There’s all sorts of reasons how hackers find targets to attack. The mere mention of WordPress is sometimes enough. I have a completely static site the mentions WordPress a few times and it gets all manner of WP hack attacks despite the fact there isn’t a single form on the entire site. Just registering a new domain name seems to be an invitation for hackers to probe the domain’s site for vulnerabilities.
It seems all plugin vulnerability probes are for long ago patched vulnerabilities. If you’ve kept your plugins updated and they are regularly maintained by the authors, there’s not any reason for concern. Sure, there could be a zero day vulnerability, but that’s highly unlikely.
Brute force attacks do not leverage plugin vulnerabilities anyway. As long as all admin users use good strong passwords, there’s nothing to worry about from brute force attacks. Hack attacks happen, it’s part of having a website. Beyond having your security measures in place, there’s little need for concern. If you also keep good backups (you need to do this if you aren’t), and your DB does not contain anyone’s sensitive personal information, then there really is nothing to worry about.
]]>I’ve looked over hardening wordpress and going to watch a video by Brad Williams about security (https://wordpress.tv/2010/01/23/brad-williams-security-boston10/) but I think I’ve done just about all I can do. Thanks for the helpful advice.
]]>