Is Namecheap that bad now

You are right... I found unknown admin users under WordPress
I remember deleting them from one of my site but i see they are in all my sites..

List of plugins i have:

Plugins:

Yoast SEO

Gutenberg
Elementor
Contact Form 7
LiteSpeed Cache
One Click Demo Import
W3 Total Cache
Akismet Anti-spam: Spam Protection
Envo Extra
WooCommerce
Loginizer
LiteSpeed Cache

WPForms Lite
PopularFX Website Templates
PageLayer
Site Kit by Google

Easy Table of Contents
Live Chat
which one is nulled.
after delete unknown admin it will automatically add through cron-job also he added some unknown database table in your phpmyadmin. you need to delete it via editing in notepad++

also need to edit very injected php files

if you can not then pm me
sorry for weak english
 
dont use site kit, use a plugin for ads like WPQuads. Having site kit is such a vulnerability since you add your adsense account to the website. So, hackers are probably all over you. Also, use a different URL for login instead of using that default link and also add a security plugin that limits login attempts.
Which plugin is best to change url link and for login security i am using loginizer
 
Which plugin is best to change url link and for login security i am using loginizer

WP Security is the best, it has everything you need to make your websites buletproof. But since you are breached, I would advise that you to find the plugin or change the theme since the theme is probably that the malware entered your website.
 
WP Security is the best, it has everything you need to make your websites buletproof. But since you are breached, I would advise that you to find the plugin or change the theme since the theme is probably that the malware entered your website.
Can you send me the link... I see so many wp security plugins

And all my sites have different theme installed... Do you recommend to change all of them
 
I have many sites hosted on namecheap shared hosting. From last 2-3 months my wordpress sites are getting malware attack and that really impacts my G Ads account. Everytime they run scan and malware attack keeps coming.

Really pissed off with them. Should just move all my sites to another provider or go for any security.

They are blaming my wordpress plugins ( I am only using trusted plugins)

My sites wordpress/php versions are update

Need your inputs

Thanks
From their name, it tells a lot.
 
the basic one would suffice. applying all of the rules that they have in that plugin should help alot. make sure to read about their introduction to those security patches, so you can understand how it benefits you.
for example user enumeration, is a common way to exploit a wordpress site using brute force. and if you dont know about it , you dont protect against it, and you end up being hacked and not know the reason why.
but once you inform yourself and understand the principles behind these holes for wp, you can better manage them

why i dont recommend with that plugin is the 2FA .. i heard it sometimes fails ...
 
Do you recommend to use basic or advance security feature for this plugin

just activate firewall, change the login link, add some question when it comes to login, and you can limit the login attempts to avoid brute force. Overall, these are the most important things. Also, in the firewall settings block the access to XMLPRC. this is one of the common ways hackers to exploit your website.
 
I believe its because of any of your plugins or themes. I have been using namecheap more than 4 years without having any issue. Check your wordpress version and plugins. If you have developer then ask him if he ever used any nulled plugins or themes. Download themes and plugins from trusted source. You can use Premium Vault as well to source your plugin and themes. Or you can purchase directly from the developer as well. But i believe this problem is not related with namecheap.
 
just activate firewall, change the login link, add some question when it comes to login, and you can limit the login attempts to avoid brute force. Overall, these are the most important things. Also, in the firewall settings block the access to XMLPRC. this is one of the common ways hackers to exploit your website.
Added all these features except add questions. Is it Cookie based Brute force prevention?
By the way i have added captcha settings

Do i need to make changes to the database which may have been damaged by malware
 
Added all these features except add questions. Is it Cookie based Brute force prevention?
By the way i have added captcha settings

Do i need to make changes to the database which may have been damaged by malware

I really don't know about that. The more experienced guys who had these issues can tell you more probably. The best according to me would be to clean up the malware and if the site is protected, this shouldn't happen again.
 
Back
Top