What happens on the server?

To keep your WordPress website secure, it’s essential to monitor what’s happening at the file level. Having a clear overview of all activities on the server ensures that hackers have no chance, and you can take action before Google, Adwords, and other sources block your website.

Let’s provide a brief explanation of these terms and how they work:

WordPress at the File Level

WordPress consists of various components on the server to function fully. This includes the administration panel, which resides on the server, as well as the display of your theme, homepage, registration pages, and more. If hackers can manipulate these files, they can accomplish a lot—such as obtaining customer data, login credentials, or redirecting visitors to their own sites.

Overview of Activities

As if that’s not bad enough, they can also add a file to send emails via your website using your address! Having such a file on your server is something you definitely want to avoid. Therefore, knowing the activities taking place on your server is crucial.

How to Monitor Server Activities

If you are a keyboard enthusiast like us, you can use an FTP program to access the server or use the file manager of Directadmin/Cpanel.

However, there’s an easier way!

With this security plugin: Website File Changes Monitor* for WordPress, you can see what’s happening on your server. The plugin is relatively new at the time of writing and is free to use.

scanner for wordpress

*In the past, we recommended iThemes Security, but it has been showing too few changes in the logs in recent months..

WordPress implements forced update

In WordPress 4.7.0, a new API was introduced that turned out to be insecure.
The new REST API, which is enabled by default in all WordPress 4.7.0 releases, can be used to modify posts without having administrator rights.

This is every hacker’s dream! With automated injections, modifying posts could lead to millions of sites displaying unwanted text, advertisements, and links.

Silence is golden

The WordPress developers were informed of the vulnerability by a major security company. From that moment on, the developers worked tirelessly to test and fix the vulnerability.
To prevent hackers from gaining an advantage, they kept knowledge of the vulnerability quiet and implemented a forced update. It was only a week after the update was released to millions of sites that the news became public.

What is a forced update?

This forced update is different from any regular update. Normally, you can choose whether you want to update WordPress automatically or not.
This update to 4.7.2 was forced and applied even to websites with “automatic updates” turned off.

Who disables automatic updates?

You would expect that automatic updating only has advantages. You don’t have to pay attention to updates yourself, and your website never falls behind.

But sometimes, the plugins you use are not up to date, or there are no more updates provided for the plugins.

At that moment, the new WordPress release may conflict with your plugin, causing the plugin to stop working or display errors on your website.
And if you don’t notice it because the update was done automatically…

What does WPbeveiligen do with updates?

For websites with 2-5 plugins, it is relatively safe to allow automatic updates. However, when it comes to websites with 8-20 plugins, we prefer to perform updates manually, especially for plugins. While updating, we check the website to ensure everything is still functioning correctly. If an error occurs, we can immediately identify the cause.

Securing your WordPress website

Securing Your WordPress Website: Is It Really Necessary? Isn’t WordPress Secure Enough?

Hackers are constantly searching for vulnerabilities in WordPress and its plugins. And unfortunately, they have been successful!

These hackers are not just amateur programmers with too much time on their hands.

You’re dealing with full teams, where each programmer uses their knowledge to create a hack.

Secure WordPressPlugins + Themes = A Vulnerable Site

Among the 48,749 plugins available for free download and the 40,000+ paid premium plugins and themes, there are 6144+ WordPress plugins and themes that have reported vulnerabilities known to hackers.

Securing your WordPress website is no longer a luxury with all these vulnerabilities! It has become necessary to protect your WordPress website.

A hacked WordPress website can cause the following issues:

  • Sending spam (unwanted advertisements) using your website address
  • Capturing and redirecting customer information
  • Displaying advertisements (links) within your own content

Securing Your WordPress Website Against Hackers

Hackers are not personally involved in hacking your WordPress website.

Hackers deploy scripts online that continuously search for WordPress websites via Google and test them for vulnerable plugins and outdated WordPress versions.

It’s important to keep WordPress up to date and prevent these (hack) scripts from gathering information about your website. The more a hacker and/or script knows about your website’s data, the easier it is for them to find a vulnerability.

Securing Your WordPress Website Against Vulnerable Plugins

Plugins are developed by web agencies and programmers from all over the world. Many of these programmers are unaware of hackers’ tricks. Even though they create brilliant plugins, those plugins are unfortunately susceptible to automated hacks.

Securing Your WordPress Website Against Injections

WordPress has various methods for updating news, such as through the app or APIs. It’s crucial to prevent these injections!
An injection is a command given to your website through a specific URL, typically through the navigation bar.

Secure WordPressPlugins like iThemes Security PRO NL block long commands, significantly reducing the possibility of injections.

Securing Your WordPress Website with WPbeveiligen

We actively secure WordPress websites seven days a week. We know hackers’ tricks and have the knowledge to defend against them.

Let us secure your WordPress website!

Securing WordPress with a plugin

Is it necessary to secure WordPress with a plugin?

By default, WordPress is relatively secure, and any XSS hacks are neutralized in updates. However, the plugins and themes developed by others have vulnerabilities that allow hackers and automated scripts to gain access to your website.

Securing WordPress starts with hiding and securing your admin area. Through the admin area, a hacker can do whatever they want, such as creating new posts and pages and injecting ads into your content or layout.

But… I have hosting security, right?

The hosting provider’s role is to protect against DDoS attacks and ensure the server functions properly. They implement security measures such as firewalls and brute-force protection, primarily focused on safeguarding the server itself. The server’s security software is NOT designed to protect Content Management Systems.

This is because certain permissions and freedoms are required for a Content Management System to edit, create, and delete files.

Protection against hackers? My website isn’t that popular!

Out of a thousand websites, 999 are discovered by automated scripts through Google and get infected with a virus. So even if your website is for a local fishing club, the automated script doesn’t discriminate and will still inject malware.

Malware? Virus? Hackers? Injection?

These terms can be confusing! Isn’t a virus for computers? Like the Windows viruses in the early 2000s? Explanation: A server hosting your website is a “stripped-down” computer with only an operating system like Linux. Linux has fewer viruses that work due to root protection. However, with WordPress, it’s different.

And isn’t malware something in my browser? Explanation: Malware is short for Malicious Software. It refers to the scripts/software that hackers place, or rather “inject,” on your server.

Injection is a term from medicine, right? Explanation: It involves taking a piece of code and releasing it on the server, which then spreads to various directories and files.

Hackers are intruders who primarily work with electronics. In this case, they spend days experimenting with a known vulnerability and target their virus to exploit that vulnerability.

Can a plugin stop all of that?

Not just “any plugin,” but the enhanced iThemes Security PRO NL can. This plugin has undergone years of development, testing, updates, and improvements in both the United States and the Netherlands to make hackers’ lives more difficult and protect your WordPress website.

How does the plugin work?

Against viruses: The security plugin restricts write and execute permissions on important files, making it more difficult for viruses to spread and modify critical files.

Against malware: Malware has certain characteristics and often executes commands that this security plugin can block.

Against injections: Injections are often attempted through the navigation bar, and this security plugin blocks suspicious injections and long codes that hackers try to inject into your website.

Against hackers: Hiding the LOGIN admin screen and implementing two-factor authentication are some of the most important preventive measures. Additionally, this security plugin hides various features that hackers exploit to gain access to your website, such as user information, database details, WordPress version numbers, and more.

In summary…

It is essential to secure your WordPress website against attacks, viruses, and malware. The iThemes Security PRO NL plugin offers the best protection for WordPress. We have been using this plugin for years and cannot imagine operating without it. Can you?

Uploads folders of WordPress are a weak link

The upload directories of WordPress can be used by any plugin to store files.

Hackers exploit this by placing malware in the upload directories through vulnerable plugins.
With that malware, they can send spam and display advertisements for their own (often illegal) products on the website.

Securing the weak link

Preventing plugins from placing files in the upload directories is not an option since it would hinder their functionality.

However, you can ensure that the malware cannot be executed!

How?

With this security plugin, you can simply click to disallow the execution of files (malware) in the upload directories.


This is one of the many options the security plugin offers to make your WordPress site much safer!

Maintaining WordPress this is how you do it!

WordPress maintenance? Is that necessary?

It’s not a moped, after all.

It doesn’t rust, since when do you need to maintain digital data?

In the article below, we will explain why you need to maintain your WordPress website and guide you through the process of updating your website in 5 steps.

Updating is 80% of the maintenance WordPress websites need.

Maintaining WordPress against cybercrime

WordPress, especially the plugins, are constantly tested by hackers for vulnerabilities. And unfortunately, they succeed 🙁

Hackers have been making a living for years from the income generated through advertisements and products promoted via hacked websites.
maintaining WordPress against hackers
The advertising industry is worth millions, just look at the ads on YouTube, television, newspapers… they are everywhere!

And cybercrime, as they call it, is still on the rise!
Why is that? Because the internet has global reach, from the office to the couch with a smartphone. People of all ages can be reached and are primarily active online.

Note: we are talking about automated hacks here. These are programmed once and then executed thousands of times a day by a computer.

1) Maintaining WordPress: Backup

First, make a backup of your entire website.

You can easily do this with UpdraftPlus, with just a click of a button, you have a backup! The free version is sufficient, and the premium version offers even more features.
making backups for WordPress

2) Maintaining WordPress: Update WordPress

Start by updating WordPress itself.

This can usually be done within WordPress itself, but if it fails due to file permissions or other errors, you can manually replace WordPress on the server using an FTP program like FileZilla.

3) Maintaining WordPress: Update Plugins

Update the plugins and check if your website is still working.
maintaining WordPress plugins
If you want to be extra cautious, update your plugins one by one. This may take longer, but it avoids a lot of trouble if there are issues with a new update of a plugin.

Did you know that we can handle the updates for you monthly?! That saves you a lot of effort. We also update more frequently when vulnerabilities in plugins are discovered.

4) Maintaining WordPress: Update the Theme

Update the theme, but be aware that it may disrupt the appearance of your website.

PRO TIP: Check the release log of the theme first; it often happens that only updates with visual adjustments are released. You don’t have to apply those updates every time.

Update your theme only if there are security updates.

For more information, you can also refer to the article Updating WordPress, the ultimate guide.

5) Maintaining WordPress: Don’t Give Hackers a Chance

Not all plugins and themes are adequately maintained by developers.
This allows hackers to exploit vulnerabilities in plugins and inject unwanted advertisements and other viruses into

your website.

Free plugins are sometimes not updated because the developer is too busy with other work.
Premium plugins are not always updated on time because developers are not always aware of vulnerabilities in their plugins.

What you can do to prevent hacks

Vulnerabilities in plugins and themes are inevitable. It is important to minimize the opportunities for hackers.

This can be achieved with a good security plugin for WordPress.

The security plugin does the following:

  1. Limits file permissions in sensitive folders and files
  2. Filters injections through vulnerable plugins
  3. Sends notifications when your website unexpectedly changes
  4. And more!

A security plugin is not a luxury; it is essential to protect your website against hackers and hack bots.

Maintaining WordPress: The Easy Way

We work with WordPress 7 days a week. We have the expertise, passion, and knowledge to keep hackers out and maintain the security of WordPress websites.

For a small monthly fee, we maintain, update, and secure your WordPress website.

Convenience and security above all!

90% WordPress sites infected undetected

90% of all WordPress websites are infected with malware without you knowing it.

Here are 5 reasons why WordPress sites are infected unnoticed:

  1. Malware is hidden from server security
    That’s the trick of hacking scripts – they place malware on your website that operates stealthily and goes unnoticed by the server’s security measures. One way this works is by externally loading scripts and encoding the code.
  2. Do you know what malware is, or base64 encoding? How cookies are used to display/hide the malware? Chances are you don’t know what server malware, viruses, scripts, base64 encoding, and cookies do. That’s why you can’t tell when your website is infected (unless you, like us, secure and restore websites five days a week).
  3. You don’t expect hackers to target your website
    A hacker won’t personally target your website but has written a script that tests and infects thousands of websites per hour. It’s all automated. Every website found on Google is a potential target, regardless of its size.
  4. The ad is only visible once… to you!
    The aforementioned cookies ensure that ads are shown only once or that visitors are redirected once. So, the second time you visit the website, you think everything is fine. But every new visitor still sees the ads.
  5. You trust your web administrator, your hosting provider
    Bad news: 70% of web administrators cannot completely remove malware, let alone detect it!

Pure scare tactics! Marketing!

No, unfortunately, it’s not just a strong story. The above five reasons are daily realities. There is a significant amount of internet crime because WordPress, plugins, and themes are used globally. Clever hackers who want to make money create malware in Russia or China, which works just as well here and spreads from server to server.

What you can do to prevent and detect malware

Still a bit of advertising

We manage WordPress websites for many businesses that value security. We provide preventive security, maintenance, monitoring, backups, and more! Everything to ensure that your site is free from malware or to prevent future infections.

We can do the same for you!
Sign up your website!

This is normal! They are trying to hack my WordPress!

The surprise remains great when we mention that there are daily attempts to hack a customer’s WordPress website.

My website? Out of all the websites out there?

We will try to explain it as simply as possible without getting into too technical details.
(Most of our blogs go into such detail that even hardcore programmers can’t follow anymore)

They are trying to hack your website!
This is logical because:

  1. Tens of thousands of scripts are active day and night on hackers’ computers and infected websites.
    These scripts have one purpose: to search for WordPress files/websites through Google and then perform a standard number of requests (hack attempts).
  2. If your website is discoverable on Google, then a Hackbot will find it too!
    A computer can perform millions of calculations per minute, so imagine the reach of such a Hackbot.
  3. The scripts are ingeniously crafted by former programmers.
    The scripts executed by the Hackbot are highly sophisticated.
  4. All plugins you use leave traces in the source code of your website, which provides a foothold for a Hackbot.
  5. There is a lot of money to be made by hacking WordPress websites.
    They can inject advertisements on your website.
    They can engage in link building through your website to boost their own website’s ranking on Google.
    They can change your payment details on WooCommerce to their own. (PayPal)
  6. WordPress is Open Source and available for free download, along with thousands of free plugins.
    They can thoroughly examine those plugins and search for vulnerabilities.
  7. Currently, 40% of all WordPress sites do not have an antivirus plugin.
    It’s only with an Antivirus plugin that you can see how many hack attempts are made.
    You can also see how many false attempts are blocked.
  8. Criminal activity is significant, very significant. Especially online, as the perpetrators can remain “anonymous”.

Every website that can be found on Google is simply facing attempts to break in. Files and URLs are being tested.

Think of it like a criminal checking if your backdoor is open.

At the time of writing, we have over 200 articles, many of which cover methods to prevent hackers from gaining access.

Do you want to secure your website?

We ensure that your website does not allow unwanted visitors (hackers and hackbots). They are registered, blocked, and cannot execute their scripts on your website!

We offer a comprehensive service/maintenance package so that you no longer have to worry about your website!

Click here if you want to leave the maintenance and security of your website to WPbeveiligen.

 

Maintain WordPress plugins, theme and security

WordPress is a free Open Source software that needs to be maintained to ensure that hackers don’t have a chance. However, it’s important to note that we’re not referring to hackers who personally target your website, but rather to automated scripts that scour Google for outdated plugins and themes with vulnerabilities.

In this article, we will explain which parts of WordPress need to be maintained and how you can manage maintenance without risking causing more problems than you prevent.

Maintaining WordPress Plugins

Ensure that you use as few plugins as possible and delete any plugins that you don’t use, even if they are deactivated.

Not all plugin updates are immediately necessary.

New updates for plugins are released monthly, weekly, and sometimes even daily. However, not all updates are equally important. Many plugin updates only bring new features or bug fixes that are not directly related to the security of your WordPress website.

Update your plugins regularly, such as every three months unless you read about a specific vulnerability in a plugin you use.

Maintaining WordPress Themes

wordpress theme

First and foremost, you should only keep the active theme on your server. Remove any themes you have previously tried 😉 Hackbots scan the server for themes with vulnerabilities and use them as an entry point to fill your website with malware.

You can remove themes via FTP or by clicking on the theme details of the themeThe Theme Details button appears when you hover over the thumbnail. Then, in the bottom right corner, you will see a “delete” link.

Maintaining WordPress “Core”

Updates for WordPress are released monthly, sometimes even weekly. However, not every update is relevant to security. Wait for a day before updating as there may be bugs or issues in the new releases.

Read on WordPress.org to learn about the type of update, whether it’s a security update or an upgrade with new features.

Maintaining the Server

If you have a Shared package:
This is the entry-level package that costs a few euros per month. You share a server with others, and if their websites get hacked, the speed of your website will also suffer. Additionally, the shared IP address may end up on a blacklist, causing your emails to no longer be delivered.

The advantage is that the hosting provider keeps the software up to date. So you don’t have to maintain it yourself.

If you have a Managed VPS:
With a Managed VPS, you are generally in good hands. The server is updated and provided with important security patches by the hosting provider.

If you have an Unmanaged VPS:
If you have an “unmanaged” VPS, it means that the hosting provider will not perform maintenance on it. You are responsible for maintaining and updating PHP, CentOS, etc. Choose this package only if you have knowledge of Linux or IIS, including shell access.

If you have a budget hosting provider:
Some budget hosting providers are slow with updates, which allows known vulnerabilities on the server to be exploited and viruses to be injected into your website. You want to avoid this as it can be difficult to detect and removing the malware can be a lot of work.

Maintaining Security

The security of your WordPress website is extremely important. Cybercrime is one of the biggest causes of problems with WordPress – it’s a global problem that even affects major banks like ING and Rabobank, but that’s beside the point.

Securing your website starts with one good plugin. We emphasize one plugin because we often see multiple plugins being used simultaneously, which only leads to problems.

Once the security plugin is properly configured, it’s best to update it as soon as new updates are available.

It’s also important to regularly check the logs to ensure everything is functioning correctly. Don’t be alarmed by the attacks you see in the logs; they are a standard occurrence for any WordPress website that can be found on Google.

A well-maintained security plugin should block 99% of all attacks.

Final Thoughts

backupEven if you have everything well-maintained, something can always happen, so make backups!

Can your fast website get slow without security?

Can your fast website become slow without security?

YES!

By default, various files of your WordPress website can be accessed, which are scanned by countless hack bots and viruses.
(Xmlrpc & rest-api & server directories & readme.html & license.txt & wp-admin directory & wp-login.php… and many more…)

These hack bots visit your website and rapidly request different files, thereby slowing down your website.
They are unwanted “visitors” who also visit 10-50 pages within seconds.
Unusual and burdensome usage of your server and data!

Are we talking about 1-2 bots per day?
No, there are 50-500 bots coming in daily.

The good security measures we implement block unwanted requests after 5-10 attempts.
IP addresses are also permanently blocked in the .htaccess file.
And we ensure that the hack bots don’t find the information they’re searching for.

Complicated? Not for us!

And not for you either. Fill out the form on this page and your WordPress website will be properly secured, updated, and monitored!
Within 24 to 48 hours. Don’t wait any longer!