Are WordPress websites still safe?

Using WordPress for your website

To be able to manage a website you need a Content Management System (CMS). With a CMS you can adjust and manage your own website. An example of a well-known CMS is WordPress. WordPress is the most widely used CMS worldwide, according to the website ‘BuiltWith’. WordPress is safe, but that does take some effort. So how do you properly secure a WordPress website like that?

Security

There are many advantages to using WordPress. But as with any advantage, there are of course also disadvantages. One of the most important disadvantages is that WordPress is very vulnerable to hackers. The most common reason for this is that necessary updates aren’t installed, meaning the website is no longer up to date and secure. We also, unfortunately, still see too often that strong login credentials aren’t used. Always create a username and password that aren’t easy to guess and for which you combine different letters, characters, symbols and numbers. When you keep regularly changing your password, hackers have little to no chance of hacking your website.

Why do websites get hacked?

Boredom or activism. Yes, really, those are the most common reasons. Young people sometimes as young as 12 are already involved in this. Why? Often because they want to show their surroundings what they’re capable of, and because a large part of websites today is built on WordPress, that’s the first target they go for. Hacking can also be a form of income: hackers are then hired by parties who want to spread malware and spam.

Why does a WordPress website get hacked?

That WordPress websites regularly get hacked mainly has to do with the fact that a large proportion of all websites use this CMS. The security of these websites usually isn’t arranged very well. It’s relatively simple to scan a website and check whether it’s secure or not. This lets a hacker get to work quickly. Hackers will, of course, also check other websites to see whether these can be hacked. But with a WordPress website, the chance is many times greater that it’s not secure, because proper updates aren’t being done or the login credentials are unsafe.

What to do if your website has been hacked?

  • Stay calm
  • Check the following four steps:
  1. Can you still log in?
  2. Is your website being redirected to another website?
  3. Does your website contain illegal links?
  4. Has Google flagged your website as unsafe?
  • Get in touch with your website’s developer and/or hosting provider. Make sure a backup of your website is restored from before it was hacked.
  • Update WordPress and all plugins, change your login credentials, make sure you use a strong password!
  • Check that all user roles are set up correctly.

What can we offer you in terms of security?

  • We update the CMS and the plugins used.
  • You receive strong login credentials from us that aren’t easy to figure out.
  • We regularly make a backup of your website.
  • We provide the website with an SSL certificate.
  • We set the permissions of all folders and files.
  • We limit the number of login attempts.