{"id":3467,"date":"2018-08-01T12:51:13","date_gmt":"2018-08-01T10:51:13","guid":{"rendered":"https:\/\/lsbeta.szmigiel.design\/blog\/czy-wordpress-jest-bezpieczny\/"},"modified":"2018-08-28T14:21:09","modified_gmt":"2018-08-28T12:21:09","slug":"is-wordpress-secure","status":"publish","type":"post","link":"https:\/\/retro.szmigiel.design\/en\/blog\/is-wordpress-secure\/","title":{"rendered":"Is WordPress secure?"},"content":{"rendered":"<div class=\"easy-reading\">\nSome discussion forums or social networks may suggest that WordPress is not secure, that it has many vulnerabilities, that it is the target of many automated hacker attacks, and that it is therefore not a good platform for professional use. Depending on the portal, the number of such opinions may turn out to be overwhelming and it is easy to get the impression that, for example, a proprietary CMS will be a better solution.<\/p>\n<p>Given that the <strong>WordPress engine drives 59.9% of websites using content management systems<\/strong> and 31.4% of all websites at the same time, these allegations seem highly exaggerated (<a target=\"_blank\" href=\"https:\/\/w3techs.com\/technologies\/details\/cm-wordpress\/all\/all\" class=\"external\" rel=\"nofollow\">w3techs.com data <\/a> as of July 1, 2018).<\/p>\n<h2>The popularity of WordPress<\/h2>\n<p>According to the <a target=\"_blank\" href=\"https:\/\/trends.builtwith.com\/cms\/WordPress\" class=\"external\" rel=\"nofollow\">BuiltWith<\/a> portal for statistical analysis of the use of different technologies on the web, WordPress CMS is used by nearly 27 million websites. For comparison, a competitive, also free solution &#8211; Joomla! provides only 2 million pages. Drupal comes in third with a score of one million pages.<\/p>\n<p>Subjectively, WordPress very often wins over other content management systems in terms of ease of installation, operation, administration and expansion. Over the years of development of this system, a lot of commercial templates and plug-ins have appeared on the market, perfectly enhancing the possibilities that this CMS offers by default. <strong>It&#8217;s not difficult to transform WordPress from a blog platform into an online store, discussion forum, or news portal<\/strong>.\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2018\/08\/blog-bezpieczny-wordpress-medium-01.png\" alt=\"Czy WordPress jest bezpieczny? | szmigieldesign\" width=\"1080\" height=\"340\" class=\"alignnone size-full wp-image-3255\" srcset=\"https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2018\/08\/blog-bezpieczny-wordpress-medium-01.png 1080w, https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2018\/08\/blog-bezpieczny-wordpress-medium-01-512x161.png 512w, https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2018\/08\/blog-bezpieczny-wordpress-medium-01-260x82.png 260w, https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2018\/08\/blog-bezpieczny-wordpress-medium-01-50x16.png 50w, https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2018\/08\/blog-bezpieczny-wordpress-medium-01-150x47.png 150w\" sizes=\"auto, (max-width:767px) 700px, (max-width:1080px) 100vw, 1080px\" \/><\/p>\n<div class=\"easy-reading\">\nWhy do I write about this in my article about security?<\/p>\n<p>A very large number of pages based on identical source code increase the hypothetical return on investment in software, the aim of which will be to carry out automated attacks on the pages in order to obtain some benefit. In other words, <strong>it is more profitable to write a program that tries to break into 27 million pages than it tries to break into 2 million pages<\/strong>. However, this does not mean that WordPress is less secure than its competitors.<\/p>\n<h2>What is a prerequisite for WordPress security?<\/h2>\n<p>WordPress belongs to a group of programs called content management systems. From Wikipedia we will learn that the word &#8220;system&#8221; comes from the ancient Greek language and means &#8220;complex thing&#8221;. WordPress, as well as other content management systems, is a <strong> combination of specialized modules<\/strong>. Some of these modules (programs) come from other authors and become part of the system because&#8230; They perfectly fulfill their tasks and there is no need to create new, identical solutions.<\/p>\n<p>In addition, content management systems can be equipped with <strong>additional functionality <\/strong>, such as discussion forums, extensive contact forms, online shops, specialized content editors, interface elements and many more.\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2017\/12\/blog-na-co-zwrocic-uwage-medium-01.jpg\" alt=\"Na co zwr\u00f3ci\u0107 uwag\u0119 zlecaj\u0105c realizacj\u0119 strony www - szmigieldesign\" width=\"1080\" height=\"340\" class=\"alignnone size-full wp-image-2724\" srcset=\"https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2017\/12\/blog-na-co-zwrocic-uwage-medium-01.jpg 1080w, https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2017\/12\/blog-na-co-zwrocic-uwage-medium-01-512x161.jpg 512w, https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2017\/12\/blog-na-co-zwrocic-uwage-medium-01-260x82.jpg 260w, https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2017\/12\/blog-na-co-zwrocic-uwage-medium-01-50x16.jpg 50w, https:\/\/retro.szmigiel.design\/wp-content\/uploads\/2017\/12\/blog-na-co-zwrocic-uwage-medium-01-150x47.jpg 150w\" sizes=\"auto, (max-width:767px) 700px, (max-width:1080px) 100vw, 1080px\" \/><\/p>\n<div class=\"easy-reading\">\nAll of this patchwork of software, although it works under one banner, has many authors with different levels of experience and a different policy of updating and developing their software.<\/p>\n<p><strong>When each element of the system may have its own susceptibility to attacks<\/strong> resulting, for example, from the use of outdated software libraries, the author&#8217;s lack of knowledge or scruffy code (done in shortcuts, without good programming procedures).<\/p>\n<p>WordPress is used by amateurs who build their own websites, as well as by professionals who offer their services on a commercial basis. Both groups use templates and plug-ins in their work. However, it may happen that the <strong> choice of additional software is not well considered and the code of the final product includes plug-ins susceptible to attacks or abandoned by their authors<\/strong>, which in the next few months exposes the website owner to attacks.<\/p>\n<p>Although the responsibility for the problems lies with the plugins&#8217; authors or developers, the general public is of the opinion that the content management system is lacking. It is a bit like blaming a car manufacturer for its poor quality when the defects result from carrying out repairs using poor replacements instead of original or other high-quality parts.<\/p>\n<h2>How can I reasonably assess whether WordPress is safe?<\/h2>\n<p>We can divide the problem into layers and look at them separately:<\/p>\n<h4><span class=\"colored-text primary bordered\">1.<\/span>\u00a0System source code (WordPress)<\/h4>\n<p>WordPress is actively developed, and <strong>security fixes are installed automatically by default<\/strong>, without user intervention. A team of several dozen people works on the security of the system, and an additional contribution is provided by a wide community of users.<\/p>\n<h4><span class=\"colored-text primary bordered\">2.<\/span>\u00a0Source code for templates and plug-ins<\/h4>\n<p>WordPress owes its ever-growing market success to a wide range of plug-ins and graphical themes. The security of these solutions, however, is extremely diverse and <strong> most often outdated plug-ins are the vectors of attacks on websites<\/strong> based on WordPress CMS. It is worth carefully selecting extensions to your website, minimizing the number of add-ons and in the case of more extensive functionalities &#8211; use commercial solutions, the authors of which offer support and continuous development.<\/p>\n<h4><span class=\"colored-text primary bordered\">3.<\/span> Authors and administrators (owners) of websites<\/h4>\n<p>WordPress is a very accessible platform for building web pages, on which a lot of web guides have been created. However, system accessibility does not always go hand in hand with security. It is up to the author of the website to choose the additional software (plug-ins and templates), the complexity of the passwords and the configuration of the hosting environment. Lack of experience in this area may put the website owner at risk. Find out <a href=\"https:\/\/retro.szmigiel.design\/en\/blog\/what-to-look-for-when-ordering-a-website\/\"> what to look for when ordering a website<\/a>.<\/p>\n<h4><span class=\"colored-text primary bordered\">4.<\/span>\u00a0Hosting providers<\/h4>\n<p>Hosting companies offer different levels of security, and the configuration of server software is not the same everywhere. Unfortunately, many hosting companies require manual configuration of Apache web server, because the default settings allow you i.e. to view the contents of folders or access key files from external sources. <strong>It is advisable to take advantage of the hosting offer of a company that takes security issues seriously<\/strong> and provides an optimized configuration for popular content management systems.<\/p>\n<h2>Summary<\/h2>\n<p><strong>There is no ideal software, 100% safe.<\/strong> and free from errors. Even the software of the on-board computer of the lunar landing vessel Apollo 11 <a target=\"_blank\" href=\"https:\/\/www.space.com\/26593-apollo-11-moon-landing-scariest-moments.html\" class=\"external\" rel=\"nofollow\">had an error<\/a> which almost led to the cancellation of the mission.<\/p>\n<p>It should be remembered that websites based on content management systems are in fact extensive applications, often enriched with additional modules written by independent authors. <strong>Safety of the entire system is a result of the quality of the components from which it is built<\/strong>. Therefore, it is worth entrusting the website design to an experienced team, and complex solutions should be based on commercial modules, ensuring professional support. A valuable idea is also to invest in <a href=\"https:\/\/dhosting.com\" rel=\"noopener nofollow\" target=\"_blank\" class=\"external\">good hosting<\/a>, which will provide an additional layer of security.<\/p>\n<p>Follow my blog if you are interested in the security of WordPress &#8211; in the near future you will find articles about popular attacks on this CMS and a guide on how to reasonably secure WordPress without spending a fortune on it.<\/p>\n<p><div class=\"idea_box\" style=\"\"><div class=\"icon\"><i class=\"icon-lamp\" aria-hidden=\"true\"><\/i><\/div><div class=\"desc\">This entry has been automagically translated with <a href=\"https:\/\/www.deepl.com\/translator\" class=\"external\" rel=\"nofollow\" target=\"_blank\">DeepL translation services<\/a>. I&#8217;d like to apologize for any spelling, grammar or logical errors in the content. Please let me know in the comments below if you find any mistakes worth correcting.<\/div><\/div>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>You&#8217;re wondering if it&#8217;s worth running a website using free WordPress software, but you&#8217;ve read on the internet that it&#8217;s a bad idea? &#8220;WordPress is bad&#8221; is an unjust simplification. Read the article and find out why it&#8217;s not that bad.<\/p>\n","protected":false},"author":3,"featured_media":3253,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","footnotes":""},"categories":[138],"tags":[141,163,167,168],"class_list":["post-3467","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-websites","tag-security","tag-web-design","tag-wordpress-en","tag-plugin"],"_links":{"self":[{"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/posts\/3467","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/comments?post=3467"}],"version-history":[{"count":0,"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/posts\/3467\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/media\/3253"}],"wp:attachment":[{"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/media?parent=3467"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/categories?post=3467"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/retro.szmigiel.design\/en\/wp-json\/wp\/v2\/tags?post=3467"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}