WordPress Hacks/Defacing [closed]

Even when WordPress is running version 3.1, sites are still being defaced. Even? There had been one major and five security releases since that version. If you are implying that 3.1 should be reasonably secure – it is not. but the only answer seems to be outdated WordPress sites What had you done to exclude … Read more

My site appears to be hacked [closed]

Look at all of the ‘related’ links to the right of your question for help with a hacked site. I would reinstall everything (WP, themes, plugins), check htaccess files (in all folders, not just the site root folder), change all site access passwords (ftp, host, email), check your local computer, look for unexpected files (in … Read more

Should WordPress Add Options to Enhance Security or Leave it to plugin developers? [closed]

RE: Username – admin Since version 3.0 the installer asks the user to provide a username for the main account, you obviously won’t get this option if you upgrade from an older version(because it’s not a new installation). You can see an image of this here: http://codex.wordpress.org/Installing_WordPress#Step_5:_Run_the_Install_Script RE: Blocking malicious users There’s no real effective … Read more

WP Site Hacked, Serp Google Spam [closed]

I’ve cleaned up a few hacked sites, and have developed my own personal procedure here. But there are many googles on how to clean up. The basics are change the passwords of everything (hosting, database, FTP, users), reinstall WP and all themes/plugins from a known good source (WP repository), and manual inspection for bad files. … Read more