Sometimes you might be asking yourself this question “Do I really need a WordPress security plugin?” and i tell you yes, you need it very seriously. However, this is a perfectly valid question. If you are not in the security industry, you might ask it.
I know that many of you are well versed in security already and WordPress security in particular. Perhaps that is why you are reading this post or subscribe to our mailing list. What I would like to provide you with in this post is a way to answer the question of “Do I need a WordPress security plugin?” to friends, family and colleagues that is both enlightening and easy to understand.
If you are new to WordPress, I hope this post helps increase your understanding of WordPress security.
When you come to compare physical security with WordPress security you will find out that many people think about WordPress security in the same way that they think about physical security in the real world.
In the physical world, we might build a facility like a bank that needs to be secured. We build barriers to entry and access controls as part of the construction project.
Once the project is complete, we have a secure facility with walls, gates, secure entry and exit, cameras, access controls and human personnel to implement security procedures as people enter and exit.
The physical construction does not change much over time, once the project is completed.
You are unlikely to discover that the concrete you used to build a wall for your bank is now vulnerable and needs to be replaced.
A wall is still difficult to penetrate and a locked gate with a guard is going to still be quite effective a few months from now.
It is easy to make the mistake of thinking about WordPress security in the same way. If you install software that is secure to power your WordPress website and you implement good security policy and controls, one might think a website would behave in the same way. In other words, one might think a secure website today should be secure a few months from now if it doesn’t change.
That is not the case and its going to be explained here. If you build a website using the newest software that has been verified to be secure and you implement good security policy, your website does not change, but the environment it is operating in changes.
Attackers continually research the software that powers your website and vulnerabilities are eventually discovered in most popular online software.
Therefore the problem is that, while your website software starts off secure, it almost always ends up being insecure without anything changing on your website.
It’s not your fault or the fault of the person who created your website. It is just the way of the online world. This differs from our building metaphor above in that, a secure building doesn’t usually end up insecure a couple of months after being built without anything in the building changing. But a website does.
In fact, this is an ongoing cycle. Vulnerabilities are discovered, attackers start using them and ultimately if you are a responsible WordPress website owner, you will have to upgrade or update your website regularly to fix those vulnerabilities. Then new vulnerabilities are discovered in new versions and the cycle repeats.
You might build a new website with the latest secure versions of WordPress and all of the relevant plugins and a theme. As time passes, vulnerabilities are discovered in your plugins, theme and the version of WordPress core you are using. Those vulnerabilities (or security holes) become public knowledge at some point.
There is usually a delay between when the vulnerability becomes public knowledge and when you get around to installing a fix. Even when a fix is automatically released by the WordPress security team, the vulnerability may have been public knowledge for some time. This was the case with the recent PHPMailer vulnerability, which took several weeks for a patch to appear in WordPress core and be automatically deployed.
A WordPress security plugin provides many valuable functions, but at its most basic, a WordPress security plugin protects your website from attacks during the time it is vulnerable.
One of the best WordPress security plugin is the Wordfence security plugin. This plugin provides security is two different ways. Wordfence provides a firewall that has rules that are constantly updated.
If Wordpfence learn about any new security flaws in the software you are using, the wordfence will release a firewall rule to your website that allows it to block hackers from exploiting that security flaws.
The second way this plugin protects you is by providing a malware scan. Wordfence detects thousands of malware variants.
If the worst happens and somehow a hacker does manage to penetrate your website, Wordfence alerts you to the presence of malware on your website and even helps you find it and remove it. Wordfence malware signatures are also continually updated.
However, Wordfence Threat Defense Feed is what distributes new firewall rules and malware signatures to your Wordfence security plugin. The Premium customers receive these in real-time, while free customers are delayed by 30 days.
Did you enjoy this post? Share it!
Felix Onyenobi is a technology enthusiast and loves to write. He is a co-founder at SkyNet Digital Agency. Also a web developer, Penetration tester and ethical hacker.