My Location:
Poole, Dorset, UK
Availability:
View my Calendar
Email or iMessage:
hello@websiteright.co.uk

Recently I got scammed out of £200. Here’s how to stop it happening to you.

Recently I got scammed out of £200. Here’s how to stop it happening to you.

When I started out in business, I had an 80/20 policy of prioritising the building up of my own website, whilst taking on a little bit of work here and there to pay the bills – “playing the long game”, you could call it.  

As time has gone on, with my own website completed and new clients coming on board on a weekly basis, the ratio swapped to a 20/80 approach – that is, spending 80% of my time on “work”, and 20% of it on my own website marketing in order to keep it ticking along.  However, as with most things, the best intentions can often end up on the back-burner – and whilst I was becoming incredibly busy, as a result I had not been keeping on top of my own website, thus putting my own site monitoring & marketing on the “later-base”

Sadly, to my own cost, I realised that a hacker managed to exploit a vulnerability on my own site, and managed to change the recipient Paypal email address for my online payment system.

Not “keeping on top” of your own site can not only be bad for search engine optimisation, but it can also cause a whole number of issues with platform, plugin, and theme security. Sadly, to my own cost, I realised that a hacker managed to exploit a vulnerability on the site, and managed to change the recipient Paypal email address for my online payment system – meaning that a £200 transaction that was supposed to go to me, went to somebody else.

New WordPress Sites Every Day
500
And counting!
In fact, it has over five times the installs of its nearest competitors.
Global WordPress Share
56
percent.
Over half of the world’s installed websites use WordPress.

Paypal is just one of a number of forms of payment that I accept, as I feel that it is important to be able to present a wide range of options to my clients. As well as providing Credit/Debit card via Stripe, BACS and Apple Pay – Paypal often gives users peace of mind with entering their payments online.  Thankfully, on this occasion, my wonderful client sent me an email detailing their transaction, with concerns about the validity of the recipient email address.  Within a few phone calls I managed to get on to Paypal to have the transaction turned around, however subsequently, it then made me want to focus on the security needs of my own website.

In terms of locking my site down, before the hacking took place, like most webmasters, I took precautions in a number of ways. For example, there were a number of free and paid for plugins that would detect a large proportion of hacking attempts, and I made sure all the basics were adhered to including password strengths and changing default logins.  It soon however became clear that there were other security holes that were penetrated which were very much higher-level – beyond the realms of the majority of website developers. They were extremely eye-opening, and very concerning, so I soon considered myself fortunate that the transaction wasn’t of a higher value!

I subsequently brought in a hosting and security expert to assist with fixing errors who gave me advice on the best ways to lock down your website.

I used this glum realisation to bring in a hosting and security expert to assist with fixing errors and to give me advice on the best ways to lock down your website. I learnt the different techniques that hackers use to exploit a website is astonishing!  After having days of intensive training, in conjunction with the world’s leading website security experts, I decided to turn the negative into a positive by creating a WordPress Security Analysis service which can prevent these issues happening to anyone else. It is a one-time service which gives your website a full health-check, but then goes on to scan your website every day for exploits and vulnerabilities.

The service is ideal for anyone who uses WordPress to process transactions online – and provides peace of mind that your website remains a secure location for clients to be able to order successfully, without their details being compromised.

For anyone else though, security still should be considered absolutely vital, therefore I have provided some of the more basic tips that are advisable for securing your WordPress installation below – these should be adhered to as a minimum!

TIPS TO LOCK DOWN YOUR WORDPRESS SECURITY

  • Improve your password security. Make it a minimum of 12 characters and involve special characters, mixed case letters, and numbers.
  • Go through your Users list regularly, and ensure that there are not any editors or administrators that you do not recognise.
  • Do not use Nulled Plugins, and ensure that each and every plugin that you are using is up to date. Similarly, keep WordPress and the themes updated whenever a new version is released.
  • Use a Child theme if you are making any theme amendments, do not edit the main theme or core code, as you may be opening up vulnerabilities.
  • Change your WordPress username from “admin” to something that is not default – this means there are two parts for a hacker to guess and not one!
  • Enable the free Wordfence plugin on your install of WordPress, which will block IP addresses which persistently try to login to your site – as well as blocking any well know spammy IP addresses.

These six tips can significantly help to improve the security of your website, however as aforementioned, if you’re a site that takes transaction online and/or stores users data, you’d be advised to check out my WordPress Security Analysis service – which will make your installation bulletproof!

Contact Me For More Information


mm

I am fanatical about providing useful web experiences, via bespoke websites which engage, inform and entertain. I have been making websites since a young age, and am a keen supporter of AFC Bournemouth.

Leave a Reply

Your email address will not be published. Required fields are marked *

Call Now on 01202 232553