The top 5 misconceptions about WordPress

WordPress has been successfully used as a blog or business website by millions of users. It has been around since 2003 and has evolved from a simple blog platform to a fully-fledged CMS for extensive (business) websites.

The best part is that it has been freely available for years! It is released under the GPL (General Public License) and can be used by individuals and businesses without limitations.

However, there are many misconceptions about WordPress that are not accurate, and WPbeveiligen has listed the top 5 misconceptions:

  1. WordPress is a blogging system and not suitable for business websites. Fortunately, WordPress is highly flexible. Many paid themes offer the option to remove the “blog elements” so that it looks and functions like a professional website.
  2. WordPress is complicated for many, and its features are too extensive. This may be the initial impression when you look at the WordPress admin panel. However, most of the features are not used by bloggers/writers, so the web builder only needs to set it up once and then never worry about it again!
  3. You have to use WordPress from WordPress.com, making you dependent on their service. WordPress is software that you can freely download and install on your own server or hosting package. You are not dependent on anyone and can be sure that your blog or business website will still be online in the future.
  4. WordPress is not suitable for search engines. Out-of-the-box, WordPress is not 100% optimized. You will need to set up the permalinks yourself and add an SEO plugin that places meta tags in the header and allows you to customize them per page.
  5. WordPress is not secure.Similar to the popular operating system Windows, WordPress has a large number of users, and therefore, hackers try to take advantage of it. Out-of-the-box, WordPress is secure, and it receives regular updates to fix any security vulnerabilities that are found.The additional third-party plugins are the ones that may have security issues.For this reason, you need a good security plugin to protect your WordPress website from hackers and brute-force attacks.

That’s the top 5! There are many other misconceptions and tips you can read on WPbeveiligen in our news section.

My articles have been copied!

My articles have been copied!

It is easy to copy texts from websites without anyone noticing. It’s a form of theft that is commonly seen on the internet. It is anonymous and easily done – just cut and paste.

Checking if your texts are stolen

You can use Copyscape to check if your texts have been stolen. In other words, to check for plagiarism. Go to Copyscape’s website and discover if your pages have been copied!

My texts have been stolen, what now?

With Copyscape, you have found the website that is using texts originally from your website. Now you can send an email to the relevant website with an urgent request to immediately remove the copied texts. Specify which text it is since such websites may have copied articles more than once.

If the website in question refuses to remove the texts, you can contact them again and mention that you will take legal action against this online theft.

Does online theft pay off?

Google has a rule that the search engine detects and often does not index Duplicate Content (copied text)!

This means that the first person who publishes the texts online is the owner of those texts and gets the credit from the search engine Google. The second person who uses the texts will not appear well in the Google index or even get a complete WEBSITE BAN, making them no longer discoverable in Google.

Stealing small pieces of text

Even small pieces of text are detected, and even short phrases that are copied can be found in Copyscape. Google is very good at identifying which texts are original and which are simply copied from another site.

Conclusion

If you want your website to rank well on Google, you must write unique texts yourself!

Setting up a good Permalink structure in WordPress

A Permalink structure? This term may not be immediately clear to many.

The Permalink is an enhancement of the link structure so that search engines like Google and others can better index the website. Properly preparing the Permalink Structure is of great importance for visitor numbers!

The Permalink structure of WordPress is not well-configured by default! It looks like this:

How to properly set up the permalink structure

To do this, go to your WordPress admin panel > Settings > Permalinks.

Right after installing a new WordPress website, you will see the permalink structure set to “Default.”

Screenshot_13 Apr. 29 11.51

It’s best to change this to “Post name” or to a “Custom Structure” where you can add a specific addition.

Screenshot_13 Apr. 29 11.48

As you can see on your own website or in the image above, the link in the navigation bar has now changed to a proper title instead of a number. The title improves your visitor numbers via Google, while the numbers that were there previously hold no meaning for the search engine.

A clean title is not only beneficial for search engines like Google but also enhances the overall appearance of your website. And as you can see, it’s a quick and easy change to make!

CMS, CRM, DMS, ERP? What are they!

CMS – Content Management System

1358956833_TextDocument The most well-known is CMS, the Content Management System. This manages content such as text, images, and more. A CMS like WordPress is free to use and makes online publishing of news easy. With a few clicks and a Word-like editor, you can write news that the CMS places on the server and makes visible online.

The benefits of CMS:

1. Easy creation of new content.
2. Structuring the content layout.
3. Updating and populating from any location and PC.

DMS – Document Management System

1358956801_kde-document-open DMS should not be confused with CMS. It stands for Document Management System and is intended for managing documents. It is especially effective for large companies with many employees who want to share information without having to manually pass it on through copies via email or prints.

Advantages of DMS:

1. Easily finding documents.
2. Reading various file formats.
3. Sharing and archiving documents.
4. Linking documents.

CRM – Customer Relation Management

1358956865_users For managing your customers, you have CRM. Customer Relation Management helps you build a relationship with your customers and generate more satisfaction, ultimately aiming to retain customers longer and generate more revenue. Having a clear management system is beneficial both for your customers and yourself, so that you don’t lose track of your customers.

Benefits of CRM:

1. Can generate more customer satisfaction.
2. Can build longer customer relationships.
3. Builds a better reputation resulting in positive publicity.

ERP – Enterprise Resource Planning

1358956888_task_completed For registering company data, you have ERP. It stands for Enterprise Resource Planning.
It involves centralizing company data that is often entered by different departments. For example, the sales department enters customer data, data like quotes and sales orders. The logistics department will enter material data such as quantities and suppliers. To avoid entering all this information multiple times by different departments and make it available everywhere, you need ERP.

Benefits of ERP:

1. Clear overview of project status.
2. Standardization for data input and extraction.
3. Working faster and more efficiently results in more income and fewer expenses.

Making a good website yourself

Creating a Good WordPress Website on Your Own

If you want to create a good WordPress website on your own, it’s essential to keep the following points in mind:

1. Know Your Target Audience: Determine your target audience and tailor your website accordingly. For the business market, opt for a sleek and professional design with concise information. If targeting the average consumer, use an informative layout with eye-catching colors and images. For younger audiences, focus on visuals as they have shorter attention spans.

2. Brand Yourself: Consider how you want your target audience to perceive your brand. A professional image is crucial for businesses, while sympathy and approachability are essential for consumer-focused websites. Building a positive connection with your audience can increase the “gun” factor, encouraging consumers to choose your products or services.

3. Promote Your Website: Creating a website and waiting for visitors is like opening a shop in an obscure alley. You need to ensure people can find your website. Some methods include offering a unique product that generates word-of-mouth, using Google Ads for visibility, optimizing your content for search engines, distributing flyers and business cards, or sponsoring other companies for advertisement exchange.

4. Design and Style: Choose a style based on your target audience. Colors evoke specific emotions and moods. Warm colors create a different atmosphere than cool colors. For instance, commercials on TV often use cool colors when presenting problems and warm colors when showcasing their solutions. Consider the effects of different colors on your audience’s perception and emotions when designing your website and promotional material.

5. Showcase Your Product or Service: Clearly present your product or service on the website and provide sufficient information. Make sure visitors don’t have to search or guess what you offer.

Finally, after successfully creating your WordPress website, take measures to protect it from hackers and scripts that might use your website for their own advertising purposes. Secure your hard work and make sure your website stays safe and functional for your visitors.

The source code betrays your WordPress website

The source code of a website is visible to everyone; in many browsers, you can press F12 or right-click to view the source code of a website.

broncode wordpress

What is the source code?

The source code is the raw version of the website without styling. The source code doesn’t display PHP code but it shows the output of PHP.

The source code displays only the specific page you requested the source code for. However, there are programs that can download the source code of the entire website.

What does the source code reveal about WordPress?

The source code of a standard WordPress installation reveals the version of WordPress.

meta generator wordpress

When hacking a WordPress site, knowing which version you are dealing with is one of the most crucial points.

But there are more pieces of information visible in the source code that can reveal weaknesses in your WordPress website.

Various plugins often leave some advertising behind.

meta generator plugin

Unfortunately, the theme can also be easily found in the source code, allowing hackers to check if that theme contains any exploits.

versie wordpress

What can you do against the open source code?

The source code will always be there, visible to every visitor and, most importantly, visible to Google. Google reads the source code of your website and uses that information to determine if your website is interesting for visitors.

It is essential to have a clear source code where the information of your website is the main player.

There are plugins that enrich the source code with important information such as the page title, the description that Google can display, and links to relevant articles and pages that visitors and Google can explore.

Can WPbeveiligen do something about the source code?

The information revealed in the source code can be altered. By using filters, sensitive information such as the WordPress release and the plugins used can be hidden, making it more challenging for hackers and hackbots to hack your WordPress site.

Cheap is expensive, hacking is free

What an old saying! Is “cheap is expensive” still valid nowadays?

**Is everything free to download on the internet?**

Yes, everything can be downloaded for free on the internet. Think of WordPress and all the information related to it. Setting up a WordPress website is just a matter of investing time and energy.

And yes, even illegal plugins are “free” to download. But in this case, the saying holds true: “cheap is expensive.”

These so-called “free” plugins have been uploaded online by people who want to profit from them. They insert code into the plugin that allows them to receive your login information or gain control over your website.

What happens then? Your website starts displaying ads for a product, or it links to strange websites.

And that’s not all. I regularly encounter websites, which, thanks to hackers, appear in Google search results with descriptions like “Buy your v i a g r a here.”

This is something you definitely don’t want! Promoting a product you have nothing to do with can be troublesome. Especially if your business has built a reputation, you certainly don’t want to be associated with such junk.

Most “free” plugins operate surreptitiously, so they won’t be detected easily. They may stop functioning when you’re logged in or display information only twice to visitors, making it hard for administrators to notice anything suspicious after three visits.

But for every new visitor, it’s an unpleasant experience. With such ads, visitors lose interest in exploring your website.

Ultimately, downloading “free” paid plugins and setting up a WordPress business website can cost you a lot of money, and as you can guess, it becomes expensive in the end.

**What to do if your website is hacked?**

If your website displays content unrelated to your services and information, thoroughly check your website.

If you have an SEO plugin, review the meta description.

However, it’s more likely that there is code injection. In your WordPress admin, go to Appearance > Editor and check the files of your theme.

Popular theme locations where hackers often insert their ads and scripts include header.php, index.php, page.php, single.php, homepage, and front pages. But it could also be injected into the database. Since WordPress stores all content in the database, it becomes an attractive place for hackers to place their code.

**Prevention is better than cure**

Yes, there’s another old saying, but it’s very applicable, especially for business websites. Once a website is hacked, you not only suffer the consequences of the hack but also need to remove all malicious code and backdoors, which takes a lot of time.

Then, the website needs to be secured, which again takes time and money.

**Putting a WordPress website online without security**

Putting a WordPress website online without security is like buying a car without locks. It may be fine for a while, but sooner or later, the wrong person will find your car.

At the beginning, when your website is new, it won’t be easily found by hackers or scripts, and there won’t be a problem. However, after some time, it’s just a matter of time before your website attracts scripts that test it for exploits (vulnerabilities).

**What do you recommend then?**

From experience, I recommend securing every important website. Any website that generates revenue and is critical to your business should be secured to avoid unnecessary costs.

**So, you’re just trying to make money!**

Well, that’s my recommendation, but at the same time, I’m giving away all the information for free on my website! As a programmer, hoster, and web designer since 2007, I’m already quite busy. However, I receive requests weekly to repair hacked websites, and I can see how frustrating it is for website owners.

For me, diving into the code and fixing it is straightforward. I know where to look to clean up the code within 10-15 minutes, or I can restore a backup.

But I realize that many people who haven’t found me on the internet yet may find it very frustrating when their website shows strange ads. It can be a search before they find someone who has been doing this since 2007 and enjoys restoring and securing websites.

That’s why I hope that people will have their websites secured before they get infected.

**Do you offer a guarantee?**

Yes! When I secure your website, I’m so confident in the quality of my work that I offer 6 to 12 months of guarantee. If a script or hacker still manages to get through, I will make sure your website is as good as new. I’ll restore a backup, secure the website, and ensure it runs perfectly. And it’s free, that’s the guarantee!

With my experience in WordPress since 2007, I know how websites function and the hack scripts that circulate online, as well as the tricks that hackers use.

I will secure your website as well as possible, and if your website gets hacked, I’ll find all the backdoors and make sure hackers and scripts can’t access your website anymore.

Een backup maken van je WordPress website

This is the last thing you want to see when you open the website!

How can the website contain malware?

If your WordPress website has outdated plugins or themes, or if WordPress itself is not up-to-date, you run the risk of bots infecting your website. Even with new plugins, it can happen.

How do I get rid of this message?

Your website needs to be completely cleaned. This means removing all malware (hacker’s code) from your website.

Once you are 100% sure that the website is clean, you can request a reevaluation from Google.

How do I prevent it from happening again?

It is essential to not only clean your website but also secure it. There are several ways bots can gain access to your site, and those vulnerabilities need to be closed.

Let WPbeveiligen secure your website!

 

 

3 Ways: How to make a backup of your WordPress website

  1. The easiest method: via DirectAdmin
  2. Manually, via Phpmyadmin and FTP
  3. Via a WordPress plugin

Making a backup via DirectAdmin

DirectAdmin is one of the easiest ways to make a backup within 3 steps, but not every hosting provider offers DirectAdmin with your hosting package.
To check if you have DirectAdmin, add :2222 to your web address. If you have DirectAdmin, a login field will appear. You should have received the login credentials from your hosting provider when you purchased the package.

Step 1 – Login
Login via your web address.nl:2222

directadmin login

Step 2 – Create
Click on create/restore backups

direct-admin

Step 3 – Options
Leave all options checked; it’s always good to save all data. But if you really only want to save the data and the Mysql database, check only the options you see in the image below.

directadmin

Important: Click on Create backupDon’t just click on any button! DO NOT click on restore, as it will overwrite the previous backup.

First, make sure you have enough space to make a backup; otherwise, your data space will fill up, and the website may not function properly.

Manually making a backup

If you don’t have enough space on the server for a full backup, you can use the previous method to backup only the database and manually backup the rest using an FTP program.

With a good FTP program like Filezilla, you can connect to the server and save all files to your computer.

Step 1 – Download an FTP program
Download Filezilla and start the software.

Step 2 – Connect to the server
First, you need to establish a connection to your server, where your website is hosted.

Fill in the Host, usually ftp.YOURDOMAIN.nl, then the username and password.

You received these details by email from your hosting provider when you purchased a hosting package.

Step 3 – Open the correct folder
After you’ve made the connection, you’ll see a standard set of folders, including www, httpdocs, or public_html. These contain the files that are live on your domain name.

Step 4 – Copy files to the computer
Copy the files to a folder on your computer. Give that folder a clear name, like your domain name with a date.

Note: This method does not backup the database. You can use the first method for that.

Using a WordPress plugin

We’ve tested several free plugins, and one of the best ones we found is Updraftplus (Download the free version or the premium).

This plugin allows you to make a backup of all data, including the database.
Download Updraftplus here

Make a complete backup with just one click

The plugin is straightforward to use. After installing it, go to the Updraftplus page and click on “backup now.” You’ll see the progress of the backup. And you’re done!

backup restore wordpress

Restoring a backup

Having a backup is important, but it gets better: Updraftplus also allows you to restore your website from the backup! You can restore your plugins, themes, and more using the plugin.

backup-restore-wordpress

This is useful when your WordPress site gets hacked, or you accidentally delete a plugin, or when a plugin update causes your website to malfunction. It happens quite often!

More advantages of Updraftplus

Updraftplus has many features available in the free version:

  • Restoring only plugins, themes
  • Writing the backup to another server
  • Automating backups based on hours, days, or weeks
  • Translated into Dutch
  • Counting the size of plugins, themes, etc.

Cloud services

If you want to use Dropbox or another cloud service, they even offer premium add-ons to further extend the plugin.

The Expoit Scanner for WordPress

An amazingly simple plugin with one purpose: to search for files that may contain code that doesn’t belong in WordPress.

You can find the plugin in the WordPress plugin library.

After installation and activation, the Exploit Scanner can be found under Tools.

As you can see in the image below, there aren’t many options. You have the option to disable “display: none,” which is common in certain themes.

You can also limit the scan to files that are not larger than 400 KB, and it is recommended to keep it that way. (although very occasionally, hackers may write very large files, in 99% of cases, scanning such large files is not necessary)

The third option you have is to limit the number of files scanned at once. It may be necessary to set this to a maximum of 100-150 if you have a hosting package with limited memory, and the pages freeze with a “memory error.”

Run the scan!!

wordpress exploit scanner

Once you have enabled the scan, it may take a few minutes.

After that, you will get a long list of files that contain Eval commands, a list of “hidden” CSS codes, and more.

Is the Exploit Scanner a one-click solution?

With one click, you can see which code may be potentially dangerous and where the files are located.
However, it is still necessary to have deep knowledge of WordPress, code, and hacker code to determine whether a piece of code belongs in your website or not.

In short, it’s a useful tool for webmasters.

This is how to backup the MySql Database

PhpMyAdmin is one of the most commonly used and well-known tools for managing your database.

PhpMyAdmin is available on 8 out of 10 hosting providers’ servers and can often be accessed via:

www.yourdomain.com/phpmyadmin

(Or they may have a different unique address for security reasons, which you usually receive in the first information email from the hosting provider)

Backing up the MySQL Database

Logging in directly to phpMyAdmin

If you have a link, a login screen will appear. Enter the database Username and password here.

 

After logging in, you will see many options, but fortunately, you only need to make a few choices to create a database backup.

  1. Select the database for which you want to create a backup
  2. Click on the “Export” tab, which is the fourth one from the top

Then click on “Start”!

Tabellen-exporteren-mysql

Your browser will then start downloading the database. It will be saved as an SQL file, which you can import again in the future if needed.

The SQL file can be quite large, and sometimes, importing it later can be difficult due to browser limitations. So, it’s best to compress the SQL into a ZIP file.

Or…

Exporting the backup as a ZIP file

When exporting, click on “Custom” (See example image above) and select “zipped” in the output options.

mysql als zip downloaden

Save your MySQL file in a location where you can easily find it later. It may be automatically saved to your Desktop or Downloads folder, but it’s better to save it in your documents folder with a name that includes the date and website.

Accessing phpMyAdmin through DirectAdmin

If you don’t have a direct link to phpMyAdmin but have DirectAdmin, follow the steps below to access phpMyAdmin.

mysql database inloggen

mysql aanklikken