EXPLORE CLOUDWAYS
Experience lightning-fast loading times and seamless platform
View Demo > A Cloudways Security Bootcamp session on the often-overlooked threats that quietly compromise WordPress sites, and practical, sometimes offbeat strategies to shut them down.
🎙️ Speakers
▸ Aleksandar Savkovic — CEO, WPPlaybook.net
▸ Host: Moeez — Community Lead, Cloudways
✨ Key Takeaways
✦ Poor cyber hygiene, weak passwords, public Wi-Fi, and neglected updates, is the single biggest threat.
✦ Malicious favicons can hide JavaScript that logs keystrokes and steals login credentials.
✦ Nulled or “GPL free” plugins are a supply-chain trap that can carry backdoors and site redirects.
✦ Abandoned admin accounts are open doors, so audit and remove or downgrade old users regularly.
✦ Fake login pages phish credentials, so check the URL and let a password manager refuse to autofill on the wrong page.
✦ Media files like PDFs and images can hide scripts, so limit uploads and clean the media library.
✦ Disable PHP execution in the uploads folder with a simple .htaccess rule, and don’t overengineer your security.
Moeez: Hey everyone, what’s up? My name is Moeez and I welcome you all to day one of the Security Bootcamp. I’m super excited to have everyone over here, and over the course of two days we’re going to be having some amazing guests who are going to take us through WordPress security and how to make your online businesses more secure. I can already see a few people joining in in the comments. I can see people interacting and engaging. I would love if people could give their introduction and tell us where they’re from, what they do, so that we get to know each other well.
Apart from the sessions we’re going to be having some fun activities as well in which you can participate and get a chance to win some exciting prizes. Now before we begin I would like to mention that everyone who has joined in, we also have a prize for the most engaging participant as well. So I would encourage everyone to leave comments, ask questions, leave comments for our guests, for our organizers and for this event if you want to win those prizes. Winners will be announced by the end of this event tomorrow.
And before I move on to our first session of the day I would like to thank our partners as well who have helped us in making this event possible. So we have Patchstack, MelaPress, WP Umbrella and Limit Login Attempts, who have been with us over the past few weeks and made this event possible. So moving on to the first session of this event, I personally am super excited for this session, not only because the topic is so interesting but because of who the speaker is. So many of you might know him as WP Alex. I call him Aleksandar, and I’m super happy to have Aleksandar Savkovic over here with us. I’ve learned from him, I have traveled with him, I have worked with him, and I’m super excited for him to be here today and present his topic. Alex, I don’t know exactly how to introduce you because you run your own agency, you sell motorcycle helmets, and I don’t know how those align. I’m sure you must do a lot of different things as well. But before we begin, Alex, why don’t you give an introduction and enlighten us on what you are up to nowadays?
Aleksandar Savkovic: Yeah, hi Moeez, and thanks for inviting me for this session. And thanks to my old team in Cloudways, which was Moeez and Danish, who also took part in organizing this. I like your fancy microphone you have now. Well, we didn’t have that one earlier when we organized sessions. Yeah, well, let’s say that partially I left the hosting business and, in general, IT business. I founded actually WP Playbook, it’s a WordPress web agency, but it’s a community-driven web agency. So the idea is that only 10% of income is going to the agency for marketing and other needs, like to cover server costs and stuff we need for the agency, and the rest is actually being shared between QA and developers.
So that’s the way how the agency is functioning. On my side, let’s say that it’s not like a profitable thing, but maybe one day if someone decides to acquire us, we have the way how we will split the acquisition money between all developers and QA and people now working for the agency. So I’m not like 100% involved there, it’s like part-time involvement, helping with bigger problems, with bigger issues when they need something to unblock them when they are fixing something. And one of the biggest pain points, definitely, in maintaining WordPress websites and the hosting industry and WordPress itself in general, is hacked websites, security.
Those are always worst case scenarios, like when the website is hacked, the time you need and the damage to reputation of your business is significant, especially if those hacks are like the Japanese hack when they inject thousands of URLs which get indexed by Google, then your website shows up in Google with Japanese letters. One of the worst hacks, and they’re really persistent hacks that are really hard to find where the problem was. And the other business you mentioned is yes, I’m importing, actually I’m official dealer and importer of three motorcycle brands. I am official dealer of LS2 motorcycle helmets, suits, shoes, and we have also mechanic service for motorcycles at the same time, so we are doing maintenance for the motorcycles as well.
And to be honest, the maintenance is not much different from website maintenance. Like if you keep your motorcycle somewhere in the shed, in the rain without maintenance, the probability that you will fall from it and break your neck is really high. So you need to take care of all your possessions, definitely.
Moeez: I love how you have drawn comparison between website maintenance and motorcycle maintenance. I only know so many people who can do that. So Alex, I’m super excited to have you over here and for your session, and I can’t wait to get started. So you have the floor, take it away.
Aleksandar Savkovic: Thanks. The point of this presentation was to touch on things that maybe you have never faced. These things are happening, they’re a bit hidden, it’s not something usual, it’s not something you see every day. And very often these hidden threats are waiting somewhere in some dark corner of your website and you don’t even know when it will activate and when you will have the problem with a specific malware or specific virus you contracted. And let’s start from the very beginning. Who am I? I explained WP Playbook. And let’s talk a bit about why we have issues with websites, especially WordPress websites, and how to fight those hidden threats.
Poor cyber hygiene is the biggest threat ever. Like for everything else in your life, if you’re not maintaining something. If you have a website and you think you can set and forget, someone created a website for you and you now have the website and no one is maintaining it, no one is updating it, just, you don’t need the website actually. If you’re not maintaining it you don’t need it. If it makes money for you, if it makes business, if it brings customers, then put some effort into maintenance. Because in physical businesses, like my other business, you need to clean the floor every day, you need to clean windows every day, to present your business in the best possible way. Because if your main window watching the street is dirty, no one will watch through that window to see what you’re selling inside.
And it’s the same with the website. If it’s hacked, and if there is some unwanted content, and that content can be really nasty, often we saw hacks with content that I don’t even want to use the word for, but really nasty stuff. And imagine how bad impact to your business can be when anyone who found you on the internet visits your website and sees something like that. If you invested money to bring people to your website, which is really expensive these days, PPC is like skyrocketing, prices per click for specific keywords, etc. So you’re spending money, you’re investing into SEO, you’re investing into everything else, but cyber hygiene is bad.
Cyber hygiene is not just updating your website, it’s not just taking care of plugins, WordPress themes, PHP version, etc. Cyber hygiene is also where you’re connecting to Wi-Fi, your laptop, are you logging into your website from a cafe, from public networks? Cyber hygiene is which kind of passwords you’re using. All of that is cyber hygiene, and if we don’t have cyber hygiene, definitely we are the problem. And the second problem is, if you think you know everything about cybersecurity, you must be the biggest threat to your company, because the moment you think you know everything about cybersecurity, you actually know nothing. You maybe know 0.00001% of everything that hackers and cybercriminals are doing.
So what poor cyber hygiene includes, it includes various risky practices such as weak passwords. I saw a million times with a million customers, passwords like admin admin, the name of the website owner, one two three, 1 2 3 4 5 6 7 8, or something like that. Neglecting security updates. Very often we have updates in WordPress, maybe even multiple times per week, not like once per month. Also we had a situation here with the government in my country where someone clicked on a link inside of an email and they got ransomware, and hijackers requested 20 bitcoins to give back all the documentation. And believe it or not, it was the documentation for communal services of the city for 20 years, for all citizens. It’s not a big city, it’s 300,000 people, but imagine having the leak of 300,000 invoices, 300,000 names, addresses, etc, because someone clicked on a suspicious email link.
This is not the part of my five hidden threats, but my suggestion is to highly avoid having shared hosting with your email inside of the same server where your website is, because any malware or ransomware can jump between folders and hijack your website and your email and everything else. Implement proper security measures like use 1Password or LastPass or something like that to store your passwords, so even you don’t know what the password for the website is, and make it as complicated as possible. And definitely the recent studies reveal that a significant part of those breaches is because of poor cyber hygiene. So it’s not like someone is extremely smart and knows how to hack your website and they put a huge effort into it, but most of the hacks are actually because of poor cyber hygiene, and it was really easy to hack those websites.
So prioritize strong password creation, use unique credentials for different accounts, don’t use the same password for all of your emails, websites, etc, and maintain regular cybersecurity housekeeping like update your plugins, update your antivirus or spyware software on your computers. Always use secure networks, do not connect over insecure public networks to anything that is really important to you.
I made a list of five hidden threats, something not as common but possible, and something that is really hard to detect, but there are mitigation strategies for each of these possibilities. So number one is a favicon based malware injection, because .ico files can be hacked and can contain malware or spyware or whatever inside. Number two is fake WordPress plugin updates, where supply chain attacks can happen. The third one is abandoned admin accounts, ghost admins. Fourth are fake admin login pages, and the fifth one is hidden malware in media files.
So not to waste too much time, let’s start from the first one, to explain each one and how they function. Number one is favicon based malware injection. So attackers can disguise malware and malicious JavaScript into .ico favicon files. These files are often cached, and it’s not something that you would be checking, like an .ico file on your website. No one does that, even me. I would never check or see what’s inside the file, it’s not something any of us will be doing. But they provide that way to execute malicious code.
And that code, for example, this is one of the examples, is that an attacker gains access to a website and replaces that favicon .ico, and the problem is that the code is logging keystrokes, so when you log in or any of the users logs in, their login credentials get stolen. So they can literally store all the usernames and passwords of the people logging into your website. Imagine when it’s an e-commerce WooCommerce store or something like that. If they steal admin or store manager for that role, they will instantly have access to all the customers you have on WordPress or WooCommerce, with all their details like names, surnames, their emails, even phone numbers, addresses, everything they ever ordered. So it’s like a valuable asset to steal and sell to your competitors, and maybe even worse, just to ask from you money, otherwise they would report to GDPR agencies, etc. And we know how huge the fines are for having that kind of data leaks.
What is the mitigation strategy for this scenario? The first one is to always use content security policy, or CSP headers, to restrict which domains can load JavaScript. Regularly verify the integrity of files on your server by using checksums or any kind of monitoring tools. Good thing, and I think this is also possible with Cloudways and CDN, to store favicons and other assets in a secure CDN or trusted repository instead of keeping them on your main server. And restrict file upload permissions to prevent unauthorized users from modifying static assets. So static assets are mostly uploads, so those are not files which are being executed like PHP files, but more like media files, PDFs, .ico files, and files that will be just served by the server as is, without using PHP and without running any scripts or JavaScript.
The second one is fake WordPress plugin updates, or supply chain attacks. Before I explain this in detail, it’s a very rare occasion that something like this happens in the official WordPress repository, like almost never, maybe not almost but never. This very often happens with GPL sites. These are the sites from those, I don’t want to use the word because Moeez would have to beep me, so I will just leave the word but you can guess which word I would be using. And on GPL free sites you can actually buy for, I don’t know, 20 bucks or 30 bucks, you can buy a yearly membership and get access to 50 pro plugins like Elementor, like WP Bakery, like Visual Composer, Brizy Pro, whatever, just name it and it’s there, and you will get that for like 20, 30 bucks.
By doing that you will maybe save 40 bucks by not purchasing directly from the vendor, but you’re a cheapskate and you want to buy from some GPL free site and to get multiple plugins for free. And then when those plugins start getting updates, you don’t know even with the plugin you downloaded, even with the plugin you bought, you don’t know what’s inside, because inside can be whatever they want, can be malicious malware, can be whatever the owner of the GPL free site wants. Firstly, if you expect them to have morals, they don’t have any, because if they had morals they wouldn’t be doing GPL free, they wouldn’t be stealing plugins and themes and selling them as their own. So you don’t expect any ethics from their side.
So what attackers do, they trick WordPress users into installing these malicious plugin updates by compromising legitimate plugin repositories or creating fake versions of popular plugins, exactly what GPL free sites are doing. They buy or download the pro version from somewhere and then they modify the plugin as they like. So you think you installed WP Bakery, or you think you installed something else and that is a legit source of the code, but it’s not. And once installed, these updates are injecting malware, they are stealing user data, creating hidden backdoors for hackers, just name it, whatever you like. When you install the plugin with PHP files inside and JavaScript, you don’t know what will happen and you don’t know in how many ways your website can be hacked, because it’s already hacked. The question is just the moment when you will see the results, or the damage the malware is making to your website.
Example is simple. You see an update notification for a plugin you use. It’s a hacked version uploaded by an attacker. It’s not what you want to update, you just click the update button, you think it’s safe, but the new version adds a hidden admin user and steals information from your WooCommerce store. That’s just one of the attack scenarios. But it can even redirect your website to some other site. So if you have big traffic, good traffic, you invested a lot into SEO, they just inject scripts which will be redirecting people from your website to their website, which can be actually the identical copy of your website with a payment gateway, where people will order goods and products from you, but they will be actually ordering products from the attacker and connecting their credit cards and paying for those products or services to the attacker.
Then your business is on the line, because you made that disturbance, it’s not your fault, but the people will have to sue someone else, like someone who stole their money, but they will never buy again from your website because they don’t trust you anymore, and they will never ever trust you again. And we mentioned earlier how expensive it is to bring one customer over. Mitigation strategy is quite simple. Download plugins only from trusted sources like the official developer websites, reputable marketplaces like CodeCanyon, for themes it’s ThemeForest on Envato, so only from trusted sources. Whenever you see an ugly website with an ugly design like done in Paint or something like that, you should know that those are not trusted sources, and you shouldn’t be even using your credit card buying some subscription for that kind of site.
Enable automatic updates only for trusted plugins, of course. Use WP-CLI or safe updates from tools like Cloudways. You can use WP-CLI through Cloudways and you can use safe updates also on Cloudways to test updates before applying. All of that. You should also monitor plugin changes using any of, I just mentioned the most popular ones like WordFence or WP Activity Log, to get alerts when files are modified. But if you have some other preference, I’m not pushing you to use these, I’m not telling you these are the best ones, every plugin of that type is good and they all do the trick. Also check plugin reviews and update logs before installing updates. If something seems suspicious, wait before updating.
What we tend to do, especially WordPress users, is that when we see an update we just click update and that’s it, update plugin, click update, update this. It’s not always just click and update. Sometimes you need to be careful and to see what is being updated, why it’s being updated, is it synced, and is it compatible with your other plugins, is that version of the plugin compatible with your WordPress version. So it’s not like just running around like a chicken without a head and clicking update buttons. That will be also risky, as much as keeping them out of date.
Number three is abandoned admin accounts, or ghost admins. Over time, website owners and teams create multiple accounts. There are developers, there are designers, there are contractors, there are copywriters, SEOs. So if this website is a couple of years old, like two, three, four years old, there will be a lot of accounts there. If it’s an e-commerce, if it’s a WooCommerce store and you have regular customers there, you will have thousands and thousands of users on your website. Attackers can target any computer, any phone, and check for usernames and passwords, that can be an old account, someone who hasn’t logged in for a couple of years, two or three years, and that is a security threat, that is the possible breach, and you should be deleting those accounts regularly.
So one of the examples for this one is that a former employee had an admin account that was never deleted. Attackers find it and use leaked passwords, because occasionally you can see that there are databases with leaked passwords shown somewhere. Even LastPass was hacked once, and they use, from a completely different breach, they use login data and take over your website.
For this there is also a way to mitigate. Just to say hi to people in chat, just to take a short break because I would say I’m running fast. Hi Tommy from Serbia, from my country, and hi all other people here. I hope you, I prefer doing major updates manual. Yeah, well, you shouldn’t be keeping plugins waiting for an update for too long. It’s always like, don’t do it that very moment when the plugin is live, it’s not safe to do it, wait a day, two days, three days, check the forum, check comments, check on WordPress.org what’s happening.
And let me see, Tyler is asking, is there any merit to having more than one admin/super admin on a site, so if one gets compromised, password loss, you still have another way in, or is that just, no. You can have more than one admin or super admin however you like. It is super useful to have more than one, because if one is hijacked then you have the problem, because you can’t access the dashboard. There is a way, maybe people here don’t know how to regain access to the website. In Cloudways you have the button, database access, you go to database access, you find the table WP users, and inside WP users you will find the list of all admins without access to the WordPress dashboard.
If you see new admins which are not your account, you can just select them from the WP users table and drop them. When you drop them they will instantly lose access to your website. And if they changed the password to your original account, you can change the password like resetting password through your email. But if they managed already to change the email, you can easily change email, username and password through the WordPress database. You just have to type in the new password in the field, select hash MD5, click update, and then you will have your access back, and then you can delete and block all other users in the WP users table.
Is it bad to have auto update enabled? Yes, because you don’t know. We are witnesses, especially with page builders and WordPress builders, that just keeping auto update enabled can destroy the website, then you need to go back and forth like asking the support to restore your website if you’re not technically educated to know how to do it yourself. So it’s definitely smarter not to have auto update enabled for the WordPress core, because you should be updating WordPress core as soon as it’s live, but I’m also skipping that one, I always wait for two or three days before I update anything on the website.
So mitigation strategy for this kind of old admin accounts is to review all user accounts regularly, delete or downgrade old admin accounts to lower roles like subscriber. If they are subscribers they see literally nothing inside of the dashboard and the possibility they can take over something is zero. Oh yeah, Cloudways support is really good. I had, a couple of days ago, an experience, I was a bit annoyed to be honest, because a couple of times we did some migration and it didn’t work, we did it ourselves, and then one of the girls from Cloudways did the trick, she figured out what happened and we sorted it out in like 15 minutes, everything.
So use a plugin like WP Security Audit Log so you can track logins and see if some inactive admin suddenly logs in, because it can happen that some of your old employees log in again after two years. Why would they log in after two years? You’re not paying them to do that. So even if it’s them, their intentions are not good. Enable two-factor authentication for all admin users, so there can’t be any login with leaked credentials, because you need an extra step, like when you’re logging into Cloudways you need to enter your username and password and then you need to wait for an email with a six-digit code so you can actually log in. And implement automatic logout for inactive accounts using a plugin like Inactive Logout.
To set up passkeys with WordPress, yeah, I guess you can find some cool plugins for that, but there are things that I would say, Tyler, would be overengineering. Once, one person I don’t like much as a person, which is Elon Musk, I think he’s an egomaniac, but he said one really good thing, he said that the biggest problem of software engineers is that they’re actually fixing things that shouldn’t be existing. And that’s the major thing, don’t overengineer things. The less you engineer things, the smaller number of problems can happen.
Next one is fake admin login pages. This is very often, and I don’t know how and why people are not paying attention to this kind of stuff. It can happen that hackers inject fake login pages. Fake login pages are pages which are not the regular ones like /wp-admin, but they’re mostly like /wp-admin-2 or /wp-admin-2314, like those fake accounts, sending you a link on your Facebook, threatening you that your ad account on Facebook will be terminated, you need to fill out some form, and then you see the website is Facebook-admin-something-something-dot-whoever-knows, and people are not paying attention, they just click links and that’s it.
Good thing, hola Miguel Kastas. What we also do, we are sometimes doing things blindly, especially when we are panicking, and we are panicking when we receive some email with uppercase letters like, your website is in danger, add your username and password to confirm your identity, otherwise we will delete your account in 72 hours. Whatever, it won’t happen, no one will delete your account ever in WordPress. But people who are not technically well educated, like just website owners, store owners, they are not prepared for scenarios like that. Imagine that your mother or someone is retired and they have their own web shop for some handmade items, they would click and leave their credentials there.
Yeah, but that is exactly one of the mitigation strategies. So what they do, they send you to a fake admin page. The good thing is when you’re using managed hosting like Cloudways, you have the button, and the button inside the dashboard is taking you to the right place to log in, so you never use something that is not the place, except the button you click on to take you to the login page on Cloudways. So mitigation strategy is, be smart. Check the browser URL before logging in, and your WordPress login is, and mostly will be, yourwebsite.com/wp-admin or yoursite.com/wp-login.php.
Good thing is to rename these WordPress login URLs using plugins like WPS Hide Login to prevent attackers from easily creating a fake page. And of course plugins like WordFence to detect and remove unauthorized login pages. Also use password managers to autofill login credentials, and this will prevent you from entering credentials into a fake form, because 1Password or LastPass wouldn’t offer you username and password because you never logged in on that URL, and then you will just see the blank fields and you will be asking yourself why these fields are blank, why doesn’t it want to populate them. And you don’t know the password because the password is autogenerated by 1Password or LastPass, and when you check the address bar then you will figure out that someone is trying to steal your credentials.
And the fifth one, this one is not that rare, it’s kind of often, that hackers hide malicious code inside images, PDFs or other media files, SVGs uploaded. These files are mostly sleeping somewhere inside of the uploads folder and wait to execute malicious scripts when it’s the best moment or when it’s triggered by someone. Why is it inside of the media? Because inside of the media we now, because of all the optimizations like making new image formats to consume less storage, to consume less space in loading the web page, to make the website perform better, we are using newer formats. Newer formats, I don’t want to say less secure, but they rely more on the code than the physical form of the files itself.
I’m using only All-in-One WP Security. As I said, Martin, most of the security plugins are doing the job well, so I just took WordFence as an example because WordFence is with us for I don’t know how many years, like probably 15 or so, so it’s the most popular. It would be like, I was using Ford or Harley-Davidson if you’re talking about motorcycles, just to refer to the most known brand. In motorcycles the most known brand is Harley-Davidson. The best one, it’s questionable, what do you prefer. So yes, definitely you can use All-in-One WP Security.
So these files mostly sit unnoticed, and what attackers do, they upload an infected PDF or image via contact form, or they use some user upload area, especially if you have a jobs page or something like that where people need to attach a PDF with their application. And these files can contain hidden scripts, when accessed they create a backdoor or inject spam links into your website. So this is not rare, this is something I saw many times happening. It’s not hard to mitigate this kind of situation, but it can be tricky because it’s a PDF, like when you see those PDFs, “Mohammad Moeez CV.pdf” and you think it’s actually Mohammad Moeez CV.pdf but it’s not, it’s actually malware waiting and sleeping somewhere to attack your website. And Moeez is also a suspicious person, so it can be detected as malware. I would detect it as malware because I know him personally.
And for this there is a mitigation strategy, of course, is to limit file upload permissions and only allow trusted users to upload media files. To use a malware scanner, again I mentioned WordFence or Sucuri, to scan media files for hidden scripts. To regularly review and delete unused files in the media library to reduce the risk of hidden threats. What is happening often, and we see that on our customers’ websites, they upload the image and then they don’t like it, in the gallery or whatever, then they detach that one, upload the new one, and then you see hundreds or thousands of media files detached, which are not used anywhere on the website. And then you figure out they actually removed those images but they never deleted the image from the media library, they just removed the image from Elementor or some gallery plugin, but they never actually removed that media.
That is good practice, because you don’t want your website to be extra huge. It doesn’t affect loading. Whoever tells you that having a lot of media on your server is slowing down your website, it’s not. It would be telling you that the truck is moving slower because in your backyard you have a lot of things on your trailer, but that trailer is not attached to the website itself. So the truck is only pulling things which are inside the truck. So media that is being used and that is being generated into HTML, CSS, sent to a client browser, but media that you have in storage somewhere on the website doesn’t affect loading speed.
And disable PHP execution in the uploads folder using .htaccess. Why? Because there is no need to ever execute PHP in the uploads folder. Uploads folder is a storage, the place where you are storing media files, there is no PHP and there is no need that any PHP execution is happening inside of that folder. So how do you do that in Apache or LiteSpeed or whatever you have? You add one directive, which is directory WP-content/uploads, FilesMatch PHP, PHTML, SHTML, CGI, PL, EXE, etc, you set order allow deny, deny from all, close FilesMatch, close directory, and this will prevent any PHP code or code execution inside of the uploads folder. By this simple directive you will be forbidding any PHP action or execution, so malware will be dead, and you will even get a notification in WordFence or Sucuri if some script is activated but it won’t be executed. Have some questions? No? Okay.
Moeez: Yeah, Alex, that was very insightful, and thank you so much for the kind words in the middle. I don’t know why but I was expecting, knowing you personally, that somewhere in your presentation you may come up with some sort of comment. But anyways, we do have some questions, but before I take those questions I would like to appreciate everyone who is engaging in the comment section. I can see we have people from Spain, from Pakistan, from the UK, from the US, from Nigeria, from Addis Ababa, from Toronto, from Mississippi, Netherlands. I’m so happy to have everyone over here and excited to spend this day one of Security Bootcamp with you guys.
So let’s take some questions first. Let’s start with this one. So we did have some questions in the start, so I’m going to start with the ones who were asked earlier. So Matt had this question, how often should WordPress plugin updates be done, is it safe to install minor updates frequently and do major updates less frequently?
Aleksandar Savkovic: Okay Matt, this I have a simple answer to. I won’t say I’m 100% right, I’m always sharing only my experience, so whatever I tell you doesn’t mean that this is 100% correct or carved in stone and you should do it like I’m doing it. My background is Manage WP, GoDaddy, Cloudways, so mostly hostings and WordPress hostings. So how often should WordPress plugin updates be done? As I mentioned earlier, I always wait for a couple of days after an update is released, to see which kind of problems will happen. Just visit Facebook groups, like if it’s Elementor Pro, go to the Elementor Pro users group on Facebook, there are like 100,000 people, and check after a day if someone is complaining about something being broken, does the header or footer break, are the global elements not working. So if you see that, just don’t update, wait for a patch or for a fix. And of course before any update, back up the website. Before any update, it’s like a golden rule.
Moeez: Yeah, I think that’s backup, that’s update 101. If you want to update anything on your website, take backups before doing that. So next question is from Anto, how can website owners educate their customers to spot fake login pages?
Aleksandar Savkovic: Force them to use, if you are maintaining their website, so if you’re an agency and you’re responsible for the website, you’re charging them monthly for maintenance, so you are responsible for the security as well. Make them use two-factor authentication, that is number one. And make them use software like 1Password or LastPass, because as I said, if it’s a fake login page then LastPass won’t work and they can’t login. So you need to force them, you shouldn’t be educating them, it’s really hard to educate. Especially on technical things, like, try to educate my mother. You don’t educate people, you just set procedures. You just set procedures so they have to use a secure way to log in and to use the website. And one of the procedures is setting up, for them or with them, LastPass, so they don’t know their password.
Moeez: Yep. Next question we have is from Ralph. As mentioned, changing WP admin login URL can help, but can it also cause issues with some plugins, any suggestions? I don’t know, with which plugins it can cause issues. Ralph, if you’re there, can you give us an example for that? So just mention in the chat, Ralph, if there are any plugins that you have come across who are affected by this, then you do mention that and Alex will be happy to answer.
Aleksandar Savkovic: Yeah, because I never had a situation where changing the login page actually had a conflict with any other plugin. There was a problem with Manage WP, let’s say some early versions like 12 years ago, while they hadn’t used tokens to login and file for auto login, but they used actually username and password for migrations, etc. Yes, in those cases it could cause issues, but nowadays everything is using APIs, so I don’t see a reason why any plugin would use the login URL. But if there is a case, please share with us.
Moeez: Yeah. Tyler seems to have another question. Maintaining WordPress sites manually, reading changelogs, testing on staging, can feel like a full-time job. Has AI become helpful in some of this process, maybe the testing phase? I would love to have an agent that checks changelogs for me to tell me if I should update based on aggregate feedback for example.
Aleksandar Savkovic: Well, AI is a tool of today and tomorrow. I won’t say future because we don’t know what the future is bringing to us, because we are all Homer Simpsons, we don’t know what future is bringing because we are dumb, mostly. We have too many information available so that made us dumb. Yeah, don’t laugh, like, you’re checking me. Well, Tyler is asking if AI is helpful or not, and I would say yes, if you’re using it correctly, and if you make a good bot that could actually aggregate some changelogs, etc, and based on some data give you advice, would it be good or wait for something to be updated? Yes, why not. I’m for the new technology 100%.
Moeez: Perfect. So Resty has a question. How do malicious codes in PDF, favicon and images get executed? Do they rename them or some kind of manipulation?
Aleksandar Savkovic: Yeah, JavaScript code inside, it’s simple, JavaScript code inside, and then JavaScript code can actually hijack the client browser and the keyboard, whatever you like. When you’re typing anything on the website, they know that you’re actually typing username and password, because that is the most common way, first type something, then type something else, so it’s two fields, it’s username and password, and JavaScript knows that and JavaScript reads the field username and password.
Moeez: So Tyler actually had another question that I sort of missed. He’s asking, is it possible or advisable to set up passkeys with WordPress?
Aleksandar Savkovic: Yeah, I saw the question, and that was the answer I had during the session, like, do not overengineer things.
Moeez: So Philippe has a question. Is it bad to have auto update enabled?
Aleksandar Savkovic: Yeah, I think it is, if it’s not safe update. So if you don’t have safe update activated, so it detects that something is broken after auto update and reverts those changes, then you shouldn’t be having auto update enabled. And you never know, what if auto update happens at 3:00 a.m. when you’re sleeping, and your customer is in a time zone where they are already selling their products, it’s working full on, and you’re sleeping and some nightmare scenario happens, and actually the fix for that scenario is two clicks, but you’re in your warm bed and you don’t want to have that kind of experience. So just don’t use auto update.
Moeez: Perfect. Let’s take one last question, Alex. So Anto had a question earlier, that is it enough to simply delete a potentially compromised GPL plugin, or should additional security measures be taken as well?
Aleksandar Savkovic: It’s never enough to simply delete, because you don’t know how many new files are being created or generated, how many files are being infected. Because if the GPL plugin was compromised, then probably index.php, .htaccess and who knows how many other files are being injected with the same malware, and it spreads around.
Moeez: Perfect. I think this is pretty much it, we are on time for the session, Alex. I can still see more questions over here, but I think I will just forward them to you and you can get back to me over email and I can give those answers to these attendees. I just want to thank Alex for being here today, taking his time out of his very busy schedule, as you have heard before that he is involved in multiple projects and doing multiple things at the same time. So thank you Alex for being here, thank you for making this presentation and presenting it to us. I’m sure the people on this call listening to this would have learned a lot from you and your presentation today. So yeah, any final thoughts, Alex, on the Security Bootcamp, or any final thoughts before you leave?
Aleksandar Savkovic: Be smart. So security these days is common sense. Don’t do stupid things, don’t act stupid, and everything will be fine. Like update regularly, check your website regularly, don’t open emails from people you don’t know, don’t click on links inside emails. There are so many filters now inside Gmail, inside any email provider, so the technology is helping us as much as it’s possible to help us not to do stupid things, and we still just need a bit more common sense and everything will be fine.
Moeez: All right, so basically you’re saying don’t be stupid.
Aleksandar Savkovic: Yeah, yeah, don’t be Homer Simpson.
Moeez: Got it. Thank you Alex, thank you so much for being here, and I wish you all the best for your current and future projects. So thank you so much Alex, see you, bye-bye.
Aleksandar Savkovic: Thank you, bye.
Answer a few questions, and we'll present you with a personalized tour of the Cloudways platform based on your answers.