 2023 Update in Space Black Color

Credit: Apple

Yes, the new 14-inch and 16-inch MacBook Pros come with upgraded internals, but the first thing you might notice is the new color: Space Black. Beneath that color, you’ll find that new line of M3 chips. The 14-inch MacBook Pro can contain any of the trio, while the 16-inch model will only come with the M3 Pro or M3 Max chips.

As we’ve noted, the M3 chips packed into both models are putting an emphasis on getting the most out of the new GPU, though Apple also boasts that both form factors’ battery can last 22 hours on a single charge.

Both are available for preorder tonight, with the 14-inch MacBook Pro starting at $1,599 and going to $1,999 with the M3 Pro. The baseline 16-inch MacBook Pro goes for $2,499 and the pricing for the M3 Max chip upgrade for both models has yet to be disclosed.

And that space black color is exciting news for any Mac fan still pining for the 2006 MacBook, whose dark tone hadn’t been replicated in the MacBook iterations that followed, even those Midnight MacBook Airs.

Check out the full rundown on the new MacBook Pros here.

New M3 iMac

2023 M3 iMac Spec Rundown

Credit: Apple

Apple’s iMac line is getting a colorful refresh, with an added M3 chip to add horsepower to the palette change. Apple is sticking with the 24-inch form factor, and upgrading the screen with a 4.5K retina display, 1080p FaceTime camera and a six-speaker system supporting Dolby Atmos and Spatial Audio. The new iMac will be available for preorder with green, yellow, orange, pink, purple, blue and silver options starting tonight.

The $1,299 baseline comes with a 8-core GPU and 8-core CPU, with a $1,499 version upgrading you to a 256 SSD.

For more info about what else is new in the M3 iMac, head here.

An sneaky iPhone showcase

You may not have noticed it, but at the very end of the event, Apple dropped a quick note on the stream: “This event was shot on iPhone and edited on Mac.” It’s a bit of a victory lap, but as our other Apple expert Darrell Etherington notes, it’s a pretty impressive flex for Apple to shoot its half-hour hardware showcase entirely on a phone.

Recap the full Scary Fast event

If you want to just dive right in and experience the October event all over again or for the first time, you can catch the entire archive via the YouTube embed below right on Apple’s website.

This post was originally published on this site

Continue Reading

Trending

SmallBiz.com does not provide legal or accounting advice and is not associated with any government agency. Copyright © 2023 UA Services Corp - All Rights Reserved.