A while back, I started using WPMUDEV’s Defender Pro plugin for security on all my WordPress sites. I made a decision this week to switch to WordFence. The conversation was forced on me, because I had a site using Defender Pro that was hacked. I do not blame Defender Pro for the hack, however, this hacking incident caused me to re-think my WordPress security strategy a bit.
Almost all of my sites utilize a server-based Web Application Firewall – the site that was hacked does not, as it’s on a different infrastructure from the others. Put simply: WordFence has a Web Application Firewall (WAF) built into the plugin, whereas Defender Pro does not. I don’t know for a fact that the WordFence WAF would have protected me in this case, but it’s very possible it would have saved the day.
For the record, Defender Pro does a fine job of scanning your site for hacked files – in fact, their scans are very comparable to WordFence’s scans. But Defender Pro does not proactively protect your site from malicious folks in real time. Since this most-recent hack, I even upgraded all my sites that do not have a WAF to the WordFence paid tier, which provides some additional real-time checks to keep the bad guys out of the site.
More posts from themightymo.com
As part of our summer celebration, we want to offer you this package at a great price: $499 – WordPress blog or website – Theme customization – Hosting for a year – Domain registration or transfer This is a great deal for anyone looking to get started with a great website! Contact us today!
Hello! I am excited to introduce “TheMightyMoo!”, our first WordPress theme template available for free download and public consumption! YEAH!!! HUZZAH!!! *celebration* To see it in action, visit Net Impact Minneapolis and TobyCryns.com. Here is a screenshot of the default installation: TheMightyMoo! is a fully-customizable accordion theme that uses the MooTools framework to display posts.…