Web & Application Development · Hosting
Top

All articles

Security

Keeping a site from being compromised

Almost every compromised site we see was broken into through something the customer installed, not through the server.

Keep applications, plugins and themes updated. An out-of-date plugin with a public exploit is the single most common way in.

Remove what you are not using. A staging copy of a site you forgot about, still on an old version, is an open door — deactivating a plugin is not the same as removing it.

Use distinct passwords for the control panel, the database and the application admin. Reusing one password across all three turns any single compromise into a total one.

Take backups you have actually tested restoring. A backup nobody has ever restored is a hypothesis, not a backup.

If a site is compromised, we may suspend it — not as a penalty, but because a compromised site usually starts sending spam or serving malware to its own visitors, and at that point it is harming people who did nothing wrong. Open a ticket and we will help you clean it and get it back up.

Still stuck? Open a ticket and a person will pick it up.

Open a ticket