An open community 
of Macintosh users,
for Macintosh users.

FineTunedMac Dashboard widget now available! Download Here

Previous Thread
Next Thread
Print Thread
Building a WordPress Site - Advise?
#40830 06/02/16 11:55 PM
Joined: Aug 2009
OP Offline

Joined: Aug 2009
Do I need Jetpack? Are there add-ons you recommend? We are using Tiny Framework template.

Re: Building a WordPress Site - Advise?
slolerner #40832 06/03/16 05:10 AM
Joined: Aug 2009
Likes: 1
Offline

Joined: Aug 2009
Likes: 1
You only need Jetpack if you want any of its features. It's part of a standard WordPress install, but you don't have to enable it.

Biggest advice: KEEP IT SECURE. If you fail to install security updates in a timely manner, it will get hacked. It doesn't matter how small, inconspicuous, or obscure it is. Organized criminals use special tools that search the Web for vulnerable WordPress sites and hack them automatically, and then use them to plant viruses and malware, host phony bank pages, and host other content that they can not legally host anywhere.

Also, use really strong passwords for your administrator users. If you use weak passwords, again, you will be hacked--it's not a matter of if but a matter of when. I guarantee your site will be attacked.

If you run WordPress you absolutely MUST keep on top of security. I recommend tow free WordPress plugins for everyone who uses WordPress:

1. Wordfence Security: https://wordpress.org/plugins/wordfence/

This free plugin will harden your site. It will email you to let you know of security updates, it will install an automated firewall, it will prevent brute-force hack attacks, and it will cut off anyone who tries to use a known Wordpress compromise.

2. WPS Hide Login: https://wordpress.org/plugins/wps-hide-login/

This free plugin has one purpose: It will move your WordPress login page from wp-login.php to anything you want (such as yoursite.com/my_secret_login_page). This will prevent people from attempting to hack your site by brute-force guessing passwords.

Running a WordPress installation without these plugins is begging for trouble.


Photo gallery, all about me, and more: www.xeromag.com/franklin.html
Re: Building a WordPress Site - Advise?
tacit #40836 06/03/16 12:04 PM
Joined: Aug 2009
Offline

Joined: Aug 2009
Originally Posted By: tacit
Running a WordPress installation without these plugins is begging for trouble.

From all the hacking of Wordpress that I've seen over the years, running Wordpress seems to be what is "begging for trouble"?

But I suppose this is more a case of selling a product to the masses as a "web site anyone can run" when it requires at least some due diligence and technical investment to keep it from being hacked is the core of the problem. It's not as effortless as a "one click install" as they would have you believe, and too many people seem to think it is.

"(YES/NO) Wordpress doesn't require any technical skill to install and use, anyone familiar with a computer can run it" I'm pretty sure that at least a quarter of the people running wordpress would select YES, because that's what they understood about it and why they bought it. They're not technical people and they want to run a website anyway, and this product appears to deliver that. Not sure if that's mainly the customer's fault, WP's fault, or a fairly even split of responsibility?


I work for the Department of Redundancy Department
Re: Building a WordPress Site - Advise?
Virtual1 #40843 06/03/16 03:02 PM
Joined: Aug 2009
OP Offline

Joined: Aug 2009
Quote:
You only need Jetpack if you want any of its features. It's part of a standard WordPress install, but you don't have to enable it.

So I should install it? Is not automatically installed. Is there any downside or conflict with the ones recommended?

Thanks for all the advice and links. It is a domain I bought for a friend so she has kind of a hobby learning WordPress. Its got SSL and Sitelock but I will install the security software recommended above.

Last edited by slolerner; 06/03/16 03:04 PM.
Re: Building a WordPress Site - Advise?
slolerner #40866 06/07/16 05:59 PM
Joined: Aug 2009
Offline

Joined: Aug 2009
Originally Posted By: slolerner
So I should install it? Is not automatically installed. Is there any downside or conflict with the ones recommended?

Every time you install another bell/whistle/feature, you add another outside door to your house. Even if it's locked, it's still another door. You're increasing what's called the "attack surface". Every door has a different kind of lock on it. If someone finds a way to pick a certain kind of lock, the more doors you have on your house, the greater the odds that someone can now get in. It also makes it more difficult for you to keep track of, and remember that "oh yeah, I have that, I installed that two years ago, I better get that patched!"

So as a general rule, when running a server, disable all unnecessary services. (and don't add new ones unless you need to) IMHO, this goes double for anything marketed to "non-technical users".


I work for the Department of Redundancy Department
Re: Building a WordPress Site - Advise?
Virtual1 #40870 06/07/16 10:01 PM
Joined: Aug 2009
OP Offline

Joined: Aug 2009
Thanks V1 and Tacit. This really helps.


Moderated by  alternaut, dianne, MacManiac 

Link Copied to Clipboard
Powered by UBB.threads™ PHP Forum Software 7.7.4
(Release build 20200307)
Responsive Width:

PHP: 7.4.33 Page Time: 0.019s Queries: 26 (0.012s) Memory: 0.5945 MB (Peak: 0.6688 MB) Data Comp: Zlib Server Time: 2024-04-19 11:29:06 UTC
Valid HTML 5 and Valid CSS