WordPress is the most popular CMS in the world. More than 409 million viewers browse over 20 billion pages every month. On the back end, there are over 55,000 plugins available to extend and customize the platform to fit your team’s needs.
WordPress is an incredibly powerful and versatile tool for publishers; however, because it’s so ubiquitous, it’s also ripe for hackers.
How do you ensure that your WordPress website is secure? Here, we’ve listed 15 of our favorite WordPress security plugins to install to shield your site from cybercriminals.
You might already know that WordPress powers more than 30% of the web. It’s by far the most popular online publishing platform, and it hosts 70 million new posts per month.
But why is it so ubiquitous? And what makes it so powerful and instinctive for users? Here, we break down five of the key benefits of WordPress for current and potential users.
We originally published this piece in 2015. We’ve updated it with additional WordPress security advice in 2019.
Our Google Apps Login Premium and Enterprise plugins allow all users with an email address in an organization’s Google Apps domain to log in to the WordPress site with one click. If the user doesn’t have an account in WordPress already, one is automatically created based on their Google profile information — taking their first name and last name, for example. The plugin needs to generate a unique WordPress username, so the simplest thing is for the plugin to use the email address as the username directly. This ensures it is unique — but an email address can be long and cumbersome as a username when used throughout the site.
WordPress is the most popular CMS in the world. In fact, it powers more than 32% of the entire web. But that doesn’t mean it comes fully optimized for you or your team. WordPress plugins exist so that you can tailor your workstream to the platform.
From integrating with Google Apps to efficiently scheduling your posts, WordPress plugins allow you to take your projects to the next level.
Below we’ve highlighted nine of our favorite plugins to boost your productivity — even on this already powerful site. (more…)
Thought you knew WordPress? Think again.
Even savvy WordPress users, who work with cutting-edge WordPress plugins, often don’t understand the full power of the platform.
Check out these facts and stats below to get a full picture of the technology you’re working with — and discover ways to improve and optimize your site. (more…)
Open source WordPress powers more than 30% of the World Wide Web. Users publish over 41 million new posts on 15.5 billion pages for 409 million viewers every month.
This enormous surface area makes it a prime target for hackers. In 2018, 90% of all breached CMS sites came from WordPress according to a recent report by Sucuri.
In this post, we break down five of the most common WordPress attacks — and offer solutions to mitigate risk. (more…)
Following a series of Google Apps login phishing attacks (specifically on Google Docs) in 2017, Google made several improvements. At the time, while we welcomed Google taking steps to address the phishing problems, it caused issues for WordPress plugins.
Specifically, the updates made it challenging in cases where customer installation required individuals to create a Google Cloud project with their own OAuth 2.0 Client IDs.
To make things easier and safer for legitimate users who need to create Google applications, we recommended that Google:
- Allow users to authenticate against an OAuth ID they created using the same account as the one being used to access the app.
- Allow admins to whitelist specific ID/Secrets on their domain and also allow any regular Gmail account to whitelist for their own use.
- Provide a clearer error message where unverified apps encounter ‘Invalid Scope.’
- Deliver documentation explaining the new verification processes they have rolled out.
- Offer a more robust and selective solution than joining the ‘Risky’ Group (Google already confirmed to us they are aware this cannot be a permanent solution).
Since then, we have even more suggestions for WordPress users using Google Apps login to deter attackers.
Why should you add a Google Login button to your WordPress site? It’s simple.
- It’s more efficient. Instead of trying to remember yet another password, Google’s one-click login allows access without having to reset accounts. (It takes far less admin work as well.)
- It’s more secure. Particularly, if you opt for Google’s multi-factor authentication (MFA) solution, even if a hacker does get through the first wall — he or she will also have to track down a second piece of data, such as the user’s fingerprint or voice, to break in.
- It improves the onboarding of new users. In the past, it took a while for a new WordPress account to be set up, leading to a greater potential for churn. With Google login, user profiles are automatically populated, leading to immediate engagement.
Read on to learn how to improve your site with Google login.
[Image via Pexels
A popular feature of Google Apps Login Enterprise version has always been the ability to specify role mapping rules – so that members of different Google Groups can have different WordPress roles assigned to them.
The only problem was that some companies didn’t have relevant Google Groups already set up (e.g., for email@example.com to contain their Marketing team) but instead had their G Suite domain arranged around different Organizational Units to control access to various G Suite features.
Google recently rolled out ‘Team Drives’ to their G Suite business customers. One big problem for enterprises using Drive is that there is always one ultimate owner of any files shared within Drive. So popular files can be shared by employees, but if the owner happens to leave the company, or decides to reorganize their own ‘My Drive’, the files can be lost to everyone else.
Team Drives aim to overcome this by providing storage space completely outside of anyone’s ‘My Drive’, truly belonging to the organization rather than any individual.