Documentary encyclobjects: 08 Security and maintenance

Earn 10.00 Reward Points by commenting the blog post
Documentary encyclobjects: 08 Security and Maintenance
If we look at the passage of time, every day, people and companies dedicate more resources to safety and security. This is true in all areas of life.
Personally, we have insurance for our house, our car, our dog, our health, etc… Professionally, controls and processes are also carried out to obtain correct levels of safety and maintenance of the facilities for their optimization over time.
This set of actions and measures must also be carried out in our WordPress. We need security on our website, to protect it from hacker attacks, malicious software and annoying spam. We must also provide security and confidence to our users, updating and optimizing our website, both in its loading times and in the features and interaction options.
In short, good risk management is important. This is what we are going to talk about in this chapter.
Security strategies
To carry out proper risk management in our WordPress, we first need to evaluate the risks that we may encounter and, subsequently, protect our website with the appropriate tools. That is, carry out a security strategy. Do it, the sooner the better. You will not regret it and you will work more calmly.
When I started the project I installed a security plugin (Sucuri), a plugin to control brute force attacks and logs (Limit Login Attemps Reloaded), another plugin to control spam (Akismet) and, in addition, I had the security tools that my previous hosting (Ionos) gave me. Too many tools (some of them very complex) and too much work.
I needed to simplify.
Everything changed with hosting on Siteground and installing their Security Optimizer plugin, an extraordinary all-in-one security plugin that’s easy to set up and a full-time worker.
For spam I activated Google reCAPTCHA v3, which is the one that causes the least inconvenience to the user.
With these 2 tools I solved the security of my WordPress, and I started working with more peace of mind.
Specifically, although it is impossible to have zero risk, it is possible to have good tools to make it very difficult for the “bad guys”. Let’s see how these tools work:
On the part of the Security Optimizer plugin, we control the following aspects:
– Site Security: Protects system folders . Hide the WordPress version. Turn off the theme and plugin editor . Disable the XML-RPC file. You can disable RSS and ATOM feeds (in our case we enable them to favor users who follow us via RSS) Enable advanced XSS protection . Delete the Readme.html file by default.
– Access security: Custom access URL . Login access limit (of URLs suspected of brute force attack). Identification of 2 access factors for administrators and editors. Deactivation of “common” usernames. Limitation of the number of access attempts (in our case, 3).
– Activity log: At all times we will have a record of the IP addresses that visit our website (type of visitor, IP, page visited and server response). We will be able to block the IP or see its activity. We can also order the registration by registration IP, by blocked accesses, obtain weekly reports and receive the activity log by e-mail.
– Actions of a hacking action: We will be able to reinstall all the “free” plugins , force the password reset to the users and disconnect all the users.
On the part of Siteground hosting (GoGeek) we have the following tools:
– Backup: Daily (possibility to restore files, database and e-mails). Create backup (always keeping 5 active), restore and download.
– SSL Manager: for each domain with Let’s Encrypt Wildcard
– Force HTTPs: for all domains, presenting all our pages securely.
– Protected URLs: If we wish, we can include URLs that are specially protected to prevent access to any user.
– Blocked traffic: We can block IP addresses or all IP addresses from any country.
– Site Scanner: Siteground’s optional tool that scans our website daily for threats. Check if our domain is blacklisted and all our URLs and files for malware. Reports automatically.
Backups
What would we do without backups? I don’t know, the fact is that we, on some occasions, have had our jobs saved.
Without a doubt, it is the security tool par excellence.
Having a hosting with good backup management is essential today.
But, don’t worry, good hosts, such as Siteground, maintain excellent backup tools .
In our case, our hosting provides us with a backup daily , so that, in case of problems, we can always go back to the previous day, losing only the work of the current day. It is advisable not to relax and, in addition, before updating plugins, themes, changing PHP version or including any additional software on our server, make an additional backup. This will allow us to react immediately to any incident that may arise. There are few minutes of caution that can save us the work done.
Siteground will always keep the last 30 backups visible, being able to go back up to a month if necessary. From each stored copy we can restore files, databases and e-mails. We can also download and install them in another environment. We also have a history of restores and downloads.
Optionally, on demand (e.g. on very high-traffic sites), backups can be performed every hour.
Upgrades and maintenance
WordPress, as you know, is one of the so-called “open source” software. That is, when we work in WordPress, we can modify the source code of the application. Thus, in this way, WordPress has risen to number 1 in the world CMS (Content Management Systems) software.
Periodically, by applying new features, rectifying errors or applying security patches in the event of vulnerabilities, WordPress is updated. This task is VERY IMPORTANT and it is necessary that you follow the update instructions that, periodically, WordPress will leave on your website to keep it always, always, UPDATED.
The same happens with the plugins and themes that we are using. They also make updates and require us to incorporate them into our website. It is the best way to keep everything in order, free of vulnerable elements and with the maximum possible performance.
It is convenient, just after updating our website, to visit it and check that our front-end is correct.
We would then say that, like any software, like any company, our website also needs a maintenance program. Basically, a serious maintenance program for WordPress should contemplate the following points:
– Permanent updates: As soon as possible, both of WordPress and of themes and plugins.
– Daily monitoring of the health of the site: Visualizing the messages and dealing with each warning that is presented to us.
– Monthly web performance monitoring: Using tools such as Page Speed Insights.
– Monthly SEO monitoring: Through tools such as Google Search Console or Bing WebMasters.
– Monthly traffic monitoring: Through tools such as Google Analytics.
Optimization and performance
But as man does not live by bread alone and, to close the circumference, we need to take action to optimize the performance of our website and provide our users with the best browsing experience. This is a long-distance race and requires that we prepare our website, from the beginning, in healthy practices, application of media and appropriate software for its proper functioning.
As in SEO, a good WordPress optimization is best achieved through a good plugin. At first, without a doubt, I put myself in the hands of WP Rocket. This cache, CSS, and image optimization plugin is one of the most widely used and achieves very good loading times. I have even used it coexisting with Siteground’s Speed Optimizer and, although with some problems (Divi is also responsible), I have kept it until recently, when I have preferred to continue only with Siteground’s Speed Optimizer.
Siteground makes some very complete plugins. Both Security Optimizer and Speed Optimizer, apart from being complete, work perfectly. In other words, what they do, they do well, and this, in WordPress, is very interesting. I know it seems like a truism (a fictional character who is attributed with presenting the obvious in a sententious way), but as Fernando Tellado would say: “you can’t have everything”.
The fact is that, with Speed Optimizer I have achieved a good balance and, although there is room for improvement, I have decided to wait for the release of Divi 5 to see how to adjust the 3 tools (Divi, Speed Optimizer and WP Rocket).
Let’s see what settings Speed Optimizer provides us:
– Cache settings: NGINX server cache accelerator, file cache settings (preheated every 12 hours), and Memcached object cache. Smart cache flushing , manual flushing, exclusion of certain URL’s from the cache, exclusion of contents from the cache (if required) and browser-specific cache (not applied, slows down a bit). In addition, you have a tool that can check if any URL on your website is cached or not.
– Environment settings: forced HTTPs (secure connection), insecure content corrections (if presented), WordPress Heartbeat optimization, checking post editing pages every 15 seconds and your desktop and front page every 60 seconds (disabled in our case due to high consumption of server resources) and scheduled database maintenance (weekly cleaning).
– Front Page Settings: Minifying CSS files, merging CSS files, and preloading CSS files. Minimize, merge, and defer Javascript files. Minimize HTML output, optimize web fonts, preload fonts , remove static file strings, disable emojis , and external DNS preloads.
– Media Settings: image compression, WebP image usage, lazy loading media, excluding CSS from lazy loading and maximum width of images (1920 px).
– Site Performance Dashboard : Page Speed Insights checker and history.
On the side of our Siteground hosting, and optionally, we have another powerful tool to optimize the performance of our website. It involves offering our website through CDN (Content Delivery Network), which stores our website on several servers around the world to display our site from the server closest to the visitor, reducing loading times considerably.

