Best WordPress Hosting
 

WP Cerber Competitors Automattic and Patchstack Also Spread False Claim of Vulnerability in the Plugin

Earlier in the week, we detailed what looks to be going on with the closure of the popular WordPress security plugin WP Cerber on WordPress’ plugin directory. What seems like it could have started the closure was a claim made Continue reading WP Cerber Competitors Automattic and Patchstack Also Spread False Claim of Vulnerability in the Plugin

Not Really a WordPress Plugin Vulnerability, Week of September 30

In reviewing reports of vulnerabilities in WordPress plugins to provide our customers with the best data on vulnerabilities in plugins they use, we often find that there are reports for things that don’t appear to be vulnerabilities. For more problematic Continue reading Not Really a WordPress Plugin Vulnerability, Week of September 30

The Simple Way to Avoid Your WordPress Website From Being Hacked Like Fast Company’s Was

The news outlet Fast Company has been in the news for the past couple of days over obscene push notifications sent out through Apple News and an apparently relating hacking of their WordPress powered website. The hacker posted on Fast Continue reading The Simple Way to Avoid Your WordPress Website From Being Hacked Like Fast Company’s Was

Kaspersky Looks to Have Shuttered the Threatpost, the Security News Outlet They Secretly Own

When it comes to try to better understand the security risks that WordPress websites face, one big problem is that security companies and security journalists are often spreading inaccurate and far too often outright false information related to that. In Continue reading Kaspersky Looks to Have Shuttered the Threatpost, the Security News Outlet They Secretly Own

How to Replace Overpriced and Ineffective WPScan Based Penetration Testing of WordPress Websites With Cheaper and Better Automated Testing

Last week Bloomberg’s Katrina Manson covered a recommendation from the US Cybersecurity and Infrastructure Security Agency that urged companies to automate threat testing. The story touched on one of the realities of the poor state of security that doesn’t get Continue reading How to Replace Overpriced and Ineffective WPScan Based Penetration Testing of WordPress Websites With Cheaper and Better Automated Testing

Wordfence and Security Journalists Are Again Creating FUD About the Security of WordPress Websites

Last week numerous news outlets ran scary sounding stories about a claimed security issue in a WordPress plugin. Here are some of the headlines of stories that were included in Google News: WordPress zero-day vulnerability compromised more than 280000 websites: Continue reading Wordfence and Security Journalists Are Again Creating FUD About the Security of WordPress Websites

Only Six WordPress Security Plugins Protected Against Exploitation of Zero-Day Vulnerability in BackupBuddy

Last week the developer of one of the most popular WordPress security plugins, iThemes Security, disclosed that another of their plugins, BackupBuddy, had recently had a zero-day vulnerability. That is a vulnerability being exploited by a hacker before the developer Continue reading Only Six WordPress Security Plugins Protected Against Exploitation of Zero-Day Vulnerability in BackupBuddy

Unlike WP Sec, Our Service Actually Determines if Your Site is Using a Known Vulnerable WordPress Plugin

One of the things we do to be able to provide customers of our service with the best information about known vulnerabilities in WordPress plugins is by monitoring the WordPress Support Forum for possibly relevant topics. Along with the information Continue reading Unlike WP Sec, Our Service Actually Determines if Your Site is Using a Known Vulnerable WordPress Plugin

The All In One WP Security & Firewall Plugin Provides Little Firewall Protection With Recommended Settings

When we do testing of WordPress security plugins to see what protection, if any, they provide against vulnerabilities in other plugins; we try to enable any options that will cause them to provide all the protection they could possibly offer. Continue reading The All In One WP Security & Firewall Plugin Provides Little Firewall Protection With Recommended Settings

7G Firewall Tested: It Doesn’t Provide “Powerful” or “Super Strong” Protection

Yesterday, we compared the claims the developer of WordPress security plugin BBQ Firewall makes about its protection to the reality of the very limited protection in provides. The developer of the plugin is also the developer of a set of Continue reading 7G Firewall Tested: It Doesn’t Provide “Powerful” or “Super Strong” Protection

The BBQ Firewall Plugin for WordPress Isn’t a “Powerful WAF”

One of the most recent reviews for the BBQ firewall plugin for WordPress is titled “Not a real firewall..” and the author makes this claim: I had the PRO version and it doesn’t stop the real hacks. [Read more] ShareTweetSharePostSharePin Continue reading The BBQ Firewall Plugin for WordPress Isn’t a “Powerful WAF”

Only Two WordPress Security Plugins Prevented Exploitation of Vulnerability in Security Plugin WP Cerber

Security plugins for WordPress are supposed to help protect websites from being hacked, but not only do most of them not do a good job of that, they often introduce security vulnerabilities of their own. Like most vulnerabilities in WordPress Continue reading Only Two WordPress Security Plugins Prevented Exploitation of Vulnerability in Security Plugin WP Cerber

Cloudflare Isn’t Adding New Firewall Rules to Protect Against Vulnerabilities in WordPress Plugins

It isn’t hard to find people citing the Cloudflare service as a good security solution for WordPress websites. What is lacking is any of those people citing evidence that Cloudflare provides effective protection for WordPress websites. If it was an Continue reading Cloudflare Isn’t Adding New Firewall Rules to Protect Against Vulnerabilities in WordPress Plugins