Massive attack against 1.6 million WordPress sites underway

This is why it's better to use a proper CMS. October CMS, Winter CMS are a couple of excellent Laravel based solutions - free caching plugins that won't get your site destroyed too :)
I would say that they probably aren't less likely to be secure, just less likely to be targeted due to the smaller market share.
 
Had some issues with malware for the last 7-10 days with few of our google news approved blogs. We were scratching our head why this keep happening suddenly? Now we know the culprit is...automatic plugin.
 
Users should finally replace WordPress with less risky yet more productive framework like .. laravel. If you don't have the skills then pay dev to build your website. Pay once is less costly that recovering from funny attacks. Good luck hacking laravel .
 
For anyone who didn't know, wordpress updates security patches automatically now.
I took a Wordpress survey, and it said something like "did you know that Wordpress updates security patches...?"

These hackers are still a bloodthirsty bunch! :D
I don't think you have a good website until you have wordfence attempted hacks from all around the world. Then finally you are a global brand!
 
an checklist which I advice EVERYONE to implement before even installing 1 freaking theme....this is my actionplan lets say everytime...

- register domain
- password protected on the spot (through the server)
- install Wordpress clean on an subdomain or folder
- install wordfence
-install an plugin to hide your wordpress
- install wp static also
- keep your original path of Wordpress obviously hidden (either through server commandline or password protected)
- seal all paths and rights which are not really needed all the time
- captcha solving to avoid the bruteforce stuff also handy
- in wordfence you can also assign or block Ip's who can access anything.
- customize however you want ......then convert it to static HTML to the domain path.... so your Wordpress is installed on wp.domain.com ..... but the static is published to domain.com.

at end of the day... if someone wants to get in... they will get in....the whole point is to make it as difficult possible so they give up and move on to easier targets......... security is an 24/7 and the foundation of any website you start...... this lesson I learned back like 20 years ago when my freshly installed windows got an virus the moment I put my ethernet in it and went online...... and another time moment I installed the Wordpress and then went shopping for plugins etc..... so ... if you like your work and website...... start with security first before even shopping around for themes and plugins.... and also very obvious.... download from source....
 
Thanks for the warning. Checked my sites they are OK so far. But I don't use those plugins / themes and I also regularly update plugins and themes
 
Back
Top