Or who, for that matter. If you think your website just sits there and serves pages to friendly visitors, you’re missing out on all the fun that’s going on behind the scenes. Properly securing a website + ongoing maintenance are critical to preventing your site from being “hacked”.
Websites are not a “set it and forget it” sort of thing. Server logs should be inspected on a regular basis. An Intrusion Detection System should be in place. Updates for software should be installed on a regular basis. WordPress must be updated and maintained and if you ignore this maintenance, you’ll have some friends coming to visit you…
And what are these “friends” doing on your website? Just running some friendly Dictionary Attacks, that’s all…
Attempting to log in as ‘admin’…
If you have a WordPress site, unsuccessful login attempts are not blocked, so someone can try to log in to your admin page over and over again without you ever knowing. That is, unless you have the right tools in place. At the very least, make sure you install the Limit Login Attempts plugin.
Security is a multi-layer approach, so don’t think there is just one simple solution to secure your website. Make sure you or someone is maintaining your website, installing the latest updates, pruning as many attack vectors as possible, checking your logs, etc.
If you have any questions, feel free to comment below or Contact Us!
Dean and Cara- So timely! I just got my wordpress site back up and running. Will look into installing
that log-in protection. Thank you for your awesome help!