A Detailed Overview Of Our Security Strategy

Table of Contents

Many WordPress Managed Hosting providers often promote ‘Enterprise-Grade Security’ to describe their infrastructure, but they typically don’t explain the specific measures they take to protect your site and data. In contrast, we believe in transparency, which is why we outline every step and action we take to safeguard your websites. Additionally, our security settings can be easily adapted to fit nearly any WordPress installation with just a few adjustments. If you’re not hosting with us, feel free to replicate it on your own server.

Without further ado, here’s a clear and straightforward overview of the comprehensive measures we implement to ensure the safety and reliability of your sites:

1. DNS: Cloudflare

DNS management is the foundation of every online service, and Cloudflare stands out as the fastest and most reliable provider. Acting as the first line of defense for your site, it sits in front of all access attempts. In addition to its strong default settings, Cloudflare offers crucial features such as DDoS protection, bot mitigation, and a Web Application Firewall (WAF) with a complimentary managed ruleset.

We implement the following non-default customized settings:

SSL/TLS (Edge Certificates):

  • Configure encryption mode: Full (Strict)
  • HTTP Strict Transport Security (HSTS): On
  • Certificate Transparency Monitoring: On

Security (WAF – Custom Rules):

  • Managed/JS Challenge on wp-login.php;
  • Region lock /wp-admin to the countries you access from;
  • (Rate Limiting) Authentication requests that make use of leaked passwords;

Security (Bots):

  • Block AI Bots: On

Rules (Configuration Rules):

  • High Security Level on /wp-admin;

Scrape Shield:

  • Hotlink Protection: On

2. Datacenter: Contabo

We exclusively use Contabo as our data center provider. This German company boasts over 20 years of experience and, according to their own words, implements ‘RBAC rules across the entire company, 24/7 surveillance, and layers of security measures.’ Most importantly, they offer DDoS protection on every server, adding another crucial layer of security to our stack.

Moreover, we deploy one virtual machine for each WordPress installation. This approach ensures proper isolation and eliminates the risk of contamination spreading from one infected site to another.

3. Server: Ubuntu + WordOps

Ubuntu 22.04 is our preferred Linux distribution for default installations. It is widely used on servers, has proven to be very reliable over the years, and boasts a strong community.

In addition, we leverage WordOps to manage our servers and WordPress sites. This tool comes packed with security directives by default, including:

  • SSH Hardening: no password and root login (WordOps actually permits root login without password, but we disallow it), servers can be only accessed using SSH keys by select users;
  • Brute-force Prevention: Fail2Ban block access to intruders that keeps failing to authenticate;
  • Firewall: UFW only allow access to relevant ports used by the web-server and block access to everything else;
  • SSL: Cloudflare DNS API or Let’s Encrypt certificates, TLS v1.3 with HTTP/3 QUIC;
  • Antivirus: ClamAV with database updated weekly. We actually use clamdscan – which is not included with WordOps – cron scheduled weekly. (still working on this)

We also utilize external tools to assist with day-to-day server activities:

  • Uptime Monitoring: We keep an eye on uptime metrics with the help of updown.io, which alerts us via real-time messaging of any downtime.

4. WordPress

We always install the latest WordPress version and keep it, as well as any plugins installed, updated automatically.

WordOps takes care of securing WordPress with all the best practices and we harden it with additional measures:

  • WordPress main configuration file (wp-config.php) is moved one directory up from the default place (htdocs);
  • Authentication errors are obfuscated by default, returning a generic error.

Security features provided by plugins:

  • Password Hardening: WP Password Bcrypt by Roots is installed as a mu-plugin (must use plugin) and takes care of encrypting passwords using bcrypt, the strongest hashing function available in PHP;
  • 2FA (Two-factor Authentication): Wordfence Login Security provides outstanding support for 2FA using any TOTP-based authenticator app. Available to all users, including customers who only access the frontend, and enforced to admins;
  • Session Management: By default, WordPress will logout users – by cookie expiration – after 48h or 14 days if the “Remember me” option is selected. We lower both values to 1 day for admin accounts, allow no more than 1 session and terminate idle sessions after 4 hours, using the aptly named Sessions plugin, part of the great PerfOne suite of plugins. Any user role can have any combination of session timeout. Simple Login Notifications is enabled for all accounts, instantly alerting users of any login. This behavior decreases the window of opportunity for any attempt at cookie hijacking;
  • Anti-spam: Cloudflare Turnstile is applied to every compatible input with Simple Cloudflare Turnstile, including de default login and registration forms;
  • Activity Monitoring: Simple History tracks and logs any activity within WordPress and presents them in a nice interface;
  • Backups: UpdraftPlus. See more below;
  • Virtual Patching: Patchstack. See more below.

5. Backups

We employ a 3.5 layered approach to backups:

  • Datacenter: Weekly snapshots of the virtual machine, stored in Contabo. We keep the most recent available copy and it will be used only if all the other options fail;
  • Server: An automated backup of the database and files inside /var/www/ runs before any changes are made through WordOps and is stored locally. This backup is the most versatile and will be the one used in migrations or in case anything goes wrong during changes at the OS level;
  • WordPress/Updraft Plus:
    • IDrive: Daily backups of the database and files runs automatically, and the last 7 versions are stored. A concurrent incremental backup is created in real time and is usually the most up to date version of your site. All files are encrypted at rest and hosted by IDrive, with a choice of 5 locations across the globe. You have access to these backups in the WP Dashboard and can download them at any time;
    • You: We also encourage you to set a separate backup service of your choice, based on the supported backup services by Updraft. Popular choices like Google Drive and Dropbox are available. This is a an optional but highly recommended feature, ensuring that even in the case we go out of business, you’ll have a safe backup of your site.

6. Virtual Patching: Patchstack

WordPress plugins and themes are often the most vulnerable aspect of a WordPress site and can be the primary source of security breaches. Since they are developed and maintained by third-party entities, we have limited control over their security standards.

Virtual patching is a highly effective approach to addressing vulnerabilities in WordPress plugins and themes. It functions similarly to a customized WAF, but much more effective, with rules tailored to each specific context. When a vulnerability is detected, Virtual Patching technology creates a protective “shield” around the affected plugin or theme, even before the developer releases a fix.

We employ Patchstack Protection on all of our sites, significantly reducing the risk of security breaches. Besides, vpatching, we also activate the following modules and security settings:

  • Advanced Hardening: Security rules to block common malicious requests against WordPress sites, including:
    • Disable theme editor (PHP file edit);
    • Disabled user enumeration;
    • Block application passwords;
    • Restrict XML-RPC access to authenticated users;
    • Limit Login Attempts to 10 over 5 minutes;
  • Community IP Blocklist: Community list of IPs that are exploiting vulnerabilities;
  • Generic OWASP: OWASP Top Ten firewall rules covering the most common types of attack.

Conclusion

It’s clear that we prioritize security and are committed to continuously enhancing our systems. Enjoy a safer WordPress experience, signing-up now.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *