{"id":21333,"date":"2017-01-25T16:40:29","date_gmt":"2017-01-25T21:40:29","guid":{"rendered":"http:\/\/neighborly-eyes.flywheelsites.com\/?p=21333"},"modified":"2019-02-13T14:32:52","modified_gmt":"2019-02-13T19:32:52","slug":"worpress-site-need-security-plugins","status":"publish","type":"post","link":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/","title":{"rendered":"Does your worpress site need security plugins"},"content":{"rendered":"
\n

This is reprinted post from Wordfence, a vendor that we use on all of our sites. \u00a0Search Traffic Now requires security plugins because of the nature of wordpress, being open source, and the fact that both humans and bots are trying to hack wordpress site approximately every 5 minutes. \u00a0Moreover, when we host and manage your site, we do not stop with security plugins, our servers all have special software designed to restrict malicious traffic, software to prevent server and website side intrusion and we also use 3rd party platforms like Cloudflare that offer another layer of security between the server, browser, and website. \u00a0This is an interesting article – please enjoy.<\/p>\n

Do You Need a WordPress Security Plugin?<\/h1>\n

This entry was posted in General Security, Wordfence, WordPress Security on January 25, 2017 by Mark Maunder.<\/p>\n<\/div>\n

<\/p>\n

At Wordfence we are a big team these days with millions of customers, and we think about security all day long. Sometimes we can get deep down the proverbial rabbit hole and forget about the basics. \u00a0I recently overheard someone asking \u201cDo I really need a WordPress security plugin?\u201d and I realized this is a perfectly valid question. If you are not in the security industry, you might ask it. \u00a0I know that many of you are well versed in security already \u2013 and WordPress security in particular. What I would like to provide you within this post is a way to answer\u00a0the question of \u201cDo I need a WordPress security plugin?\u201d to friends, family and colleagues that is both enlightening and easy to understand. \u00a0If you are new to WordPress, I hope this post helps increase your understanding of WordPress security.<\/p>\n

Physical Security compared to\u00a0WordPress Security<\/h1>\n

\"\"Many people think about WordPress\u00a0security in the same way that they think about physical security in the real world. In the physical world, we might build\u00a0a facility like a bank that needs to be secured. We build barriers to entry and access controls as part of the construction project. Once the project is complete, we have a secure facility with walls, gates, secure entry and exit, cameras, access controls and human personnel to implement security procedures as people enter and exit. The physical construction does not change much over time, once the project is completed. You are unlikely to discover that the concrete you used to build a wall for\u00a0your bank is now vulnerable and needs to be replaced. A wall is still difficult to penetrate and a locked gate with a guard is going to still be quite effective a few months\u00a0from now.<\/p>\n

It is easy to make the mistake of thinking about WordPress\u00a0security in the same way. If you install software that is secure to power your WordPress website and you implement good security policy and controls, one might think a website would behave in the same way. In other words, one might think a secure website today should be secure a few months\u00a0from now if it doesn\u2019t change. \u00a0That is not the case and I\u2019m going to explain why. If you build\u00a0a website using the newest software that has been verified to be secure and you implement good security policy, your website does not change, but the environment it is operating in changes. Attackers continually research the software that powers your website and vulnerabilities are eventually discovered in most popular online software.<\/p>\n

Therefore\u00a0the problem is that, while your website software starts off secure, it almost always ends up being insecure without anything changing on your website. It\u2019s not your fault or the fault of the person who created your website. It is just the way of the online world. This differs from our building metaphor above in that a secure building doesn\u2019t usually end up insecure a couple of months after being built without anything in the building changing. But a website does. \u00a0In fact, this is an ongoing cycle. Vulnerabilities are discovered, attackers start using them and ultimately if you are a responsible WordPress site owner, you upgrade your site regularly to fix those vulnerabilities. Then new vulnerabilities are discovered in new versions and the cycle repeats.<\/p>\n

The Time Gap Between Vulnerability Knowledge and Installation of a Security Fix<\/h1>\n

You might build\u00a0a new website with the latest secure versions of WordPress and all of the relevant plugins and a theme. As time passes, vulnerabilities are discovered in your plugins, theme and the version of WordPress core you are using. Those vulnerabilities (or security holes) become public knowledge at some point.<\/p>\n

\"\"There is usually\u00a0a delay between when the vulnerability becomes public knowledge and when you get around to installing a fix. Even when a fix is automatically released by the WordPress security team, the vulnerability may have been public knowledge for some time. This was the case with the recent PHPMailer vulnerability,\u00a0which took several weeks for a patch to appear in WordPress core and be automatically deployed. \u00a0A WordPress security plugin provides many valuable functions, but at its most basic, a WordPress security plugin protects\u00a0your website from attacks during the time it is vulnerable.<\/p>\n

We do this in two ways. Wordfence provides a firewall that has rules that are constantly updated. At Wordfence, when\u00a0we learn about a new security hole in software that you might use, we release a firewall rule to your site that allows Wordfence to block hackers from exploiting that security hole. The second way we protect you is by providing a malware scan. Wordfence detects thousands of malware variants. If the worst happens and somehow a hacker does manage to penetrate your website, Wordfence alerts you to the presence of malware on your website and even helps you find it and remove it. Our malware signatures are also continually updated. \u00a0As many of you know, our Threat Defense Feed is what distributes new firewall rules and malware signatures to your Wordfence security plugin. Our Premium customers receive these in real-time. Free customers are delayed by 30 days.<\/p>\n

Protecting You When You\u2019re Vulnerable is What We Do<\/h1>\n

\"\"Wordfence provides many other security functions including two factor authentication, country blocking, brute force protection, rate limiting and more. But the most important function we provide is this: Wordfence protects your WordPress website\u00a0once vulnerabilities are discovered in your previously secure website and before you have installed a fix. \u00a0Most websites are hacked as a result of an attacker gaining entry by\u00a0exploiting a vulnerability in the website software. By using an effective WordPress firewall like Wordfence with a real-time Threat Defense Feed, you are protected, even if your website suffers from a vulnerability. \u00a0I hope this has helped provide a fundamental understanding of the most important reason you or someone you know needs a WordPress security plugin like Wordfence<\/a>. As always\u00a0I welcome your feedback in the comments below.<\/p>\n","protected":false},"excerpt":{"rendered":"

This is reprinted post from Wordfence, a vendor that we use on all of our…<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"yoast_head":"\nDoes your worpress site need security plugins - SearchTrafficNow.com digital agency<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Does your worpress site need security plugins - SearchTrafficNow.com digital agency\" \/>\n<meta property=\"og:description\" content=\"This is reprinted post from Wordfence, a vendor that we use on all of our...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/\" \/>\n<meta property=\"og:site_name\" content=\"SearchTrafficNow.com digital agency\" \/>\n<meta property=\"article:published_time\" content=\"2017-01-25T21:40:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-02-13T19:32:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png\" \/>\n<meta name=\"author\" content=\"[email\u00a0protected]\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"[email\u00a0protected]\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/\"},\"author\":{\"name\":\"[email\u00a0protected]\",\"@id\":\"https:\/\/searchtrafficnow.com\/#\/schema\/person\/a9b166f2f8290fa065d3a5dc969c38bd\"},\"headline\":\"Does your worpress site need security plugins\",\"datePublished\":\"2017-01-25T21:40:29+00:00\",\"dateModified\":\"2019-02-13T19:32:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/\"},\"wordCount\":1148,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/searchtrafficnow.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png\",\"articleSection\":[\"Website Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/\",\"url\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/\",\"name\":\"Does your worpress site need security plugins - SearchTrafficNow.com digital agency\",\"isPartOf\":{\"@id\":\"https:\/\/searchtrafficnow.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png\",\"datePublished\":\"2017-01-25T21:40:29+00:00\",\"dateModified\":\"2019-02-13T19:32:52+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#primaryimage\",\"url\":\"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png\",\"contentUrl\":\"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/searchtrafficnow.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Does your worpress site need security plugins\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/searchtrafficnow.com\/#website\",\"url\":\"https:\/\/searchtrafficnow.com\/\",\"name\":\"SearchTrafficNow.com digital agency\",\"description\":\"Web Design, Search Engine Marketing, SEO, Local Optimization\",\"publisher\":{\"@id\":\"https:\/\/searchtrafficnow.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/searchtrafficnow.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/searchtrafficnow.com\/#organization\",\"name\":\"SearchTrafficNow.com digital agency\",\"url\":\"https:\/\/searchtrafficnow.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/searchtrafficnow.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/searchtrafficnow.com\/wp-content\/uploads\/2016\/02\/logo.png\",\"contentUrl\":\"https:\/\/searchtrafficnow.com\/wp-content\/uploads\/2016\/02\/logo.png\",\"width\":225,\"height\":79,\"caption\":\"SearchTrafficNow.com digital agency\"},\"image\":{\"@id\":\"https:\/\/searchtrafficnow.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/searchtrafficnow.com\/#\/schema\/person\/a9b166f2f8290fa065d3a5dc969c38bd\",\"name\":\"[email\u00a0protected]\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/searchtrafficnow.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a5d49b9971664627d6282b50b9a34379?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a5d49b9971664627d6282b50b9a34379?s=96&d=mm&r=g\",\"caption\":\"[email\u00a0protected]\"},\"description\":\"David is a principal at Search Traffic Now and CountertopWebsites.coom. STN is a boutique digital marketing agency based in Ardmore PA. Countertop Websites is a demo site for Countertop, Cabinet and Flooring professionals. Our goal is to help industry professionals with their website development, design, and digital marketing efforts. David is also a principal in PowerPay - a consumer finance platform delivered via home improvement contractors. See My LinkedIn Profile\",\"url\":\"https:\/\/searchtrafficnow.com\/author\/dshaasgmail-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Does your worpress site need security plugins - SearchTrafficNow.com digital agency","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/","og_locale":"en_US","og_type":"article","og_title":"Does your worpress site need security plugins - SearchTrafficNow.com digital agency","og_description":"This is reprinted post from Wordfence, a vendor that we use on all of our...","og_url":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/","og_site_name":"SearchTrafficNow.com digital agency","article_published_time":"2017-01-25T21:40:29+00:00","article_modified_time":"2019-02-13T19:32:52+00:00","og_image":[{"url":"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png"}],"author":"[email\u00a0protected]","twitter_card":"summary_large_image","twitter_misc":{"Written by":"[email\u00a0protected]","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#article","isPartOf":{"@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/"},"author":{"name":"[email\u00a0protected]","@id":"https:\/\/searchtrafficnow.com\/#\/schema\/person\/a9b166f2f8290fa065d3a5dc969c38bd"},"headline":"Does your worpress site need security plugins","datePublished":"2017-01-25T21:40:29+00:00","dateModified":"2019-02-13T19:32:52+00:00","mainEntityOfPage":{"@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/"},"wordCount":1148,"commentCount":0,"publisher":{"@id":"https:\/\/searchtrafficnow.com\/#organization"},"image":{"@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#primaryimage"},"thumbnailUrl":"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png","articleSection":["Website Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/","url":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/","name":"Does your worpress site need security plugins - SearchTrafficNow.com digital agency","isPartOf":{"@id":"https:\/\/searchtrafficnow.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#primaryimage"},"image":{"@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#primaryimage"},"thumbnailUrl":"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png","datePublished":"2017-01-25T21:40:29+00:00","dateModified":"2019-02-13T19:32:52+00:00","breadcrumb":{"@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#primaryimage","url":"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png","contentUrl":"https:\/\/www.wordfence.com\/wp-content\/uploads\/2017\/01\/vault.png"},{"@type":"BreadcrumbList","@id":"https:\/\/searchtrafficnow.com\/worpress-site-need-security-plugins\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/searchtrafficnow.com\/"},{"@type":"ListItem","position":2,"name":"Does your worpress site need security plugins"}]},{"@type":"WebSite","@id":"https:\/\/searchtrafficnow.com\/#website","url":"https:\/\/searchtrafficnow.com\/","name":"SearchTrafficNow.com digital agency","description":"Web Design, Search Engine Marketing, SEO, Local Optimization","publisher":{"@id":"https:\/\/searchtrafficnow.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/searchtrafficnow.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/searchtrafficnow.com\/#organization","name":"SearchTrafficNow.com digital agency","url":"https:\/\/searchtrafficnow.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/searchtrafficnow.com\/#\/schema\/logo\/image\/","url":"https:\/\/searchtrafficnow.com\/wp-content\/uploads\/2016\/02\/logo.png","contentUrl":"https:\/\/searchtrafficnow.com\/wp-content\/uploads\/2016\/02\/logo.png","width":225,"height":79,"caption":"SearchTrafficNow.com digital agency"},"image":{"@id":"https:\/\/searchtrafficnow.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/searchtrafficnow.com\/#\/schema\/person\/a9b166f2f8290fa065d3a5dc969c38bd","name":"[email\u00a0protected]","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/searchtrafficnow.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a5d49b9971664627d6282b50b9a34379?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5d49b9971664627d6282b50b9a34379?s=96&d=mm&r=g","caption":"[email\u00a0protected]"},"description":"David is a principal at Search Traffic Now and CountertopWebsites.coom. STN is a boutique digital marketing agency based in Ardmore PA. Countertop Websites is a demo site for Countertop, Cabinet and Flooring professionals. Our goal is to help industry professionals with their website development, design, and digital marketing efforts. David is also a principal in PowerPay - a consumer finance platform delivered via home improvement contractors. See My LinkedIn Profile","url":"https:\/\/searchtrafficnow.com\/author\/dshaasgmail-com\/"}]}},"_links":{"self":[{"href":"https:\/\/searchtrafficnow.com\/wp-json\/wp\/v2\/posts\/21333"}],"collection":[{"href":"https:\/\/searchtrafficnow.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/searchtrafficnow.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/searchtrafficnow.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/searchtrafficnow.com\/wp-json\/wp\/v2\/comments?post=21333"}],"version-history":[{"count":0,"href":"https:\/\/searchtrafficnow.com\/wp-json\/wp\/v2\/posts\/21333\/revisions"}],"wp:attachment":[{"href":"https:\/\/searchtrafficnow.com\/wp-json\/wp\/v2\/media?parent=21333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/searchtrafficnow.com\/wp-json\/wp\/v2\/categories?post=21333"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/searchtrafficnow.com\/wp-json\/wp\/v2\/tags?post=21333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}