wp_security@2x

Six recommended security measures for corporate websites using WordPress

Hello, I'm Sato from non-standard world.

WordPress, introduced as a standard in corporate site CMS (update system), is an essential tool given the convenience of operation but it should be remembered that there are always security risks.

However, there may be some people who are concerned about what specific measures will be needed.
Today, we will introduce the recommended security measures to corporate sites that have introduced WordPress.

Protection of WordPress Management Screen

This is a countermeasure against attacks that attempt to hit the management screen and guess user name/password.

Countermeasure 1-1: Access Limitation by IP Address

By limiting access to the management screen by IP address, you can only access it from a specific place (company).

Specifically, we will apply IP restriction to the following.

  • /wp-login.php
  • /wp-admin/ * Excluding admin-ajax.php

Measures 1-2: Two-step authentication (recommended)

In addition to authenticating with a normal username and password, it also provides a more secure environment by authenticating using your smartphone, making it convenient for you to use Google’s two-step authentication system that uses your phone.

Countermeasures 1: Login lockdown (recommended)

If the user name and password have been entered incorrectly, there is a possibility of total attack, so access from that IP address will be locked out for a certain time.

Countermeasure 1-4: Leave logs of access and operations (recommended)

It is possible to monitor suspicious operation by leaving the operation history in case it was taken over.

Protection of Database Information

This is a measure about an attack that tries to steal "database connection information" of WordPress.

Countermeasures 2-1: Limitation of access to wp-config.php (recommended)

php with database connection information is prohibited from external access.

Countermeasures against Falsification of Corporate Website

It is a countermeasure against attacks that attempt to exploit malware (malware) and tamper with the contents of corporate sites by exploiting program vulnerabilities.

Measures 3-1: Limitation of access to wp-includes

Make sure that the folder below wp-includes which contains a core function of WordPress is not accessible from outside.

Countermeasures 3-2: Disable file editing (recommended)

You can not edit WordPress theme files (design information) and plugin files (additional functions) from the WordPress management screen.

Countermeasures4. Introducing security measures plugin

This is a comprehensive measure against various attacks on corporate sites.

Measures 4-1: Introducing iThemes Security, a comprehensive security plugin (recommended)

security plugin that detects and countermeasures various attacks iThemes Security We will introduce.

Countermeasures 4-2: Introduction of Theme, Plugin Checker (Recommended)

Introducing a plugin to check if there is any vulnerability in the theme, plug-in.

Introduction of automatic backup

In the unlikely event that a corporate site is falsified or cracked, it will be required for smooth recovery.

Countermeasures 5-1: Introduction of VaultPress, an antivirus and automatic backup service

This Web Service Lets You Regularly Check and Back Up Your Virus VaultPress In addition to preventing virus infection, recovery work in case of infection can be carried out smoothly by introducing “recovery process”.

* We need to make sure that backing up data to external services is not a problem with security policies.

Measures 6. Introduction of Firewall

It prevents malicious access from reaching the web server.

Countermeasures 6-1: Introducing CloudFlare Firewall Service

a service that speeds up the site and provides firewalls (the ability to prevent malicious access from reaching web servers) CloudFlare By introducing the “Accidental Attack”, it prevents attacks at waterfront.

* It is not necessary to install a firewall on the current server.

 

How was it? If you have installed WordPress but haven't taken measures, we recommend that you implement the measures as soon as possible.

We hope you will realize a safe CMS environment and operate our corporate website.


We are looking for a person in charge of the corporate site!
We are looking for a person in charge of the corporate site!

「 Solving the troubles of corporate site personnel! In the “Contact Us” section, we are looking for questions and questions that corporate web personnel have on a regular basis.
For those who have introduced questions on our blog, we will present you with an original postcard set.
Please feel free to contact us for any small questions from the following “Commentary Sending Form”.
*When posting a blog, please be assured that the company name or your name will not be published.

postcard set image
Pictures and contents may change.

article category