Best WordPress Security Plugin – Better WP Security Plugin
- Price:
- FREE
- Rating:
- 5
Summary:
WordPress security plugin, best for me, which can handle most of the work for me easily and automatically. The name of that WordPress
“Is my WordPress site secured?” Have you ever asked this question to yourself? I did. When one of my friend’s site got hack. Nothing like hack, actually. But it was all messed up. The site was showing some homepage designed by the hackers. All other pages and posts were showing fine. Someone messed with .htaccess file and maybe with the theme files. A simple theme change was the simplest solution to get over the whole problem.
After all this, I came to my WordPress dashboard and had a look to my security plugins. If they were working fine and if my blog is secure from these type of attacks. There are tons of security plugin out there. Most of them has different work and are for different purpose. But what if you can get a single security plugin which can do most of your work?
I have got a very good WordPress security plugin, best for me, which can handle most of the work for me easily and automatically. The name of that WordPress security plugin is Better WP Security.
WordPress Security Plugin – Better WP Security
Better WP Security - The easiest, most effective way to secure WordPress. Improve the security of any WordPress site in seconds.
There are lot of awesome features of this WordPress security plugin. It obscure vulnerabilities (reason for most of the WordPress attacks) , protect the site by blocking users (who tries to attack), detects of all other vulnerabilities and bots and a few more. So, instead of copying all those features, description of this WordPress security plugin here in this post, I would suggest you to have a look at the plugin page and read all about it (MUST READ about a plugin you are going to use). And I will focus what you should do after installing this WordPress security plugin so that you wouldn’t mess up with your site (there are lot of easy ways to mess up the things
).
How to secure your WordPress site with Better WP security plugin?
After installing the plugin, you’ll be taken to your WordPress dashboard (if not, go yourself) and you will see a welcome message where the plugin will be asking you to make a back up of your database which will be sent to your email address associated with your site. COOL!
Of course create a back up, get it from your inbox and save it in your hard drive.
Next, you’ll be asked for the permission to edit WordPress core files like wp-config.php . I would recommend you to allow this. But make sure to read the message it will show while asking for this permission like below:
Finally, after this you’ll get an option for One-Click Protection from basic attacks. Click on the button which says “Secure my sites from basic WordPress attacks”.
Okay. Now we are safe from Basic attacks. But it doesn’t mean our site is completely secured and cannot be hacked or messed up by bad guys out there. After this we are taken to our dashboard where we are up with our WordPress site system status. It will show 19 things you need to work on, like in the image below.
No need to panic if you see items in RED or ORANGE which means your site is not secure on those items. As you can see, there is a link “Click here to fix”, which will take you on the respective item’s settings where you can alter it and secure your site in just few click (nothing complicated there).
The question is, should you do all 19 fixes suggested by this plugin? And the answer is NO, especially in case you are doing all that on your old site, not on a fresh one.
So, for newbies who are new to WordPress and a bit non- techie, here I’m sharing which of these 19 options you should fix and how.
So, in the system status page you will see (also, as in the image I shared above) #3, 4, 6, 8, 11, 12, 15 are already in Green. So, we don’t have to worry about it.
For #1, you can leave it because it is already set for administrators password.
#2. You can go with the Fix suggested by the plugin. When you’ll click on the link “Click here to fix” you will be taken to header tweak settings. Check all three options there.
#5. Now, you have to be a bit careful. If you have a new website and a fresh installation of WordPress then you can go with this fix BUT if you are doing this on your old site then I would suggest you to skip this one. It can mess with your site and posts you have published already.
#6. Database backup: This one is already set to schedule back up regularly. You can edit the settings in the left bar of this plugin. There are two options, one is to get an email of every back up and another is to get the back up in any of your folder and you can get it via FTP client.
#7. I recommend you to do this fix. It will lock your dashboard when you don’t use it. For example, I’m sure you don’t visit your dashboard after you are slept. So, you can enable the Away mode by this option. You can select the time after which the site backend will be disabled and when it will be enabled again. Now, you can sleep without any worry. Anyone visit any dashboard link will be redirected to blog homepage.
#9 and 10. Fix it. There no problem in doing that.
Note: If you do #9 fix then your Login, register URLs will be changed to whatever you make it.
Now, you can leave the rest. One important one is #16 but now we have our .htaccess file fully secured. So, we can skip this.
I’m suggesting to leave the rest because all the other options may cause conflicts with some plugins and themes.
Limit Logins
This is really helpful to stay safe from brute force attack. Brute force attack is like a software trying to login many times with all possible combinations. You can enable/edit this option from left sidebar of this plugin. The plugin will block if a host will enter wrong password more than the times you set. Set email notifications, so that you will be notified every time a host is blocked.
I get 2-3 emails every day, when a host is blocked. When a host is blocked more than 2-3 times, it means may be that host is trying to enter my site. Then I just BAN that host/IP (again, in the left sidebar).
You may get email many times or will get warnings in your dashboard but just have a quick look. It will notify you every time, about every change in your WordPress files.
Which WordPress security plugins you use?
I would love to hear from you. Which plugins you use, why? It would be great if you can share with my readers here.
- FREE
- editor rating5
About Abhi Balani
Hello reader, I'm +Abhi Balani, owner of this blog. Computer Engineer (very soon), part time Blogger, a little of gEEk, Technology Lover, Mad for Gadgets, Software Freak, Hardware Junkie, Non-Political, Internet Addict, Funny! Visit my My tech Blog
-
Abhi, unfortunately your that friend is me only. LOL
You already told me to install this plugin and at last we fixed this mess up that day.
And yes I would like to thank you for publishing this informative post
And yes one more plugin is there i.e. “Disable Directory Listing” as it prevents virtual directory listing services from listing the contents of directories or show a page in place of a directory’s listing. -
-
-
Hey Rizwan,
Yep, both are good in their own. You know, as I said in my article, I get 2-3 site lockout notification everyday. And if there is site lockout with the same IP. I ban that user.
Yes, it’s HARD. But you know, there are so many kids, little unskilled hackers who think they know hacking very well. But actually, whatever they do can be done by anyone. We all know there are tons of articles on Google to hack which is ABSOLUTELY WRONG, I think.
-
-
-
-
-
-
-
Hello Abhi,
Nice post regarding WordPress security. I am currently using two plugins on my site for the wordpress security 1) Secure WordPress 2) BulletProof Security and i am very happy with its out come. It’s also very important to backup your wordpress data on regular basis and for that i am using Xcloner want to know which one you are using for backup purpose?Thank you and have a good day.
-
I don’t know how to describe my feelings because at this time i am so happy and sad too. I am happy because i have just read an awesome article on WordPress security but after reading your article i see a huge security collapse in your blog and that is your Admin Username i.e “Abhi” is displaying in all your articles. If any hacker see this than he can try to unlock your password and get into your WordPress admin page.
-
Hi, Abhi
It is good to read all your content to protect our WordPress blog But hackers are very smart even they can hack. I am telling this because in my team a person is certified hacker and network administrator and i told about this article then he laughed and tell all these.by the way, It is Awesome
-
Hello Avinash,
Yes, I agree with you. And this security is NOT from certified hackers. It is from those unskilled hackers who try to MESS UP other’s sites by Google tutorials and whatever.
A hacker is not who can hack a site or change it’s homepage.
A hacker is one who can decode a password without the help of any software OR make a software himself to do decode an encoded password.
But I guess, our site is more secured from those who just want to play with others.
-
-
1
Thanks for the writeup on my Better WP Security plugins.
To address some comments, no, this plugin can’t guarantee you won’t get hacked. Nothing can promise you that. The bulk of attacks on WordPress these days aren’t targeted and are simply the result of a bot stumbling across an un-patched vulnerability, weak password, etc. This plugin is designed to take care of those types of issues. If you’re specifically targeted by someone who knows what they’re doing then all bets are off regardless of the countermeasures you have taken.
-
I found this post very helpful Abhi. I had taken the option to rename my table prefixes before I read this. So far, I don’t see any issues with it on my 2+ year old blog. Hopefully, I dodged a bullet on this one.
I’m thankful that I read your comments and DiTesco’s recommendation to delete other security plugins. I removed WordPress Firewall. Do you (or anyone else) recommend removing Login Lockdown too?
-
-
-
Hello Raaj,
Nice to see you here, buddy! Let me know if you are confused in any of the fix in that plugin.
Can you please do me a favor? I’d be grateful if you can visit my contest entry and hit all the buttons and join the conversation their.
Here’s the link: http://www.blogengage.com/blogger/10-reasons-why-i-will-not-accept-your-guest-post/
Hope to see you their.
-
-
-
Personally I use WP-Security Scan and harden the rest manually, but this plugin I have run into on a few clients blogs and is very good, unfortunately I had a client click to fix and completely lock up their site so they couldn’t hit anything, no images loading, no wordpress admin.. had to fix it all from Cpanel manually and was a pain.
-
-
-
-
-
-
-
#53 written by Ariel, 9 months ago
-
#55 written by Aghper 9 months ago
i am getting error on my site when using this plugin and got a message saying locked out
A host, 70.25.46.222(you can check the host at http://ip-adress.com/ip_tracer/70.25.46.222) has been locked out of the WordPress site at http://mysite until Friday, August 3rd, 2012 at 5:14:58 pm UTC due to too many attempts to open a file that does not exist. You may login to the site to manually release the lock if necessary.
does this gives that error message?
-
This is not error. It’s just reporting. If you get lock out notification from the same IP address again and again then it means someone is trying to hack your site from that IP address. Then you can go to this plugin and add that IP address in BAN hosts to ban that user from your site.
Let me know if you get that. There’s nothing to worry.
-
-
-
#59 written by Ariel, 9 months ago
-
Hey Ariel,
Yes, few plugins may turn the sites slower, especially those 404 plugins. But not necessarily all plugins, actually most of the plugins doesn’t.
Yes, you can use that plugin, to lock users out after few attempts but it will secure you only from those brute force attacks.
There are many other things we need to take care of when it comes to security like .htaccess files (especially this one, I see a lot of cases when hackers play with this file if they are left open).
Let me know if you need any more help.
-
-
#61 written by Ariel, 9 months ago
-
To protect .htaccess files, maybe, the plugin fix the values for the files. I am not so sure, though.
Yes, the back ups are sent to your email address and if you wish, instead of getting a regular back up email, you can rather get the back up file uploaded to your WordPress directory which can be accessed later via FTP.
Yes, hosting services provide this back up service, and it’s good. But they charge money for this.
Contact me through my contact form if you still have any doubt.
-
-
-
-
-
-
-
-
Right, Jane! It’s worth a try. I was getting so many hacking attempts emails. Now they are all stop, because hackers know my site is not THAT MUCH vulnerable so they skip it.
And about that disabling dashboard, sometimes, when I am up till late, my blog kick me out of my dashboard after the time I have set up. LOL!
Thanks for adding your comments, Jane.
Take care while installing the plugin, I know you will but still.
-
-
-
-
-
-
How many times I will have to confirm for the same thing ? I already did two times.
YES, We have to check all three.
Don’t worry. Just make a back up before starting the process. Okay?
If you still find any problem, contact me through the contact form. I will be happy to help.
After you are done with this plugin, please take a minute to visit the link below and write some comments. That’d be great.
Thank you!
-
-
-
-
-
-
I’m afraid it will trash my site. I tested this on my backup wordpress and it did some very bad things to the site.
For now I’m using Pie Register – which at least ads re-captcha for users wishing to register and then I have to approve them.
Its a start at least (and thanks for showing it to me too!)
-
-
Sudeep Acharya:
Yes Abhi,
I have updated to the latest version.Do we have an alternative to this plugin?I am still looking for a solution from you.
Thanks. -
Hi Abhi,
At wp repo, I found alternatives to your recommendations and I felt that I should share them.
I installed simple login lockdown which is very much similar to you stated but the plugin is an updated one.
Also I installed OSE Firewall which is again an updated and do lots of work .You can even show a security seal in your website . -
-
-
#94 written by Tisa Yonts 4 weeks ago
-
- Comment Feed for this Post
- Blog Engage Guest Blogging Contest Winners – I WON!
- So you got hacked.. now what?
- Better WP Security: You Should Have it Now » Personal Blog of Justin Germino
- 3 WordPress SEO plugins you may want to consider!
- Better WP Security | James Perry
About Abhi (123 posts)
Hello reader, I'm +Abhi Balani, owner of this blog. Computer Engineer (very soon), part time Blogger, a little of gEEk, Technology Lover, Mad for Gadgets, Software Freak, Hardware Junkie, Non-Political, Internet Addict, Funny! Visit my My tech Blog














Funny thing – I tried this and another security plug-in blocked it.
Seriously, this is a good plug-in, from what I can tell. I run a different combination of things, but this does all the right things, from the looks of it. Good post, Abhi.
I mean – useful, helpful, educational, and proactively preventive post!