September seemed like a good month to talk about website security, so we’re calling this little series Secure September.
I know, cybersecurity isn’t exactly the subject most business owners wake up excited to discuss. Nobody pours a cup of coffee in the morning and thinks, “You know what would really make today special? A detailed conversation about WordPress vulnerabilities.”
Unfortunately, hackers don’t seem particularly concerned with whether the topic interests us.
WordPress is an incredibly flexible platform, which is one of the reasons we’ve worked with it for so many years. That flexibility comes from an enormous ecosystem of themes, plugins, developers, hosting companies, and third-party tools that can make WordPress do just about anything a business needs.
It also creates a lot of moving parts, and moving parts need maintenance.
Most small-business websites aren’t compromised because an international criminal mastermind has spent six months studying the company. Attacks are often automated. Bots continuously scan websites looking for known vulnerabilities, outdated software, weak credentials, poorly protected forms, and other opportunities.
You don’t have to be important enough for somebody to target you personally.
Your website just has to be easier to compromise than the next one.
That’s what makes website security relevant to every business owner, even if you never intend to learn what PHP stands for.
Here are seven risks worth understanding.
A WordPress website usually has several layers of software working together. There’s WordPress itself, the theme controlling much of the site’s appearance and functionality, and plugins handling everything from contact forms and SEO to galleries, calendars, e-commerce, and dozens of other jobs.
All of that software changes.
Updates sometimes introduce new features or fix annoying bugs. More importantly for this discussion, updates also patch security vulnerabilities discovered after the software was released.
That means an outdated plugin isn’t simply “an old version.” It may be running code with a known security problem.
Once a vulnerability becomes public, attackers don’t need to invent a new way into the website. They can start looking for sites that haven’t installed the fix yet.
This is why WordPress core and plugin updates are part of our ongoing StrottCARE website maintenance. We’d much rather install and manage security updates proactively than receive the considerably less pleasant phone call that begins with, “Something weird is happening with the website.”
There is a little judgment involved here. Clicking every update button the moment it appears isn’t necessarily a maintenance strategy either. Updates can occasionally conflict with themes, plugins, or custom functionality, which is why backups and proper site management matter too.
The goal isn’t merely to update the site.
It’s to keep it updated without breaking everything else in the process.
Considering how sophisticated cybersecurity has become, it’s almost disappointing how often the humble bad password remains useful.
Company names, birthdays, football teams, children’s names, Password123, or one password recycled across twelve different services are all easier to remember.
They’re also easier to compromise.
WordPress administrator accounts deserve particularly strong credentials because those accounts can make substantial changes to the site. Once somebody has administrator access, we’ve moved well beyond an annoying amount of contact-form spam.
A password manager makes it much easier to use long, unique passwords without expecting employees to memorize what looks like the launch code for a missile silo. Multi-factor authentication adds another useful layer by requiring something beyond the password before access is granted.
Yes, that makes logging in take a few seconds longer.
I’ve never heard anyone cleaning malware from a compromised website complain that their old login process was simply too secure.
Contact forms look harmless enough.
Someone enters a name, email address, phone number, and a message. The website sends it somewhere. Everybody moves on with their day.
Except a form is deliberately designed to accept information from outside the website, and that makes it something security has to account for.
The problem can come from an outdated form plugin, poor input validation, automated spam, malicious uploads, or vulnerabilities in whatever software is processing the submission. None of this means a business owner needs to start reviewing form code after lunch.
It does mean forms should be part of ongoing website maintenance rather than something installed once and forgotten.
Spam protection, properly maintained plugins, reasonable upload restrictions, and security monitoring all reduce the opportunity for abuse.
I tend to think of forms as doors.
They’re supposed to let certain things through.
That’s why we generally recommend locks.
People often picture a hacked website as something obvious. The homepage disappears, somebody replaces it with a skull, and the entire office quickly becomes aware that the afternoon schedule has changed.
That certainly happens.
A lot of malware is much less theatrical.
Attackers may insert hidden links, create spam pages, redirect visitors, send unwanted email, steal information, or leave themselves a way to return later. From the front of the site, everything may still look perfectly normal.
Sometimes the first sign comes from a customer who gets redirected somewhere strange. Other times Google or a browser warns visitors away from the site, or the hosting company detects malicious files.
By that point, the compromise may have been sitting there for a while.
This is where proactive monitoring and malware scanning earn their keep. Our security and maintenance services include monitoring designed to catch problems rather than waiting for customers to discover them for us.
I’ve always preferred finding out about a website problem before the client does.
Clients tend to agree with this policy.
If I sat at a WordPress login screen and manually tried a few thousand username and password combinations, I’d probably lose interest fairly quickly.
Software has no such problem.
Brute-force attacks automate login attempts, testing credentials over and over until something works or the system stops them. It doesn’t need lunch, sleep, encouragement, or even a particularly interesting username.
Strong passwords help enormously, but they shouldn’t be the only defense. Login protection, security tools, firewalls, multi-factor authentication, and monitoring can make these attacks much less productive.
This is a good example of how we think about WordPress security generally. There usually isn’t one magical product that makes a site “secure.”
There are layers.
Our maintenance and security services combine ongoing monitoring with software maintenance, advanced security measures, malware scanning, and firewall protection because each one addresses a different part of the problem.
None of them is terribly exciting on its own.
That’s fine.
A fire extinguisher isn’t particularly exciting either, right up until the moment you need one.
Hosting tends to become interesting to a business owner at two specific moments: when the bill arrives and when the website stops working.
The rest of the time, it’s easy to think of hosting as little more than the place where the website lives.
There’s more going on than that.
The hosting environment affects site performance, uptime, backups, SSL, server maintenance, and security. A well-managed hosting setup can provide protections at the server level before an attack ever reaches WordPress itself.
That’s why our managed hosting isn’t separate from the way we think about maintenance and security. We combine hosting with proactive monitoring, routine maintenance, server-level security, SSL support, and dependable backups.
Can a more expensive host guarantee that nobody will ever compromise your website?
Of course not.
Anyone promising that level of certainty should probably be selling something else at the county fair.
But good hosting removes unnecessary weaknesses and gives us better tools when something does go wrong.
There is also something to be said for knowing who to call.
A security incident is a particularly poor time to discover that your hosting company’s idea of customer support consists of a knowledge base and sincere good wishes.
Backups aren’t glamorous, which is probably one reason they’re frequently neglected.
Nobody redesigns a homepage and says, “You know what really makes this thing pop? The automated off-site backup schedule.”
But when something goes wrong, that backup can suddenly become the most valuable part of the website.
A good backup strategy should answer a few basic questions. How frequently is the site backed up? How long are those backups retained? Are the website files and database both included? Where are the backups stored? Most importantly, can the site actually be restored from them?
That last question matters.
A backup you can’t restore is really more of a comforting concept than a backup.
We include website backups as part of StrottCARE and also incorporate dependable backups into our managed hosting because recovery has to be part of the security plan. Prevention is the goal, but pretending prevention will work perfectly forever isn’t much of a strategy.
Things happen.
A plugin update can cause trouble. A server can fail. Somebody can delete something important. Malware can get through despite the protections around it.
When that happens, we want a clean path back.
Preferably one that doesn’t involve reconstructing a website from screenshots and fond memories.
This is where the technical language around cybersecurity sometimes does business owners a disservice.
A hacked website isn’t ultimately a problem because there are malicious files sitting on a server.
It’s a problem because customers may stop trusting the company. Leads may stop coming in. Search visibility can suffer. Advertising campaigns may suddenly have nowhere safe to send people. Staff can lose access, and depending on what the website collects, there may be customer information involved as well.
Then there’s the time.
Somebody has to figure out what happened, clean it up, work with the hosting company, reset passwords, restore files, check Google, talk to whoever manages the advertising, and make sure the attacker hasn’t left another way back into the site.
What began as “a WordPress problem” has a way of involving quite a few people who don’t work in WordPress.
That’s why we view website maintenance, hosting, and security as connected services rather than unrelated line items.
Our StrottCARE maintenance service includes ongoing WordPress updates, backups, advanced security, 24/7 website monitoring, and maintenance support. We also provide dedicated website security services with malware scanning and firewall protection, along with managed hosting that adds server-level security, SSL support, monitoring, and backups.
The idea isn’t to pile technology onto the site simply because we can.
It’s to remove as many obvious opportunities for trouble as reasonably possible, notice problems quickly, and have a plan when something inevitably misbehaves.
Most business owners know who built their website.
Fewer know who is responsible for it today.
That’s the question I’d ask.
Who checks the WordPress updates?
Who manages the plugins?
Who watches for security issues?
Who knows whether the backups actually exist?
Who gets notified if the website goes down at 2:00 in the morning?
Who has a plan if malware is detected?
If there’s a clear answer to all of that, great.
If the answer is a former employee, a developer who disappeared three years ago, or “I think the hosting company handles it,” Secure September might be arriving at a good time.
At Strottner Designs, we manage WordPress websites with the understanding that keeping them secure is an ongoing job. Our maintenance, managed hosting, monitoring, backups, updates, and security services are designed to handle the work most business owners quite reasonably have no desire to spend their week thinking about.
Security will never be a promise that nothing can happen.
What we can do is make the site harder to compromise, easier to monitor, and much easier to recover when something goes wrong.
And ideally, from the business owner’s perspective, make the entire subject wonderfully boring.
If nobody calls you about website security this month, that may be a sign that somebody is doing it right.
A secure WordPress website isn’t something you set up once and forget about. Software changes, vulnerabilities are discovered, attacks keep coming, and backups only help if they’re actually there when you need them.
Our StrottCARE Website Maintenance & Support service is built to handle the things most business owners don’t want to spend their time managing, including WordPress updates, backups, ongoing maintenance, and support. We also provide proactive website security with monitoring, malware scanning, firewall protection, SSL management, and managed hosting designed around reliability and security.
If you’re not completely sure who is responsible for keeping your website secure, that’s probably a conversation worth having before there’s a problem.
[Talk to Us About Website Security]
Interested in a new site and SEO, or just a new site? Visit Home of the Free Website to learn how we can build you a free or affordable site.
Privacy Policy | Sitemap | Terms of Use