Automattic Improves WordPress Security With BruteProtect Acquisition

Published: Aug 27, 2014
Updated: Feb 2, 2021
2 minute read
Automattic Improves WordPress Security With BruteProtect Acquisition
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

The open-source WordPress blogging and content management system software is widely deployed and is also often attacked. In a bid to improve security, Automattic, the lead commercial sponsor behind WordPress, announced on Aug. 26 that it has acquired security vendor BruteProtect. Financial terms of the deal have not been publicly disclosed.

BruteProtect provides multiple security capabilities for WordPress sites. Prior to being acquired by Automattic, BruteProtect offered a free and a paid Pro version of its service. The free version provides WordPress sites with protection against brute force attacks. Brute force attacks can take many forms but typically involve an attacker automatically trying out multiple username/password combinations in order to gain access to a site.

Brute force attacks against WordPress sites are not theoretical; they are in fact a danger that impacts sites on a regular basis. In July, eWEEK reported on one such large-scale brute force attack against WordPress attempting to gain access via the wp.getUsersBlogs function, which is intended to provide an administrator with a list of blogs. According to BruteProtect, the free version of its software has protected users from 141 million attacks since April 2013.

In addition to the free version, BruteProtect has a Pro version, which was offered at a subscription rate of $5 a month. The paid service is now being offered for free by Automattic to all WordPress users via its Jetpack plug-in. Jetpack is an optional plug-in for WordPress sites that provides services from Automattic. The BruteProtect Pro capabilities include uptime monitoring of WordPress sites as well as update alerts for WordPress plug-ins and themes.

“The BruteProtect team is based in Portland, Maine, and they’re long-time contributors to the WordPress community,” WordPress founder Matt Mullenweg wrote. “We’re excited to see them join forces with the Jetpack team and up the level of security, protection, and peace of mind we’ll be able to bring to the millions of sites already using Jetpack.”

WordPress plug-ins have been an area of focus for attacks in 2014. In June, an exploit in the Timthumb image manipulation library left unpatched sites at risk. In July, an attack against outdated MailPoet WordPress plug-in users was reported leaving sites at risk.

WordPress has taken a number of steps to improve site security over the last year. With the WordPress 3.7 release in October 2013, a new core feature that enables automatic updates for security fixes was included. That automatic update feature enabled WordPress to roll out its recent 3.9.2 release rapidly to fix a critical denial-of-service (DoS) vulnerability.

Advertisement

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。