The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Intermediate & Advanced SEO
    4. Whats the Best way to Protect Wordpress Website from Getting Hacked.

    Whats the Best way to Protect Wordpress Website from Getting Hacked.

    Intermediate & Advanced SEO
    3 3 85
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Verve-Innovation
      Verve-Innovation last edited by

      Hi All,

      I just like to know whats the best way to protect wordpress website for getting hacked. I tried using Wordfence but nothing much happened. I m in shared Host and when ever there is a sign of attack my hosting company takes the site off which affects my site ranking a lot.  I m trying to keep all my plugins updated but still it happens . Like to know what other people do . I am open for Paid tool suggestion as well.

      Thanks

      1 Reply Last reply Reply Quote 0
      • O2C
        O2C last edited by

        A more detailed explanation of how you are getting hacked might help 🙂

        Do you mean you are getting spammy files uploaded to your sites root/editing your current content to include spammy words and links?

        The obvious suggestion is to make sure your Wordpress version is up to date but if you are already updating the plugins I would presume you have done this...?

        It may be that the hackers have just managed to get into your FTP rather than through your wordpress site so I would make sure you have changed your FTP server password and made it secure.

        Are you using any contact forms on your site as this can sometimes be a weakness depending on the plugin used.

        Thanks

        1 Reply Last reply Reply Quote 1
        • gowebsol
          gowebsol last edited by

          Given what you've shared you either have a target on your back or you have some lingering issues from a past infection. I've seen this before and its a pain is the $%& to deal with, but not impossible.

          For preventative measures for anyone with a WP site, I recommend the following:

          • Use Wordfence - paid version if you can (minimal cost). Monitor the notifications, use country blocking that you are comfortable with (I disable China, Ukraine, N Korea, and Russia on most sites since most are local sites in the U.S.), and enable front end scanning
          • Remove admin account and any other "easy" usernames
          • Give all WP users strong passwords
          • Use strong FTP passwords
          • Don't install any plugins you don't need
          • Update everything often! This is the best way to avoid problems.
          • Pay attention to the theme you use and they are NOT all created equal. It's not uncommon for some themes to have known or unknown exploits in them, so be careful of the theme you use. Make sure it has good reviews and excellent support. If not, find a different theme.

          In your case, I'd do the following:

          • Sign up for Sucuri for a year. They will audit your site within 24 hours and will clean any malicious files on the site. Hands down the best service for cleaning WordPress sites. $199.
          • Remove un-needed WP users, change all WP passwords, remove Admin or other easy usernames and transfer posts/pages to another user
          • Remove un-needed FTP users, change all FTP passwords
          • Audit your plugins and get rid of all you don't need
          • Keep your plugins, themes, and WP updated.

          Hope this helps. It's easier than it sounds when your get a system going.

          Joey

          1 Reply Last reply Reply Quote 1
          • 1 / 1
          • First post
            Last post
          • Best way to get love from expired domain
            seoman10
            seoman10
            0
            2
            146

          • Whats the best way to structure my site?
            Alick300
            Alick300
            0
            5
            110

          • What is the best way to get anchor text cloud in line?
            MoosaHemani
            MoosaHemani
            0
            2
            335

          • Penalized because of Pharma Wordpress Hack, Fixed, When can we expect to get out?
            evolvingSEO
            evolvingSEO
            0
            2
            109

          • Whats the best way to remove search indexed pages on magento?
            bjs2010
            bjs2010
            0
            6
            2.2k

          • Best way to get pages indexed fast?
            Michael-Goode
            Michael-Goode
            0
            6
            1.4k

          • Best way to get the keyword ranking at the top
            KeriMorgret
            KeriMorgret
            0
            8
            455

          • What are the best way to get a new subdomain ranked properly
            SimonCullum
            SimonCullum
            1
            4
            573

          Get started with Moz Pro!

          Unlock the power of advanced SEO tools and data-driven insights.

          Start my free trial
          Products
          • Moz Pro
          • Moz Local
          • Moz API
          • Moz Data
          • STAT
          • Product Updates
          Moz Solutions
          • SMB Solutions
          • Agency Solutions
          • Enterprise Solutions
          • Digital Marketers
          Free SEO Tools
          • Domain Authority Checker
          • Link Explorer
          • Keyword Explorer
          • Competitive Research
          • Brand Authority Checker
          • Local Citation Checker
          • MozBar Extension
          • MozCast
          Resources
          • Blog
          • SEO Learning Center
          • Help Hub
          • Beginner's Guide to SEO
          • How-to Guides
          • Moz Academy
          • API Docs
          About Moz
          • About
          • Team
          • Careers
          • Contact
          Why Moz
          • Case Studies
          • Testimonials
          Get Involved
          • Become an Affiliate
          • MozCon
          • Webinars
          • Practical Marketer Series
          • MozPod
          Connect with us

          Contact the Help team

          Join our newsletter
          Moz logo
          © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
          • Accessibility
          • Terms of Use
          • Privacy