Wordfence is good option?

SEO Link King

Junior Member
Jr. VIP
Joined
Apr 1, 2015
Messages
153
Reaction score
14
Hello,

My almost sites got hacked hacked - hacker is adding new authors, changing wordpress passwords, adding contents, adding redirects, malware scripts scripts and adding sidebar casino links :(

In last few months, I had a bad time for my wordpress sites, earlier got homepage massage from hackers saying "your site got hacked" (hackers are from : USA/russia and indonesia - as per mentioned in message).

I solved it by replacing all old wordpress files with new, updated wordpress files and deleting all plugins and themes, and it got solved at that time.

but from last month Hacker is entering in WordPress or in database and adding few authors, publishing contents, adding sidebar casino links , changing worpdres passwords and more... I deleted those new authors/ contents, sidebar links whenever it came to my notice... and I change wordpress password as well... but in a weeks' time they do same thing again in same domains... :(

I tried to see pattern as I'm owning good amount of unique shared hosting (shared) such as Siteground, hostinger, bluehost, namecheap and more... but hacker gets access to those and change and add things mentioned above in some of the blogs...

Can anyone help me to solve this? how can i solve this? I need help.

Thank you for reading this and your help would be appreciated.

Thank you in advance.
 
did you install any nulled or cracked plugins/ themes?
yes, but changed them as well but still they can enter it and adding bogus themes and plugins having viruses like "zend-fonts-wp" plugin and "seothemes" themes..
 
I've had wordpress sites with zero protection for years and never been hacked. Careful which host you're using, use strong password, use WPS Hide Login plugin, etc..
 
I've had wordpress sites with zero protection for years and never been hacked. Careful which host you're using, use strong password, use WPS Hide Login plugin, etc..
Thank you buddy, will add this plugin for sure : WPS Hide Login plugin. watched video on youtube how it works and its good. :) Thank you.
 
I am not a big fan of using plugins, but WordFence (and the best 2nd choice alternative) - Sucuri, are the best.

Later edit

Talking with someone inside the industry, not involved in any of the 2 plugins above: You'll not guess how many WordPress site owners still use weak usernames and passwords (and wondering after how their sites were hacked). This is a big concern, if we're talking about WordPress security.
 
Did you change the username or do you use default login? You should consider hiding your login.
There are plenty of possibility for hardening. What about 2FA or htaccess? If you cant do it by yourself search for plugins.
 
Are you using CDN? If not then get onboard with any good CDN, like cloudflare.

I see that your sites are getting hacked again and again, so do you think it is the same hacker who knows one loophole that you might have left? May be the nulled plugins that you installed in the past are the culprits?

Since this is happening again and again how about -

1) Exporting all the posts and images using Wordpress Exporter except plugins (I am not suggesting to use any other plugin for this),
2) Formatting the old wordpress install, installing a fresh copy (I know every time your host must be doing it)
3) Install only legit plugins and import the text post back to make the site LIVE again, - this is important
4) Getting CDN and some good security plugin (Wordfense or Sukuri) and see if the hacker is again able to hack your site?

This is what I would have done if this has happened with me.
 
Wordfence is only 1 piece of the puzzle
You would need to figure out to what degree what is the culprit and get rid of that.
 
Back
Top