WordPress Security Plugins I Use

Category : Adam Stuff, Get Smarter

I’ve had too many WordPress (WP) installations hacked into by !*$# robots. Just like learning the hard way that you have to back up your computer regularly when you don’t and you get to redo tons of work, the school of WP hard knocks has beat me down to the point where I require these security plugins on my WP installations.  And yes, they are in the order of absolutely completely mandatory, to really good to have installed:

  1. Bei Fen – Good backup of your complete WordPress installation. You can choose only the files, or have it include your WordPress database. Plus, it makes unguessable archives of the whole thing and puts it into a folder on your server.  Get it? You just set up an FTP script to download your whole folder every so often and you’ve got a history of your site plus database. Totally mandatory since there is no 100% guarantee that the following plugins will save you from the most malicious attacks.
  2. Update Notifier – I’m busy.  Are you busy? This plugin emails you when updates are available for your WordPress installation. To stay ahead of most of the automated attack robots all you have to do is keep you WP core and plugins up to date. But I’m busy, so this reminds me to take the 5 minutes to update everything.
  3. Akismet – If you are experienced with WP you might wonder why I don’t have this listed as #1. It is because most of my sites don’t allow comments or open registration. forestsunlimited.net is an exception and for that site Akismet is a godsend. It is a great idea. You get an API, you log in to their server, and it keeps track of all the jerks hammering WP sites and then distributes the blacklist results. It is super easy to set up and everyone should have this installed.
  4. WordPress Firewall 2 – A great plugin that blocks a whole bunch of malicious crap. Of course, sometimes it blocks you too, so remember to turn it off when you do anything heavy on the WP core. Changing files through Appearance > Editor is one place I usually remember how effective this plugin is… after a lot of choice words and many attempts to just update my stinking footer file!
  5. Secure WordPress – It plugs some simple security leaks.  Nuff said.
  6. Limit Login Attempts 1.5 – If someone is trying to get into your admin account by brute force, this plugin stops them dead.
  7. Ultimate Security Check – This plugin scans your files and install configuration to give you a score on your site in terms of vulnerability. It is a good plugin for beginners or a a reminder of easily forgotten security leaks. Honestly, I usually install it, check its results, fix what I can, then uninstall it.

There are other, more time consuming ways to tighten up your WordPress site that I’ll post later. For now, feel free to comment if you have better security plugins.

Girl Talk at Disco Rodeo!

Category : Adam Stuff, Whatnot

WOO! That was a hell of a concert! Very ravelike. Very hot as hell in the center where Matto and I were standing.

Disco Rodeo in Raleigh is an interesting place. Perfect for Gregg Gillis to spaz out. You can get ALL DAY free at Illegal Art.

Launched Responsible Use Principles Today

Category : Adam Stuff

Woo! Stewardship Principles for anyone using biotech (a.k.a. genetically engineered) trees are finally here after over 2 1/2 years of work.  Its kind of a big deal in the relatively small field of forest biotechnology.  The fact is, biotech trees are coming.  If someone didn’t step up and do the hard work of putting some stewardship practices in place, then the environment might suffer.  It isn’t easy trying to get plans for doing things right BEFORE things go wrong.  But that’s the way it should be with life-changing technology.  I hope this could be a model for other advanced, future technologies.

Plus, I made a really sweet site for it!  I jumped on responsibleuse.org and built the whole thing except for a minimalistic template I started with.  Check out the pages, extensions aren’t necessary since there is a script that bounces it to the .shtml transparently.  That lets me use includes files and keep the pages more or less future proof.  That’s important because the Principles will be printed and available at amazon.com.

Damn Hackers!

Category : Adam Stuff

I think I’m about 20 hours into cleaning, rebuilding, and fortifying my sites against hackers.  Now my bro Erich is giving it a once over à la ethical hacking.

I’m kind of surprised how few comprehensive resources there are on the internets about securing a shared hosting account against malicious code.  There are bits and pieces of information everywhere, but nothing approximating a good one-stop-shop for people who, like me, want to just get on with it and then do something more fun!

I’m smoking on it.  More later…