Simple Tips To Secure Your WordPress Blog/Website

Browsing articles in " News Updates "

Simple Tips To Secure Your WordPress Blog/Website

Sep 17, 2018   //   by MhdSafras   //   News Updates  //  No Comments


1. Don’t Use Nulled Themes

WordPress premium themes look more professional and have more customizable options than a free theme. But one could argue you get what you pay for. Premium themes are coded by highly skilled developers and are tested to pass multiple WordPress checks right out of the box. There are no restrictions on customizing your theme, and you will get full support if something does go wrong on your site. Most of all you will get regular theme updates.
But, there are a few sites that provide nulled or cracked themes. A nulled or cracked theme is a hacked version of a premium theme, available via illegal means. They are also very dangerous for your site. Those themes contain hidden malicious codes, which could destroy your website and database or log your admin credentials.

While it may be tempting to save a few bucks, always avoid nulled themes.

2. Install a WordPress Security Plugin

It’s a time-consuming work to regularly check your website security for malware and unless you regularly update your knowledge of coding practices you may not even realize you’re looking at a piece of malware written into the code. Luckily other’s have realized that not everyone is a developer and have put out WordPress security plugins to help. A security plugin takes care your site security, scans for malware and monitors your site 24/7 to regularly check what is happening on your site. is a great WordPress security plugin. They offer security activity auditing, file integrity monitoring, remote malware scanning, blacklist monitoring, effective security hardening, post-hack security actions, security notifications, and even website firewall (for a premium)

3. Use a Strong Password

Passwords are a very important part of website security and unfortunately often overlooked. If you are using a plain password i.e. ‘123456, abc123, password’, you need to immediately change your password. While this password may be easy to remember it is also extremely easy to guess. An advanced user can easily crack your password and get in without much hassle.

It’s important you use a complex password, or better yet, one that is auto-generated with a variety of numbers, nonsensical letter combinations and special characters like % or ^.

4. Disable File Editing

When you are setting up your WordPress site there is a code editor function in your dashboard which allows you to edit your theme and plugin. It can be accessed by going to Appearance>Editor. Another way you can find the plugin editor is by going under Plugins>Editor.

Once your site is live we recommend that you disable this feature. If any hackers gain access to your WordPress admin panel, they can inject subtle, malicious code to your theme and plugin. Often times the code will be so subtle you may not notice anything is amiss until it is too late.
To disable the ability to edit plugins and the theme file, simply paste the following code in your wp-config.php file.

define(‘DISALLOW_FILE_EDIT’, true);

5. Install SSL Certificate

Nowadays Single Sockets Layer, SSL, is beneficial for all kinds of websites. Initially SSL was needed in order to make a site secure for specific transactions, like to process payments. Today, however, Google has recognized it’s importance and provides sites with an SSL certificate a more weighted place within its search results.

SSL is mandatory for any sites that process sensitive information, i.e. passwords, or credit card details. Without an SSL certificate all of the data between the user’s web browser and your web server are delivered in plain text. This can be readable by hackers. By using an SSL, the sensitive information is encrypted before it is transferred between their browser and your server, making it more difficult to read and making your site more secure.

For websites that accept sensitive information an average SSL price is around $70-$199 per year. If you don’t accept any sensitive information you don’t need to pay for SSL certificate. Almost every hosting company offers a free Let’s Encrypt SSL certificate which you can install on your site.

6. Change your WP-login URL

By default, to login to WordPress the address is “”. By leaving it as default you may be targeted for a brute force attack to crack your username/password combination. If you accept users to register for subscription accounts you may also get a lot of spam registrations. To prevent this, you can change the admin login URL or add a security question to the registration and login page.
Pro Tip: You can further protect your login page by adding a 2-factor authentication plugin to your WordPress. When you try to login, you will need to provide an additional authentication in order to gain access your site — for example, it can be your password and an email (or text). This is an enhanced security feature to prevent hackers from accessing your site.
Pro Tip 2: You can also check which IPs have the most failed login attempts, then you can block those IP addresses.

7. Limit Login Attempts

By default, WordPress allows users to try to login as many time as they want. While this may help if you frequently forget what letters are capital, it also opens you to brute force attacks.
By limiting the number login attempts, users can try a limited number of times until they are temporarily blocked. The limits your chance of a brute force attempt as the hacker gets locked out before they can finish their attack.

You can enable this easily with a WordPress login limit attempts plugin. After you’ve installed the plugin you can change the number of login attempts via Settings> Login Limit Attempts. If you wish to enable login attempts without a plugin you can also do so. The full tutorial is here.

8. Hide wp-config.php and .htaccess files

While this is an advanced process for improving your site’s security, if you’re serious about your security it’s a good practice to hide your site’s .htaccess and wp-config.php files to prevent hackers from accessing them.

We strongly recommend this option to be implemented by experienced developers, as it’s imperative to first take a backup of your site and then proceed with caution. Any mistake might make your site inaccessible.

To hide the files, after your backup, there are two things you need to do:
First, go to your wp-config.php file and add the following code,

<Files wp-config.php>
order allow,deny
deny from all

In a similar method, you will add the following code to your .htaccess file,

<Files .htaccess>
order allow,deny
deny from all

Although the process itself is very easy it’s important to ensure you have the backup before beginning in case anything goes wrong in the process.

9. Update your WordPress version

Keeping your WordPress up to date is a good practice to keeping your website secure. With every update, developers make a few changes, often times including updates to security features. By staying updated with the latest version you are helping protect yourself against being a target for pre-identified loopholes and exploits hackers can use to gain access to your site.

It is also important to update your plugins and themes for the same reasons.

By default, WordPress automatically downloads minor updates. For major updates, however, you will need to update it directly from your WordPress admin dashboard.


Host Unlimited Domain Names for a Single Monthly Price $0.79

Apr 6, 2018   //   by MhdSafras   //   News Updates  //  No Comments


In this post, you will not only discover PromoHosts Basic plan Review but you will also find out why you need it.

PromoHosts offers a cheap price on all shared hosting including Basic plan with a Free Domain name in tri-annual plan. This is a good opportunity for entry-level bloggers to enjoy the powerful WordPress hosting at a low cost.

If you are planning to launch your blog or Website this year to make some money online, then this is probably the best time.

If you have tight budget on hosting and you want to some extra features and high quality server security then PromoHosts hosting for you. With PromoHosts, you never have to worry about your website being slow even when there is a millions of traffic.

Their 24/7/365 expert customer support is always there to help when you need it by phone, email, or live chat. We also cover about PromoHosts Real world Hosting performance, Server uptime, Technical Customer support, Hosting pricing, features in detailed.

If you are in a hurry and you don’t want to read the whole PromoHosts review then all you have to do is click on this link to purchase. The discount will be applied automatically.

PromoHosts 99.9% Server uptime Guarantee

PromoHosts Hosting have an amazing uptime of 99.9%. That means even for a split second, your site won’t go down or give your troubles while browsing your information or products. PromoHosts can easily handel millions of traffic without Downtime.

Let’s check last 12 month PromoHosts server uptime result.

  • January 2018 (99.994% average)
  • February 100%
  • March 100%
  • April 100%
  • May 99.987%
  • June 100%
  • July 100%
  • August 100%
  • September 100%
  • October 99.91%
  • November 100%
  • December 100%
  • January 2019 99.996%
  • February 2019 100%

PromoHosts Excellent Customer Support Team

When you run into trouble with your Website, or in the unlikely event of the server going down, you will always have a technician team there to help get you up and running your blog again.

PromoHosts offers a 24/7/365 customer support system where you can talk to their customer support representatives using live chat or phone or Tickets. There’s no hold time on phone or chat and live chat response times are almost instant which makes PromoHosts incredible. Email’s get the first response within less than 10 minutes.

PromoHosts basic plan offer Free SSL and CDN

SSL, which stands for Secure Socket Layer, is an encryption protocol. PromoHosts basic plan including an SSL certificate in its packages, is saving your money. SSL allows sensitive information such as credit card numbers, social security numbers, and login credentials to be transmitted securely.

PromoHosts also offers HTTP/2 Enabled Servers with even with their basic shared hosting plan. If you are concern about your blog or website security then SSL and HTTP/s is the best way to secure it and PromoHosts provides you without any charge.

CDN stands for Content Delivery Network. PromoHosts Basic plan offers you Free CloudFlare CDN service. The CloudFlare CDN caches your Website’s static content and distributes it over a network of 100+ servers worldwide.

After using CloudFlare CDN, you never have to worry about your blog or website being Hacked or under DDOS attack. It can block Spammers, SQL Injection attacks, DDOS attacks, excessive bot crawling, and more.

PromoHosts Server Response time (with Last 12 Month Results)

Run your site through the Google PageSpeed tool and GtMetrix to see if reduce server response time is in your report. Then your Hosting web server is slow then Server response time is the main factor to get the fastest website load time.

PromoHosts basic plan advantages:–

  • 99.9% Server Uptime
  • 24/7/365 Knowledgeable and friendly Customer service
  • 24 hours Money Back gurantee
  • Anti Bot artificial Intelligence system
  • Best server response time
  • Competitive pricing that helps customers get the best value for money.
  • cPanel access
  • Fast SSD storage
  • Daily backup
  • Free Domain Name
  • Extremely affordable hosting plans which start at just $0.79 per month.
  • Free SSL Certificate
  • Free Website Migration
  • HTTP/2 Enabled Servers
  • One click WordPress installation
  • CloudFlare CDN for Free
  • Unlimited Emails & DB