You Must Have a Security Plugin for WordPress
Over the last 36 hours I have received over 14 emails like the one below that come from WordPress iThemes Security Plugin. Over the last few weeks I have been working on SEO keywords in posts for a one site in particular to see how the stats and page rank rise as opposed to a few different things I did in the past. As I am still digesting some of the data I have ranked well for a few keywords which of course raises the visibility. Yet, with that increase visibility comes the hackers.
As I have mentioned before a security plugin is the first I install and then of course a backup plugin. The first thing I do is change the user name and set the login attempts to lock out.
Each and every email like the one below the hacker used the user name "admin" which is the WordPress Installers default user name at setup.
Security Generated Email
------------------------------------------------------------------------------
A user, admin, has been locked out of the WordPress site at http://www.workoutswithdumbbells.com due to too many bad login attempts.
The user has been locked out until 2014-11-02 05:28:05.
To release the lockout please visit the lockouts page.
*This email was generated automatically by iThemes Security. To change your email preferences please visit the plugin settings.
-----------------------------------------------------------------------------
Get a Security Plugin and change the user name.
Stay secure, Enjoy Success
-Kevin Wiley
Recent Comments
10
Thanks!! Have received loads of those emails yesterday and wasn't sure what its about. Going to change my user name now!!
Excellent, Lilly
When they know the username is "admin" they are so much closer to hacking your site. The "lock out" function is awesome. Setup for 3 tries and locked out. They just give up and move on to someone who hasn't done what you are. Even hackers have "bots" (robot scripts) that just go from one site to the next.
They won't work on ours will they! :)
If you're already getting the "lock out" emails it must have been the automatic setup when you installed and activated the plugin. Sounds like you're all set. iThemes Security is pretty in depth. After the initial setup to get protected, I try to digest a little bit at a time to fine tune it for each site.
Cool. I have installed it weeks ago, you suggested it to someone in a blog post and I went straight over to Wordpress. :)
See more comments
Thanks for sharing this.