4 ms·
The blog of WordFence has been quite informative over the years. Many plugins, and even WordPress Core, have had security issues. Some really bad ones get used
by mpol 4y ago
The blog of WordFence has been quite informative over the years. Many plugins, and even WordPress Core, have had security issues. Some really bad ones get used from a very early stage. So I do think there is some merit in being more on top of it. Updates and backups are also part of your strategy, being hacked and having to comb through the live database for 'eval()' and 'base64()' and other scary stuff is not that great.
The thing about mod_security is that it is server based. If you are on a shared host you have no control over this and every shared host has a different setup. And if you maintain the server, well, mod_security is not that easy to get right and to stay on top of things. Wordfence adds its own weaknesses ofcourse, it is more code that needs to be vetted. But for recognizing an intrusion or hack, it can work quite well I think. (haven't been hacked in years). This thing about server or account based is similar when it comes to caching of generated html pages, Varnish is server wide, a plugin is WP wide.
- Tijdreiziger 4y agoThanks, I'll check out the Wordfence blog! I'm definitely trying to stay on top of updates and backups (nobody had been maintaining it before I took over, so the update situation was dire). Yeah, since the performance on the current host is dire, I've been debating whether to go with another shared host or to just go the VPS route. The company wants to get into Microsoft 365 for e-mail/files, so maybe Azure is another option. I'm okay with spending some time setting things up, but I definitely don't want to have to put a lot of effort into ongoing maintenance.