Pint Sized Marketing, April 2019
@irishwonder IrishWonder’s SEO Consulting
WHY SECURITY MATTERS?
@irishwonder IrishWonder’s SEO Consulting
NOT JUST BECAUSE OF GDPR
@irishwonder IrishWonder’s SEO Consulting
NOT JUST FOR INTERNET
SECURITY PROFESSIONALS
@irishwonder IrishWonder’s SEO Consulting
SEO NIGHTMARES
@irishwonder IrishWonder’s SEO Consulting
HACKED SITES,
NO WARNINGS
@irishwonder IrishWonder’s SEO Consulting
BY THE TIME YOU SEE
A WARNING HERE,
IT MIGHT BE TOO LATE
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
GOOGLE WEBMASTER
GUIDELINES:
@irishwonder IrishWonder’s SEO Consulting
YOU ARE THE ONLY PERSON
RESPONSIBLE
FOR YOUR SITE’S SECURITY
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
Vulnerabilities by Type and Year
@irishwonder IrishWonder’s SEO Consulting
Who’s Attempting to Hack Your Site?
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
BUILD YOUR SITE…
@irishwonder IrishWonder’s SEO Consulting
…OR CHOOSE YOUR POISON
@irishwonder IrishWonder’s SEO Consulting
The larger the system,
the greater the
probability of
unexpected failure
- One of the systemantics laws
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
https://medium.com/@Gadgetoid/analyzing-the-pipdig-wordpress
-plugin-ddos-code-and-their-explanation-for-why-it-exists-
87f12edf5f9f
Additional Reading:
@irishwonder IrishWonder’s SEO Consulting
https://blog.sucuri.net/2014/12/revslider-vulnerability-leads-to-
massive-wordpress-soaksoak-compromise.html
Additional Reading:
@irishwonder IrishWonder’s SEO Consulting
 Once approved for Plugins Directory
inclusion, they are not checked any
more
@irishwonder IrishWonder’s SEO Consulting
 Updates are not checked
@irishwonder IrishWonder’s SEO Consulting
 Developers are not required to
maintain and update them
@irishwonder IrishWonder’s SEO Consulting
 Nobody bears responsibility for what
they do to your site
@irishwonder IrishWonder’s SEO Consulting
 While you can update standalone
plugins, you cannot update plugins
included into themes
@irishwonder IrishWonder’s SEO Consulting
 Only use plugins you
ABSOLUTELY NEED
@irishwonder IrishWonder’s SEO Consulting
 If you have to search to know
if you are using a certain
plugin, you’ve got a problem
@irishwonder IrishWonder’s SEO Consulting
REMOVE UNUSED PLUGINS
@irishwonder IrishWonder’s SEO Consulting
Only use themes from
reliable sources
@irishwonder IrishWonder’s SEO Consulting
Know what plugins a theme uses
@irishwonder IrishWonder’s SEO Consulting
Demand updates
@irishwonder IrishWonder’s SEO Consulting
Keep a clean backup of your
theme somewhere secure
@irishwonder IrishWonder’s SEO Consulting
REVOKE UNNEEDED ACCESS
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
UPDATE wp_users SET ID= '111' WHERE ID= 1;
UPDATE wp_usermeta SET user_id = '111' WHERE user_id = 1;
UPDATE wp_posts SET post_author='111’ WHERE post_author=1
*Keep in mind your actual database name,
your desired ID and your SQL version syntax
@irishwonder IrishWonder’s SEO Consulting
CHECK IF EVERYTHING
IS LATEST VERSION
(AND IF THE LATEST
VERSION IS SECURE)
@irishwonder IrishWonder’s SEO Consulting
CHECK FOR KNOWN
VULNERABILITIES
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
@irishwonder IrishWonder’s SEO Consulting
A WORD OF WARNING
ABOUT SUCURI:
IT’S AN EXCELLENT FIREWALL
BUT CAN ONLY SEE SO MUCH
FROM THE OUTSIDE
@irishwonder IrishWonder’s SEO Consulting
MYTH:
SSL = SECURE SITE
@irishwonder IrishWonder’s SEO Consulting
“buy tramadol” SERPs:
All 3 hacked sites are HTTPS
@irishwonder IrishWonder’s SEO Consulting
One site has SSL implemented incorrectly
@irishwonder IrishWonder’s SEO Consulting
CHECK YOUR SSL CERTIFICATE
@irishwonder IrishWonder’s SEO Consulting
YOUR SSL IMPLEMENTATION
IS ONLY SECURE
IF YOU CONSISTENTLY LINK
TO SECURE RESOURCES
@irishwonder IrishWonder’s SEO Consulting
HAVE A CLEAN BACKUP
@irishwonder IrishWonder’s SEO Consulting
FIRE ALARM SCENARIO:
WHEN YOU ARE HACKED/
SUSPECT A HACK
@irishwonder IrishWonder’s SEO Consulting
 Check your server logs to see any unusual
URLs being requested
 Check Majestic for your indexed/linked to
pages
 Check Google Search Console for unusual
queries, URLs and crawl errors
@irishwonder IrishWonder’s SEO Consulting
• info@irishwonder.com
• Twitter: @irishwonder
• Slideshare (for this and other decks):
http://www.slideshare.net/irishwonder/
• LinkedIn: linkedin.com/in/irishwonder
• Blogs:
http://www.irishwonder.com/blog/ -
general SEO
http://www.irishwonder.syndk8.co.uk/ -
darker areas

More Related Content

PDF
SearchLeeds 2018 - Julia Logan - Irish Wonder - How to audit your site for se...
PPTX
How to Audit a Site for Security
PPTX
Content Audit for iGaming - BAC2017
PPTX
Panda Diet for Overweight Websites
PPTX
How to Beat Your Bigger, Stronger Competitor at SEO
PPTX
What is the best seo tool in 2020
PDF
The Freelancer's SEO Checklist
PDF
Geekiest Conference Quotes by NetApp Insight Attendees
SearchLeeds 2018 - Julia Logan - Irish Wonder - How to audit your site for se...
How to Audit a Site for Security
Content Audit for iGaming - BAC2017
Panda Diet for Overweight Websites
How to Beat Your Bigger, Stronger Competitor at SEO
What is the best seo tool in 2020
The Freelancer's SEO Checklist
Geekiest Conference Quotes by NetApp Insight Attendees

Similar to WordPress Security (20)

PDF
SEO Security Audits - Is Your Site at Risk? - Amsterdam Affiliate Conference
PPTX
Wordpress SEO and Security - AAC2016
PDF
SEO for Small Businesses at #LearnInbound Dublin
PDF
Expert Panel Session - Killer Keyword Research - ionSearch 2012
PDF
WordPress Security WordCamp OC 2013
PDF
7 International SEO Dos & Dont's by @aleyda at #ionSearch
PDF
SEO Security Audits - SMX London
PPTX
Solving the Keyword Mystery: Clue In on How Customers Search for Your Business
PDF
Negative SEO: Myths and reality - BrightonSEO April 2013
PDF
Profesyonel SEO İçerik - Aleyda Solis - SEOzone 2014 Sunumu
PPTX
SEO 101: An Intro to Search Engine Optimization
PDF
Brand Monitoring SEMrush ToolBox by Jason Barnard
PPTX
Creating Content that Converts: Lean Content Marketing for Lead Generation
PDF
Firebase: What you need to know
PDF
Sell gold-seo-advice
PPTX
Widely Preached Truths That Are Not Always True - SASCon Mini
PPTX
How To Make Your Content Visually Chic, Jason Miller, LinkedIn - Social Fresh...
PDF
Google Featured Snippets, the Discover Feed & More Must-Know SEO Insights, SE...
PDF
Aleyda Solis_SearchLove London 2013
PDF
How to Succeed at Real International SEO Scenarios - #SearchLove London
SEO Security Audits - Is Your Site at Risk? - Amsterdam Affiliate Conference
Wordpress SEO and Security - AAC2016
SEO for Small Businesses at #LearnInbound Dublin
Expert Panel Session - Killer Keyword Research - ionSearch 2012
WordPress Security WordCamp OC 2013
7 International SEO Dos & Dont's by @aleyda at #ionSearch
SEO Security Audits - SMX London
Solving the Keyword Mystery: Clue In on How Customers Search for Your Business
Negative SEO: Myths and reality - BrightonSEO April 2013
Profesyonel SEO İçerik - Aleyda Solis - SEOzone 2014 Sunumu
SEO 101: An Intro to Search Engine Optimization
Brand Monitoring SEMrush ToolBox by Jason Barnard
Creating Content that Converts: Lean Content Marketing for Lead Generation
Firebase: What you need to know
Sell gold-seo-advice
Widely Preached Truths That Are Not Always True - SASCon Mini
How To Make Your Content Visually Chic, Jason Miller, LinkedIn - Social Fresh...
Google Featured Snippets, the Discover Feed & More Must-Know SEO Insights, SE...
Aleyda Solis_SearchLove London 2013
How to Succeed at Real International SEO Scenarios - #SearchLove London
Ad

More from Julia Logan a.k.a. IrishWonder (12)

PDF
SEO for the Baltic Region, Translation and Localisation - Mare Balticum 2023 ...
PDF
2022 Zangoose brochure.pdf
PDF
Zangoose Digital - Bespoke Private Networks
PPTX
Why We Should Stop Ignoring Bing
PDF
Preemptive Reputation Management
PDF
AJAX Security - LAC2016
PPTX
Controlling Your Links: How to Build a Private Network
PPTX
It's Not All About Google: Searching for Alternatives
PDF
"Catch Me If You Can" - Google vs Spam - Linkdex Gambling Thinktank
PDF
State of Search RIMC 2013
PDF
Negative SEO: Past, Present and Future - ThinkVis 2013
PPTX
So You Want to Know About AdSense?
SEO for the Baltic Region, Translation and Localisation - Mare Balticum 2023 ...
2022 Zangoose brochure.pdf
Zangoose Digital - Bespoke Private Networks
Why We Should Stop Ignoring Bing
Preemptive Reputation Management
AJAX Security - LAC2016
Controlling Your Links: How to Build a Private Network
It's Not All About Google: Searching for Alternatives
"Catch Me If You Can" - Google vs Spam - Linkdex Gambling Thinktank
State of Search RIMC 2013
Negative SEO: Past, Present and Future - ThinkVis 2013
So You Want to Know About AdSense?
Ad

Recently uploaded (20)

DOCX
Project and Portfolio 2: Full Sail University
PPT
Market research before Marketing Research .PPT
PDF
Snapshot of Consumer Behaviors of July 2025-EOLiSurvey (EN).pdf
PDF
The B2B Startup Marketing Playbook - How To Build A Revenue-Generating B2B Ma...
PPTX
Smart Optics in the Field: Understanding the AX Visio
PDF
Digital Marketing Agency vs Freelancers and VAs: Which Should You Hire in 2025
PDF
Retaining SEO Rankings During Website Redesign.pdf
PPTX
Choose the Right SEO Agency India - 7 Key Tips by Clickbold Media
PPTX
Digital-Marketing-Strategy-Trends-and-Best-Practices-for-2025 PPT3.pptx
PPTX
Top Digital Marketing Companies in Mumbai
PPTX
Mastering in Website Competitor Analysis
PPTX
CH 2 The Role of IMC in the Marketing Process (combined)
PDF
SEO vs. AEO: Optimizing for Google vs AI-Powered Search Assistants
PDF
AI powered Digital Marketing- How AI changes
PPTX
Strategic Sage Digital-The Professional Digital Marketing Company in Mohali.pptx
PDF
It Takes a Village Campaign Plan Book; Sidra Medicine
PDF
digital marketing courses online with od
PDF
5 free to use google tools to understand your customers online behavior in 20...
DOCX
IREV Platform: Future of Affiliate Marketing
PPTX
1 percent Clicks, percent Traffic Loss-Your SEO Stack Isn’t Built for AI
Project and Portfolio 2: Full Sail University
Market research before Marketing Research .PPT
Snapshot of Consumer Behaviors of July 2025-EOLiSurvey (EN).pdf
The B2B Startup Marketing Playbook - How To Build A Revenue-Generating B2B Ma...
Smart Optics in the Field: Understanding the AX Visio
Digital Marketing Agency vs Freelancers and VAs: Which Should You Hire in 2025
Retaining SEO Rankings During Website Redesign.pdf
Choose the Right SEO Agency India - 7 Key Tips by Clickbold Media
Digital-Marketing-Strategy-Trends-and-Best-Practices-for-2025 PPT3.pptx
Top Digital Marketing Companies in Mumbai
Mastering in Website Competitor Analysis
CH 2 The Role of IMC in the Marketing Process (combined)
SEO vs. AEO: Optimizing for Google vs AI-Powered Search Assistants
AI powered Digital Marketing- How AI changes
Strategic Sage Digital-The Professional Digital Marketing Company in Mohali.pptx
It Takes a Village Campaign Plan Book; Sidra Medicine
digital marketing courses online with od
5 free to use google tools to understand your customers online behavior in 20...
IREV Platform: Future of Affiliate Marketing
1 percent Clicks, percent Traffic Loss-Your SEO Stack Isn’t Built for AI

WordPress Security

Editor's Notes

  • #35: And there is no reason to keep a bunch of themes you do not use unless you run a WPMU site where users can select different themes
  • #36: And there is no reason to keep a bunch of themes you do not use unless you run a WPMU site where users can select different themes
  • #37: And there is no reason to keep a bunch of themes you do not use unless you run a WPMU site where users can select different themes
  • #38: And there is no reason to keep a bunch of themes you do not use unless you run a WPMU site where users can select different themes