Eight Steps to Eliminating Security Risks in WordPress

Published: Aug 4, 2014
Updated: Feb 2, 2021
2 minute read
Eight Steps to Eliminating Security Risks in WordPress
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る


Eight Steps to Eliminating Security Risks in WordPress

1 - Eight Steps to Eliminating Security Risks in WordPress

by Sean Michael Kerner


Keep Your Server Software Updated

2 - Keep Your Server Software Updated

If you’re self-hosting WordPress on your own server, keep the core server software updated, including the operating system, Web server, PHP and MySQL applications.


Enable Automatic WordPress Updates

3 - Enable Automatic WordPress Updates

All versions of WordPress since the 3.7 update in October 2013 can be enabled to automatically update the WordPress application for important bug and security fixes.


Update All Plug-Ins and Themes

4 - Update All Plug-Ins and Themes

Keeping the server and WordPress itself updated is not enough. It’s critically important to make sure that both plug-ins and themes are always updated. WordPress provides an easy-to-access view that provides full visibility into items that must be updated.


Advertisement

Use Secure Sockets Layer for Log-In

5 - Use Secure Sockets Layer for Log-In

It’s important to configure the WordPress administrator log-in page (/wp-admin) to be accessible via HTTPS/SSL. Otherwise, the administrator password is being sent in the clear and can easily be intercepted by an attacker.


Consider Using Two-Factor Authentication

6 - Consider Using Two-Factor Authentication

For both WordPress.com as well as self-hosted sites, users should employ two-factor authentication, which requires a second password (or factor) to log into the site, providing an additional measure of security.


Use WordPress Plug-In Security Tools

7 - Use WordPress Plug-In Security Tools

Multiple vendors provide WordPress security add-ons to help users lock down their sites. Among them are Wordfence and Sucuri, which can easily be found by searching in the WordPress plug-in listings.


Don’t Be an Attacker

8 - Don't Be an Attacker

Another useful tool from Sucuri is the WordPress distributed denial-of-service (DDoS) checker, which can identify if a given site is being used as part of an attack against others.


Follow WordPress Hardening Guidelines

9 - Follow WordPress Hardening Guidelines

WordPress regularly updates its listing of best practices on how to harden and secure sites.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。