10 Tips for Keeping Your WordPress Site Secure

  10 Tips for Keeping Your WordPress Site Secure It seems like almost every week we see a new post by Matt Southern on a new WordPress site vulnerability or exploit. This is for good reason as WordPress accounts for over 23% of all of the websites on the internet, and that number is steadily […]

WordPress malware: Don’t let too-good-to-be-true deals infest your site

  WordPress malware: Don’t let too-good-to-be-true deals infest your site Sometimes you can smell when it’s not going to end well. It’s almost like there’s a taste in the air. It started with a routine email message in my inbox. But after reading the first few words, I knew this was going to be one […]

WordPress Security and What’s New in 4.2

WordPress has come under fire in many ways over the last couple months and security has become of paramount importance when dealing with you WordPress website. There are a few things to know about security with WordPress the first of which is insuring that you have adequately provided for the security of your site by […]

8 Terrifying Reasons Hackers Love it When You Install WordPress Using 1-Click Methods

  8 Terrifying Reasons Hackers Love it When You Install WordPress Using 1-Click Methods Everyone is using 1-click installers that come with their hosting accounts simply because they don’t know any better. It is indeed quicker, but can open up your website to a ton of security vulnerabilities, especially when compared to installing WordPress manually […]

WordPress 4.1.2 is a Critical Security Release, Immediate Update Recommended

  WordPress 4.1.2 is a Critical Security Release, Immediate Update Recommended WordPress 4.1.2 is available and is a critical security update for all previous versions of WordPress. The release has eight security fixes, one of which is high risk, three are medium-low risk, and the last four added to harden WordPress. This is the first […]

Security Advisory: XSS Vulnerability Affecting Multiple WordPress Plugins

Lock up your WordPress

  Security Advisory: XSS Vulnerability Affecting Multiple WordPress Plugins Multiple WordPress Plugins are vulnerable to Cross-site Scripting (XSS) due to the misuse of the add_query_arg() and remove_query_arg() functions. These are popular functions used by developers to modify and add query strings to URLs within WordPress. The official WordPress Official Documentation (Codex) for these functions was […]

Zero-day in the Fancybox-for-WordPress Plugin

  Zero-day in the Fancybox-for-WordPress Plugin The fancybox-for-wordpress plugin is a popular WordPress plugin with more than 550,000 downloads. There doesn’t appear to be any public vulnerabilities being reported, which piqued our interest. To understand how it was connected, we decided to do our own code / vulnerability review. After some analysis, we can confirm […]

8 WordPress Security Tips to Help You Secure Your WordPress Site

It's episode 202 and we’ve got plugins for Secure Site Error Detection, Idea Submissions, BitCoin Tips, Performance Testing and a new plugin to help with natural Post Tags. It's all coming up on WordPress Plugins A-Z!

  8 WordPress Security Tips to Help You Secure Your WordPress Site Is being hacked fun? Certainly not. The worst part about it is that you could potentially lose everything. Your content. Your media. Personal data. It’s natural to want to protect your site from being hacked. It’s just as important as protecting your home […]

SoakSoak Campaign Evolves New Wave of Attacks

  SoakSoak Campaign Evolves New Wave of Attacks Since Sunday, we have seen a new wave of SoakSoak reinfections. The Javascript continues to evolve and load other scripts in order to infect additional websites. We have updates for concerned webmasters looking to stay on top of the threat and keep their site protected against these […]

SoakSoak Malware Compromises 100,000+ WordPress Websites

  SoakSoak Malware Compromises 100,000+ WordPress Websites This Sunday has started with a bang. Google has blacklisted over 11,000 domains with this latest malware campaign from SoakSoak.ru: The impact seems to be affecting most hosts across the WordPress hosting spectrum. Quick breakdown of the decoding process is available via our PHP Decoder. If you believe […]

The Invisible RootPress WordPress Malware Attack Planet Zuda

  The Invisible RootPress WordPress Malware Attack Planet Zuda The malware was invisible to Windows users and as far as we know it is also invisible to Macintosh users as well. We are very thorough when doing malware removal, so we had to find what let the hackers into the site, the backdoors, and anything […]

How to check if you’re vulnerable to the WordPress flaw

  How to check if you’re vulnerable to the WordPress flaw On November 20, WordPress announced a critical cross-site scripting vulnerability in the Internet’s most popular and widely used content management system. Initially discovered by Jouko Pynnonen with the Finnish IT company Klikki Oy, the vulnerability could allow anonymous users to compromise websites running versions […]