Stuart Neal
Director of Operations at Nextgen Marketing
We have worked with Vitalli and his team for well over a year now and will continue to do so in the future.
Having the confidence in an agency that allowed us to scale up and down development resources, as and when needed, has really made a positive difference to our agency.
Home / Blog / WordPress / How to Prevent WordPress Malware Attacks
As a white-label wordpress development agency owner – my linkedin feed is flooded with the wordpress security risks, vulnerabities and other secure concerns. As for me – couple of basic rules that we’re going to cover in this post should cover your agency in 9 of 10 situations.
A lot of marketing agencies tend to pick “simpler” solutions than wordpress because they don’t need to keep up with wordpress maintenance or server settings which has it’s own pros and cons.
Main statement is – wordpress is secure platform out of the box.
WordPress was building it’s market share for over a decade with peak of 43% of the internet – meaning by targeting 100 websites you’ll have 43 of them in WordPress with possible same issues to target makes it reasonable to work with WordPress as a primary target.
That said – the more popular website is – the higher thread is. Potentially.
Aslo, please add the fact that it’s open source and 2 of 10 developers builds their own plugins and want to add to official directory. Each plugin should be maintained to protect the website in the same way as core wordpress – by doing updates and maintenance.
Your client’s website was never the concrete target. It was just part of automated scan that happen to have the vulnerability.
Hackers can inject ads, spam links or use compromised server for computing power. Anyway – it’s bad.
By keeping these 3 items up to date – you’re making big impact into website security. As I said – from the box WordPress if very secure platform, but mistakes can happen – so automatic minor updates and secure patches get released once in a while.
If you’re using premium themes and plugins that are up to date – more likely your clients are safe.
Custom themes have lower security standard than premium themes from the marketplace – simply because rarely there is a budget for security audit, so they tend to be the most dangerous part and there are no automatic updates – so by using custom solutions, especially with big portion of AI generated code – be sure to conduct the audit.
Recently we did an audit by request and it was a total disaster with full responsibility on previous development team.
These are core important points I wish every agency folk knew.
Username “admin” is the most popular one and the biggest thread to any website. This user + weak password = immediate access to the backend and it’s not wordpress issue – it’s the developer issue or the website admin issue. Main point here is to have a strong password for every user and avoid typical “admin” credentials or “root” etc.
WordPress even notice when admin is trying to create a username with “weak” password.
For agencies I recommend to have in-house password generation URL and pattern for usernames like {agency-short-name}-support or similar plus have a strong password.
Annoying requirement that saves so many agencies from pain of going though “issues” with clients. By enabling 2FA on a website – password and username strength are not that important because even admin/admin kind of login/password combination now will need unique 6 digit code which is tough to get if you’re using Google Auth App
Because if you’re using code that coming to the email – it’s better than nothing but not as secure as unique code that changes every 30 seconds.
It’s great recommendation for non-tech teams but in most cases this is not as important as having a good hosting with automated security scans on their end. But – we still recommend and install Wordfence on client’s projects to get notifications from daily scans in case of any issues.
This is very important for agencies who offers agency hosting and store multiple websites in 1 environment.
My recommended setup is to get notification for 1+ developer responsible for maintenance in your team, you can get notifications as well but the team should action changes without your interaction. On top of that get the same list of emails for notifications from wordfence or other security plugin.
Additional attention should bring to recovery plans and backups. There are situations when hosting could be ruined completely meaning some issues on your hosting provider side ruining their filesystem and all backups generated through hosting or with a backup plugin like updraft plus gets erased with no way to restore it.
To fix this issue – agencies should have cloudbackup option – on Google Drive or any other storage. Just send backups there so you can restore everything.
Another common issue is access issue. Nobody likes to explain but having separate access to hosting with 2FA issues on controlled device is 10x more valuable that waiting for person from vacation/another timezone/etc to give you the 2fa code – you need to be able to log in into hosting panel, issue new admin credentials, FTP/SFP/SSH credentials etc.
Full access and cloud backups ensure disaster recovery. If you miss something – you may look stupid when website is down but you can’t do anything without the access.
Not something I want you to set up on advanced level, but ensure that hosting has ISO sertificate, ensure malware scanner and uptime monitor is on, ensure previous partners don’t have access to file system so nobody is going to mess around.
I know that all of this sounds dull and nobody wants to do this – but keeping this secure and up to date is normal practice for every system, including agencies.
For small agencies who has no in-house dev team and potentially <12 websites built per year – maintenance is definitely not something you should be actively doing – outsource it to white-label team.
Somebody who will consult your client on tech side of things without you being in the loop ( ot at least not monitoring every email) and have your branded email so clients are taken care of.
If you were looking for help on maintenance or disaster recovery – DM me on linkedin or book a call using the button in the main navigation.