Files left sitting in your WordPress directory can be dangerous—here’s why.

Files left sitting in your WordPress directory can be dangerous—here’s why.

Here, we’ll explain the security risks posed by various files left sitting in your WordPress directory.

Read more

A type of backdoor—one without an actual malware file—that has been wreaking havoc on WordPress sites recently

A type of backdoor—one without an actual malware file—that has been wreaking havoc on WordPress sites recently

We will explain a type of backdoor—one that lacks a main malware component—which has been running rampant on WordPress recently (and for which we have confirmed a large number of infections).

Read more

What to Do If an Unfamiliar Administrator Has Been Added to WordPress

What to Do If an Unfamiliar Administrator Has Been Added to WordPress

If an unfamiliar administrator has been added to WordPress, we’ll explain how to determine whether that administrator is unauthorized and what steps to take.

Read more

What are the countermeasures when the era of AI attacking WordPress arrives?

What are the countermeasures when the era of AI attacking WordPress arrives?

Here, we’ll explain how to prepare for the era when AI starts attacking WordPress.

Read more

How to Handle a Large Number of "Unfamiliar URLs" or Accesses to the "Login Page" in Your WordPress Access Logs

How to Handle a Large Number of “Unfamiliar URLs” or Accesses to the “Login Page” in Your WordPress Access Logs

Here’s how to handle situations where your WordPress access logs contain a large number of “unfamiliar URLs” or “login page” entries.

Read more

Practical Workflow: From the Public Disclosure of a WordPress Plugin’s CVE to Identifying the Scope of Impact Within the Company and Implementing Emergency Measures

Practical Workflow: From the Public Disclosure of a WordPress Plugin’s CVE to Identifying the Scope of Impact Within the Company and Implementing Emergency Measures

We will explain the practical workflow—from the public disclosure of a WordPress plugin’s CVE to identifying the scope of impact within the company and implementing emergency measures.

Read more

Does Changing the Table Prefix in a WordPress Database Really Help? An Analysis Based on Actual Attack Logs

Does Changing the Table Prefix in a WordPress Database Really Help? An Analysis Based on Actual Attack Logs

Is Changing a Database Table Prefix Really Effective? Let’s Examine This Using Actual Attack Logs.

Read more

An Explanation of How to Monitor and Respond to WordPress Vulnerabilities Within the Company

An Explanation of How to Monitor and Respond to WordPress Vulnerabilities Within the Company

Here, we’ll explain how to monitor and respond to WordPress vulnerability information within your organization.

Read more

WordPress Malware Infections: Typical Patterns of Malicious Code Embedded in `wp_posts` and `wp_options`, and How to Distinguish It from Legitimate Code

WordPress Malware Infections: Typical Patterns of Malicious Code Embedded in `wp_posts` and `wp_options`, and How to Distinguish It from Legitimate Code

We’ll explain typical patterns of malicious code embedded in WordPress’s `wp_posts` and `wp_options` tables as a result of malware infection, as well as how to distinguish it from legitimate code. Malware Infection and Tampering of the WordPress Database In the event of a malware

Read more

How can I prevent a site-wide warning from appearing due to a failure in the automatic renewal of free SSL (Let's Encrypt)?

How can I prevent a site-wide warning from appearing due to a failure in the automatic renewal of free SSL (Let’s Encrypt)?

Here’s how to prevent site-wide warning messages caused by failed automatic renewals of free SSL (Let’s Encrypt).

Read more

Regarding the Issue of WordPress Security Measures Being Overly Focused on Login Protection

Regarding the Issue of WordPress Security Measures Being Overly Focused on Login Protection

I’d like to discuss the issue that security measures for many WordPress sites tend to focus too much on protecting the login process.

Read more

Steps to Regain Administrator Privileges After the Person in Charge of a WordPress Site Outsourced to a Production Company Has Resigned or Closed Their Business

Steps to Regain Administrator Privileges After the Person in Charge of a WordPress Site Outsourced to a Production Company Has Resigned or Closed Their Business

Here’s a guide on how to regain administrator privileges after the person in charge of your WordPress site—which you had outsourced to a production company—has resigned or gone out of business.

Read more

The Site Looks Normal, but Search Results Are Flooded with Product Pages and Chinese Text—Detecting and Completely Removing SEO Spam

The Site Looks Normal, but Search Results Are Flooded with Product Pages and Chinese Text—Detecting and Completely Removing SEO Spam

The site looks normal, but search results are flooded with product pages or appear in Chinese—here’s an explanation of how to detect and completely remove SEO spam.

Read more

How can I restrict access to my WordPress site to my own country only?

How can I restrict access to my WordPress site to my own country only?

Here’s a guide on how to restrict access to your WordPress site to your own country.

Read more

Essential Security Measures for Sole Proprietors Who Create or Customize Their Own WordPress Themes

Essential Security Measures for Sole Proprietors Who Create or Customize Their Own WordPress Themes

In this article, I’ll explain the minimum code-level security measures that sole proprietors who use custom WordPress themes (or themes custom-built by a development company) should implement.

Read more

If You Think Your Site Is Slow, It Might Be a Brute-Force Attack—or a DDoS Attack: How to Spot an Attack and Countermeasures Even Small Sites Can Use

If You Think Your Site Is Slow, It Might Be a Brute-Force Attack—or a DDoS Attack: How to Spot an Attack and Countermeasures Even Small Sites Can Use

If you think your site is running slowly, it might actually be a brute-force attack—or a DDoS attack. Here’s how to identify these attacks and what measures even small-scale sites can take to defend against them.

Read more

Google labeled my site as "dangerous"—The actual steps to have the Safe Browsing warning removed and the reality of the review process

Google labeled my site as “dangerous”—The actual steps to have the Safe Browsing warning removed and the reality of the review process

If Google displays a “This site is dangerous” warning, we’ll explain the actual steps to have the Safe Browsing flag removed and the reality of the review process.

Read more

Slider Revolution (RevSlider) case study shows the real risk of "plug-ins that are out of license or have been moved to paid for".

Slider Revolution (RevSlider) case study shows the real risk of “plug-ins that are out of license or have been moved to paid for”.

Slider Revolution (RevSlider) case study will explain the risks of “plug-ins that are out of license or have been moved to paid” and how to deal with vulnerabilities of such plug-ins.

Read more

Page 1/20