• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

Lifeform

Web Design | Digital Imagery

  • Home
  • About
  • Gallery
  • Services
  • Work
  • Blog
  • Contact

WordPress Security: Passwords

January 31, 2013

WordPress security

Internet security and privacy frequently makes the news these days with big name sites falling prey to hackers. We store more information online than we ever have before and we’re rightly concerned about the security of that information. If you own a website, you’re a potential target for hackers, but maybe not for the reasons you think.

As I monitor & maintain a growing number of WordPress sites, I have noticed over the years and especially of late, a gradual increase in malicious activity. Taking the steps to secure your WordPress site is a bit like backing up your data or wearing a seat belt – it’s best done before disaster strikes!

WordPress is Popular

WordPress (WP) is hugely popular and considered by many to be the number 1 open source content management system available. WP now powers around 17% of the top 1 million sites on the web and around 60 million ‘blogs’ (half of those on wordpress.com and many with ‘blogs’ as only part of the site).

This is great news as it means a solid future for the WP platform. The other side of the popularity coin is that hackers are becoming more interested in breaking into WP sites.

Why would someone want to hack into my site?

You may think that no one would be interested in your site, after all you’re a small business doing good things in the world, why would anyone want to bother you?

The short answer is money. Most hackers want to place hidden links or malware on your site which either directly or indirectly allow them to advertise (dodgy) products and will try to do so via automated programs. So it’s usually not personal – it’s all about the moolah.

Is WordPress Secure?

The short answer is yes, WP is secure but no site that’s accessible via the internet will ever be 100% secure. The core of the WP program is secure but your server and the way your WP site is installed & configured, your themes, plugins or passwords may not be.

What should I do?

Most attacks on your site are automated ‘brute force’ attacks. They attempt to guess your user name and password. Most try the old default user name ‘admin’, generate passwords and repeatedly attempt to login. Some I have noticed recently sniff out your user name and then work on your password. This is only a problem if your password is weak. There are a range of measures that can be used to secure your site, however at the top of the list is insuring that your passwords are ‘strong’. So here’s a list of recommended practises and things to avoid.

Password Do’s and Don’ts

Don’t use the same password across all your websites or accounts. If one is compromised the others may follow.
Don’t use any combination of your own real name, username, company name, or name of your website.
Don’t use a word from a dictionary, in any language.
Don’t use a short password, a numeric-only or alphabetic-only password

Do make your password at least 8 characters long, preferable 15 – think about using a ‘pass-phrase’.
Do use upper and lower-case alphabet characters as well as numbers and symbols/special characters (e.g. ^ & * # _).
Do change your passwords every month (or at least every 3 months).
Do make sure your personal computer is also secure – especially if you store your passwords on it!

Yes, a ‘strong’ password may be difficult to memorise, but there are good password managers available such as 1password (https://agilebits.com/onepassword) which make the process easier.

If you want to test the strength of different types of passwords, this site is interesting and a bit of fun: http://www.howsecureismypassword.net

Like backing up your data, it’s easy to put off sorting your passwords, but the negative impact of a compromised website (or any of your online or mail accounts) on your business and reputation means it’s something worth doing sooner rather than later.

If you have any queries about website security, are unsure about how to change your password or would like a website security audit, don’t hesitate to get in touch.

More Resource: http://codex.wordpress.org/Hardening_WordPress

This post is based on an article in the Jan 2013 newsletter – more on security in coming newsletters.

Read Part 2 of this series: Easy Secure Passwords.

Filed Under: Security, WordPress

Read More:

  • Design & Creativity
  • Featured Projects
  • Gallery
  • Images
  • Inspiration
  • Marketing & Social Media
  • Mountain Biking
  • News
  • Security
  • SEO
  • Travel
  • Video
  • WordPress

Reader Interactions

Primary Sidebar

What our clients are saying...

Rob’s technical WordPress know-how has got my site up and running, but it’s his knowledge of the web that I’ve found especially useful. His advice on search engines and social media trends has helped me to develop an overall strategy – I know what I need to be doing next. Cheers Bob!

Lee Woodman - Artist & Designer

2016-11-21T10:05:57+12:00

Lee Woodman - Artist & Designer

Lee Woodman
Rob’s technical WordPress know-how has got my site up and running, but it’s his knowledge of the web that I’ve found especially useful. His advice on search engines and social media trends has helped me to develop an overall strategy – I know what I need to be doing next. Cheers Bob!
https://lifeform.co.nz/testimonials/lee-woodman-artist-designer/
I can’t recommend Lifeform Labs enough. Rob has been extremely good to work with. His approach is professional, prompt, and above all helpful. He offered, and delivered, a very affordable product geared to my specific needs. Never once did I feel overawed by all the IT stuff, yet he did encourage me to grapple with some aspects of the web, which has improved my understanding immensely. If you need a web guy Rob at Lifeform Labs is your man.

Deborah Bower - SoulScape

2016-11-21T10:19:43+12:00

Deborah Bower - SoulScape

Soulscape logo
I can’t recommend Lifeform Labs enough. Rob has been extremely good to work with. His approach is professional, prompt, and above all helpful. He offered, and delivered, a very affordable product geared to my specific needs. Never once did I feel overawed by all the IT stuff, yet he did encourage me to grapple with some aspects of the web, which has improved my understanding immensely. If you need a web guy Rob at Lifeform Labs is your man.
https://lifeform.co.nz/testimonials/deborah-bower-soulscape/
Awesome job on the website Rob, your patience, problem solving and technical expertise have been invaluable in producing just what we needed. There is a collective sigh of relief from the Pataka team that we now have a clean, user-friendly site to showcase what we have to offer, or as one of Pataka’s staff put it… 'Super bloody marvellous'!

Stu Forsyth, Senior Graphic Designer - Pataka Art + Museum

2016-11-21T10:21:59+12:00

Stu Forsyth, Senior Graphic Designer - Pataka Art + Museum

Awesome job on the website Rob, your patience, problem solving and technical expertise have been invaluable in producing just what we needed. There is a collective sigh of relief from the Pataka team that we now have a clean, user-friendly site to showcase what we have to offer, or as one of Pataka’s staff put it… 'Super bloody marvellous'!
https://lifeform.co.nz/testimonials/pataka-art-museum/
When I needed a new website one of my prime interests was to have a user friendly simple and straight forward site that was a pleasure to visit. Simple, Honest, and Effective. It was a pleasure to work with Rob, he interpreted well and built exactly what I imagined, plus kept me well informed throughout the process. And it works! I’m really pleased with the whole process, and look forward to working with Rob to develop the site further as the business evolves.

Bob Gilkison Publisher, The Twisting Trail

2016-11-21T10:26:23+12:00

Bob Gilkison Publisher, The Twisting Trail

a horse of course
When I needed a new website one of my prime interests was to have a user friendly simple and straight forward site that was a pleasure to visit. Simple, Honest, and Effective. It was a pleasure to work with Rob, he interpreted well and built exactly what I imagined, plus kept me well informed throughout the process. And it works! I’m really pleased with the whole process, and look forward to working with Rob to develop the site further as the business evolves.
https://lifeform.co.nz/testimonials/the-twisting-trail/
Rob was great to deal with, prompt in his responses to my queries and ever willing to sort out my website problems with me, often at short notice. It was important to me that I retained some degree of control over my website and that I could learn from Rob as we went along. He was very open to this. He charged fairly and I look forward to working with him on an ongoing basis.

Ange Palmer -  Medical Herbalist

2016-11-21T09:44:35+12:00

Ange Palmer -  Medical Herbalist

logo
Rob was great to deal with, prompt in his responses to my queries and ever willing to sort out my website problems with me, often at short notice. It was important to me that I retained some degree of control over my website and that I could learn from Rob as we went along. He was very open to this. He charged fairly and I look forward to working with him on an ongoing basis.
https://lifeform.co.nz/testimonials/ange-palmer/
Rob assisted me build my first ever business website and logo. To say I am a rookie in these sort of things would be generous. I had absolutely no idea apart from the fact that I wanted some nice photos, a certain theme and was quite clear on the logo I wanted.
I can only praise Rob in all his dealings with myself and my colleagues – he was calm, informed, insightful, had great attention to detail and was always there whenever we had any questions. The result is a website and logo that I am 100% happy with created in less than 3 weeks. I cannot recommend Rob more highly.

Susie Vokins -  Susie Vokins Associates

2016-11-21T09:48:57+12:00

Susie Vokins -  Susie Vokins Associates

Susie Vokins
Rob assisted me build my first ever business website and logo. To say I am a rookie in these sort of things would be generous. I had absolutely no idea apart from the fact that I wanted some nice photos, a certain theme and was quite clear on the logo I wanted. I can only praise Rob in all his dealings with myself and my colleagues – he was calm, informed, insightful, had great attention to detail and was always there whenever we had any questions. The result is a website and logo that I am 100% happy with created in less than 3 weeks. I cannot recommend Rob more highly.
https://lifeform.co.nz/testimonials/susie-vokins-associates/
We use Lifeform for all our website work. Rob does a great job administering our websites, keeping them updated and optimised.

Sue F, Nelson

2016-11-21T09:54:01+12:00

Sue F, Nelson

WordPress Logo
We use Lifeform for all our website work. Rob does a great job administering our websites, keeping them updated and optimised.
https://lifeform.co.nz/testimonials/wordpress-website-maintenance/
I needed a clean looking site that I could maintain and style myself – Lifeform Labs did an awesome job!

Jessie Leov - Musician

2016-11-21T09:55:23+12:00

Jessie Leov - Musician

Jessie Leov
I needed a clean looking site that I could maintain and style myself – Lifeform Labs did an awesome job!
https://lifeform.co.nz/testimonials/jessie-leov-musician/

Footer

WEB DESIGN SERVICES

  • Web Design & Development
  • WordPress
  • Business Sites
  • Photography & Video
  • Search Engine Optimisation (SEO)
  • E-commerce
  • Social Media Marketing

  Email us   +64 27 427 5631

PROJECTS

  • Global Career HQ
  • Wild Journeys
  • Nelson Building Inspection
  • Ecofind
  • Grape Escape Café
  • Little Pig Building Company
  • More...

 

We use Siteground web hosting.

LATEST FROM EL BLOGO

  • Taranaki Falls Video
  • Gallipoli: The Scale of Our War – Te Papa
  • Space Tower 1965
  • Taranaki Falls – Tongariro National Park, Middle Earth

ECOFIND - DISCOVER PURE NZ
List your sustainable business »

All images & text Copyright © 2019 Lifeform NZ Ltd  ·  Web Design and Development - Creative Design Studio - Nelson, New Zealand  ·  Disclaimer