Preciosas tips security and optimization for Wordpress
July 16, 2008 5 comments

With the launch of the new version of Wordpress, Wordpress 2.6, many bugs were corrijidos, many relating to the safety of the platform of blogging. Meanwhile, some extra measures can and should be taken to ensure a safe installation and inst á level of your blog, free of unpleasant surprises, such as exploits, invasions, loss of information and others.
Always be the last version of Wordpress and plugins
This is the tip simpler and easier and at the same time, the more intuitive and that virtually all to follow, without having to "think" a lot. As reviewed at the beginning of the article, whenever a new version of Wordpress leaves, in addition to the innovations and features a number of programming errors, bugs, and optimization in the codes are made.
Hence, it is always good to have installed the latest version of Wordpress and their plug-ins, since they also may submit any flaws that open loopholes and, not infrequently, endanger the instability, performance and safety and operation of an entire installation of Wordpress!
To keep updated Wordpress is simple: whenever a new version comes out, a warning appears in the administrative area. With the plug is no different, but we must often visit the page of extensions to receive notices of updates and make the automatic upgrade, available from two earlier versions of WP.
If the version of Wordpress, in itself, there are several ways to update:
- Download the latest version of Wordpress from the website and to update the manual;
- Using extensions of the WP to upgrade (as Wordpress Automatic upgrade and others);
- Some servers hosting rely on auto-update option.
Remembering always the "motto": back before, back when! ;-)
Use plugins for optimization and security of your blog or website Wordpress
There are thousands of plugins available for Wordpress; plug those that serve for the most diverse aims and purposes, from a simple enfeite in any area of your blog, to functions that, personally, believe that they should come by default in WP as options for optimization at the of SEO (by talking about it, contrary to what many think, the plugin All in One SEO Pack has not been discontinued), security and others.
So to address this on "native shortage" of Wordpress, it is recommended to use at least the following extensions:
- Akismet. The popular and known Akismet is one of the most used Wordpress plug. It prevents spam in the comments and messages of a possible attack by mass, in an attempt to sobrecarregamento and exhibition / create vulnerabilities. Utilizá it is binding in blogs and websites based on Wordpress;
- WP Security Scan. Using WP Security Scan is important because, as its name suggests, the plug is a battery of tests on their install Wordpress to detect any failure of security. This analysis of security, beyond the verification of vulnerabilities, even suggests corrective actions in the areas of passwords, permissions of files, security of the database, concealment of versions, among others;
- Optimize DB. The extension Optimize DB serves to improve performance and implement best and optimizations, in general, on the tables of the WP. With just a click examine the extension goes as the database and make the necessary improvements, providing a good increase performance;
- WP-DBManager. The WP-DBManager used strictly for tasks related to databases of Wordpress installation, allowing perform various activities such as optimizing, making backups and restores the database, delete and empty tables and data, conduct consultations and more personalized ;
- WordPress Database Backup. The extension WordPress Database Backup makes backups of databases of Wordpress install standard and also some of the tables that create plugins to work properly. It is possible to make a single backup, the time that he wants to, or schedule automatic backups, daily or weekly, which are sent to an e-mail account chosen.
Login Lockdown plugin
Outside the plugins cited above, which I consider essential for a safe installation of Wordpress, the installation of plugin Login Lockdown may also be useful. This plugin Login Lockdown, once installed, holds the IP address and timestamp of all the failed attempts to log in the control panel. Then, 3 failures of authentication in the period of 5 minutes, access to that specific IP administration panel is stopped for 1 hour.
Thus, if someone try to discover the password of the control panel WP so manually or through use of scripts that impregam the technique of brute force, that someone will have to face another layer of security and access to critical areas of your blog is more secure.
Secret Key
Many know that they can acquire a Secret Key to improve the safety of an installation Wordpress, although the team CMS often warn about the importance and necessity of having one.
First, acquire a secret key. After that, visit its base of files Wordpress and place to edit the file wp-config.php, the root of the plant. In it, simply add a line of code of his secret key.
Attention to the fact that each update of the page is generated a secret key Wordpress ú nica without repetition. I mean, store it carefully because if you lose yours, you will have to get a new one.
You have a Wordpress install secure?
Having a Wordpress install secure should be of concern anyone who has a blog or website based on the platform. Building bases safe and well-made is the first step to take in building a project of quality and long duration.
One of the first things to do when it installs a Wordpress is to make the following checklist:
- Take the latest version of Wordpress and always update the platform of blogging;
- Obtain a secret key and implement the line of code in the file wp-config.php;
- Make sure the version of the plug used is the latest and, if necessary, make the necessary updates;
- Install, configure and use properly the plugins cited for safety and optimization of Wordpress;
- Visit often to plug your page to see if any new versions came out and make the appropriate updates.
Following these steps is to provide a first step to have a good Wordpress installation, sound, reliable and secure, free, "azarões virtual" and ill intentioned people.
The next step is to keep current with Wordpress, visiting blogs that deal with the CMS, the discussion lists, forums or simply asking a friend who understand / enjoy more to warn about any major change or upgrade the security of Wordpress.
Doing so, certainly you can focus on what is most important in your blog: produce high-quality content and interact with your readers, providing a better experience and stability of access to those that prestigiam with the reading of your articles.
If you have any other hint, suggestion or macete to have better security in Wordpress, not acanhe to share with us! ;-)









Hello Tárcio. Another great article.
The safety of Wordpress and any blog is extremely important and often neglected by their authors.
Much attention it!
@ Paulo Faustino
Certainly, Paulo! Take at least these steps that are in the article and always stay connected in the updates is a good way to security and stability of Wordpress installation!
Abraços!
Trackback on July 16, 2008
Trackback on July 16, 2008
Trackback on July 16, 2008