The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Educational Resources
    4. How can I secure my website?

    How can I secure my website?

    Educational Resources
    4 4 78
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Bigbrand
      Bigbrand last edited by

      Hi, I hope you are doing well.  I wanted to ask you how I secure my website whenever I have SLL but how can I make more secure my website? I hope I will like anyone's reply. thanks in advance

      This is my website: https://www.myqurantutor.com/

      1 Reply Last reply Reply Quote 1
      • NamaSEO1
        NamaSEO1 last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • SolveWebMedia
          SolveWebMedia last edited by

          Hi again,

          I found this article very good and in-depth: https://kinsta.com/blog/wordpress-security/

          We host around 300 WordPress websites and they do get attacked all the time. Any on cheap hosting plans do get hacked. So we have an Optimised WordPress hosting service with a hack protection guarantee.  So, in a nutshell, the host is a huge factor. Plus a decent host will be faster, so that will help SEO.

          I hope this helps?

          1 Reply Last reply Reply Quote 0
          • effectdigital
            effectdigital last edited by

            Well, to prevent information / data leakage you should certainly disable directory browsing

            For example, on your homepage I can right-click your logo image and copy the image URL: https://www.myqurantutor.com/wp-content/uploads/2019/07/MY-QURAN-TUTOR-LOGO-400x56.png

            But I can edit the link to the directory level, for example:

            https://www.myqurantutor.com/wp-content/uploads/

            Now I can see all your uploads, ever:

            • https://d.pr/i/C7DTY4.png (screenshot)

            I can browse all your folders, even some backup files. There's also some info I can use to fingerprint your site build if I want to. To patch this, usually all you have to do its add "Options -Indexes" to your .htaccess file

            I didn't detect a firewall shielding your site, which would make it way easier to DDoS if someone wanted to do that. Some kind of firewall or traffic offloading facility might be useful

            Your site isn't using an HSTS entry ("Strict-Transport-Security") in the header so browsers can attempt to connect via HTTP without being intercepted (though you may handle that via redirects instead, an HSTS policy helps). You don't seem to be using "X-Frame-Options" in your header which helps browsers to know, whether content from your site can be rendered inside of frames (on other domains). If you allow frame embeds, that can lead to clickjacking and stuff (though for some webmasters there's no real way around it as allowing their site's content to be embedded, may be a requirement)

            I can't really find any fields which seem as if they would be vulnerable to SQL injection, but I'm not really an expert at scanning for that kind of thing. I'd assuredly lock down the site from an SQL-I perspective, if you haven't done so already

            1 Reply Last reply Reply Quote 1
            • 1 / 1
            • First post
              Last post
            • How can I index my website on yahoo.com?
              midnights838
              midnights838
              0
              3
              27

            • How can I post content in Moz Blog
              BlueprintMarketing
              BlueprintMarketing
              0
              3
              398

            • Can some expert help us on switching domain name issues?
              LesleyPaone
              LesleyPaone
              0
              3
              204

            • Many competitors are doing spam report as well as spam link building for my website. Could you suggest me that how can I resolve this issue?
              GSM
              GSM
              0
              3
              347

            • How can I detect Google Webmaster tools without asking my client?
              brad.s.knutson
              brad.s.knutson
              0
              6
              14.4k

            • Can anyone recommend any good PHP books for beginners?
              MilosMilcom
              MilosMilcom
              0
              5
              2.6k

            • Does anyone know if there are UK SEOMoz training courses I can attend?
              mfrgolfgti
              mfrgolfgti
              0
              4
              756

            • Website Development Company Needed
              KeriMorgret
              KeriMorgret
              0
              11
              1.5k

            Get started with Moz Pro!

            Unlock the power of advanced SEO tools and data-driven insights.

            Start my free trial
            Products
            • Moz Pro
            • Moz Local
            • Moz API
            • Moz Data
            • STAT
            • Product Updates
            Moz Solutions
            • SMB Solutions
            • Agency Solutions
            • Enterprise Solutions
            • Digital Marketers
            Free SEO Tools
            • Domain Authority Checker
            • Link Explorer
            • Keyword Explorer
            • Competitive Research
            • Brand Authority Checker
            • Local Citation Checker
            • MozBar Extension
            • MozCast
            Resources
            • Blog
            • SEO Learning Center
            • Help Hub
            • Beginner's Guide to SEO
            • How-to Guides
            • Moz Academy
            • API Docs
            About Moz
            • About
            • Team
            • Careers
            • Contact
            Why Moz
            • Case Studies
            • Testimonials
            Get Involved
            • Become an Affiliate
            • MozCon
            • Webinars
            • Practical Marketer Series
            • MozPod
            Connect with us

            Contact the Help team

            Join our newsletter
            Moz logo
            © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
            • Accessibility
            • Terms of Use
            • Privacy