7/28/2016

Best Practices To Secure Your Wordpress Ecommerce Website

The moment you decide to take your business online, you have to be prepared for security and protect your contents and information from unauthorized access. 

It is all too common for Wordpress users to overlook their website security. 

If you belong to this group, you might want to start thinking twice; especially, if you are running an e-commerce webstore on Wordpress. 

Keeping your e-commerce website hack-free is probably too idealistic. Remember that even the biggest e-commerce websites operating online like Amazon.com remain susceptible to hacking. 

For small businesses with limited financial resources, you can do a few things that will make it difficult for hackers to perform malicious activities on your site. 

Performing early precautionary security measures are less expensive against restoring your website after you have been hacked. 

Securing your Wordpress website is not really rocket science. 

Running an e-commerce store opened me to a world of vulnerabilities; but I can do a few things to add an extra coat on security layers that patches some security holes commonly breached. 

It is important to understand the vulnerabilities of your website so you can strengthen that spot and make it difficult for perpetrators to succeed. 

I am using Wordpress for my e-commerce store, an open-source content management system that offers unlimited power to explore endless functionality that is very useful to my small e-commerce business.



If you are on Wordpress, too, these suggestions might also be useful to you,

  • Use a trusted hosting service. It is exceedingly important that your server is secure. When looking for a hosting service, you might want to consider these things on top of others:
    • Services
    • Security
    • Back-up Solutions
You can start by reading hosting reviews to make an informed choice for your best options. 

  • Don’t forget to keep your Wordpress version updated. Older versions can be easier to hack because after Wordpress releases a new version, the vulnerabilities and issues in the older version are publicly announced. Don’t forget to back up before updating.
  • Choose themes and plug-ins from trusted developers. Don’t get over-excited with free offers. It does not hurt to make a quick search about the plug-in or theme you will install on your site to avoid plug-ins and themes with hidden malicious codes. If possible, use the paid versions that come with support. If you are on a tight budget, here are a few things you can do:
    • Search the author of the plug-in and download from trusted source (likely the author’s site). You can also use the Wordpress plug-in repository.
    • Find a trusted community discussing themes and plug-ins to seek advice. You can go to wordpress.org support forum and open a topic.
    • Check if the plug-in or theme has an updated version.
  • Use secure usernames and passwords. E-commerce sites are common targets of brute attacks. This is an attack that makes use of a software performing trial-and-error attempts to guess your password until they can find a match. Here’s what you can do:
  1. Do not use the username ‘admin’. Change this to something unique. When choosing your username, there are three things you should consider to avoid:
      • Do not use your name
        • Do not use your business name
          • Do not choose any part of your url
        1. Create a secure password. When creating a secure password, it is best to choose any of these recommendations:
        2. Include a combination of capital letters, lowercase letters, numbers and symbols. This makes your password harder to crack.
        3. Use password generator. This tool randomly selects letters, numbers and symbols to create a strong password that is harder to crack. If you got the budget, you might want to try this out.
        4. 2-Step verification process. A plug-in you can use is Google Authenticator that links your smart mobile device to your site; so that each time you attempt to log-in, a unique code will be generated and sent to your smart phone. This added log-in security layer will ensure that only you can access the authentication password needed to log-in.
        5. Use passphrase. Instead of using a password, a passphrase is a series of small words.

        Here’s a valuable resource video by D.K. Smith discussing the Facts and Fiction of Wordpress Security that you might want to watch. 


        http://youtu.be/8T2jxAqkrcU 



        Other recommendations: Thanks to the helpful Pinoy bloggers of #APB, we discovered about iThemes Security. Using iThemes Security allows you to change your default login area. You can personalize your login url to hide your log-in area from malicious attacks. When I used iThemes in my Wordpress ecommerce website, there has been no brute attacks so far.


        What are your security best practices on your Wordpress site? Please share in the comment box below.



        *This article was originally published in davaogarage.com

        _________________ 

        Do you need help setting up your Wordpress website? Shoot me an email!