[Is WordPress Scary?] What If Your Website Suddenly Disappeared One Day...? [Preparation Prevents Worry]

From ACIDHOUSE, INC., this is Tetsuya Ashida.

This article answers these questions.
WordPress Always Lives Alongside Vulnerabilities
According to one survey, WordPress is used by 25% of websites worldwide.
As with anything, a reasonably large user base means always living alongside vulnerabilities. WordPress is no exception.
But WordPress offers:
- Much easier website updates
- Extensibility through abundant plugins
- An SEO advantage (endorsed by Google)
So it is also true that these benefits are a trade-off against vulnerabilities.
I did write “an SEO advantage (endorsed by Google),” but that may be questionable now.
This claim is usually based on a presentation by Matt Cutts (who has since left Google) at WordCamp San Francisco 2009, but the information is very old. Also, I don't feel that merely using WordPress now necessarily provides a major SEO advantage.
Still, there are many success stories involving WordPress websites, so I included it.
How Do You Protect a Website Built with WordPress?

- Use complex passwords.
- Update immediately.
- Optimize plugins.
- Make regular backups.
These are the minimum points to cover.
I'll explain them one by one.
“Optimize configuration-file permissions,” “block access from overseas,” “protect XMLRPC” and “prevent forgetting domain renewal” are among other measures, but I'll cover them another time.
Use Complex Passwords
This isn't limited to WordPress, but hackers try every simple password they can to log in. They automate trying them all with tools, so it happens in an instant.
Always generate and use a complex password with a random mixture of letters, numbers and symbols, like “12c.Kmc_,((u6#(e”. Needless to say, changing it regularly is desirable.
However, operating with complex passwords can cause problems such as:
- You can't remember them in the first place.
- You wrote them on paper but can't tell the characters apart.
- Typing them takes time.
Password management tools solve these problems, and among them I recommend 1Password.
▶The most secure password manager | 1Password
It has a monthly running cost, but you only need to remember one password (of course, it mustn't be easily guessed), and retrieve the saved login IDs and passwords from 1Password to use them.
In real-world terms, it's like a safe containing several keys and registered personal seals.
Also, you don't need to think up complex passwords yourself; 1Password generates them, so you can use those.
Avoid reusing passwords or storing them in a form anyone can access, such as writing them in a Word file on your computer. That's no different from using the same key for every room or leaving your registered seal where anyone can pick it up.
Also, your Google password often connects to all sorts of services, so never let it leak.
Update Immediately
This isn't limited to WordPress either.
Updates apply to WordPress itself and its plugins.
One precaution: updates have the benefit of reducing security risks, but occasionally they reduce usability or cause something that worked before to stop working.
It's important to stay informed, for example by Googling whether an update has introduced problems.
When WordPress moved from 4.9.8 to 5.0, the editor changed substantially. However, the Classic Editor plugin was provided, so existing users didn't face a major burden. The new editor's stability also seems fine.
Optimize Plugins
I wrote “optimize,” but this breaks down further into:
- Don't use more plugins than necessary.
- Don't use plugins with little usage history.
- Don't use plugins that haven't been updated for a long time.
Don't Use More Plugins Than Necessary
More plugins give hackers more openings and make the website heavier, so minimize them.
There are various views on “How many is best?”, but I think 10 or fewer.
*If you're interested in each plugin's functions, try Googling them.
Not every plugin above is ideal for every user, but from the perspectives of “security,” “convenience” and “growth,” I think this is a good plugin set.
*If you use them, check the plugins' contents thoroughly first.
Don't Use Plugins with Little Usage History
After all, updates depend on usage history and feedback, so avoid plugins with little usage history.
As for judging how widely used they are, it's enough to look for a reasonable number of ratings and general users explaining how to use them on blogs when you Google the plugin name.
Ultimately, using the established standards everyone uses is best.
Don't Use Plugins That Haven't Been Updated for a Long Time
A long absence of updates increases the likelihood of security holes, making the plugin an easier target for hackers.
Incidentally, I'm reviewing this site's plugin set too. I've used Table of Contents Plus, but it hasn't been updated for a long time, and heatmaps suggest users don't use the contents much, so I'm thinking of removing it.
Also, the plugin mentioned earlier, Wordfence Security, alerts you when plugins haven't been updated for a long time, making it useful in that respect too.
Make Regular Backups
The methods above can't cover everything, and even with thorough precautions, it's entirely possible to be targeted by hackers and have the site disappear.
Nothing is 100% safe.
What matters then is how quickly you can recover. For that, it's important to build in regular backups at short intervals.
For backups, you can either use a plugin such as BackWPup or configure them through your hosting server's control panel.
I use mixhost , and back up automatically with Softaculous, an application provided by the hosting server.
Another site of mine once disappeared, but even though I'm not a server engineer, I restored it relatively quickly.
Which method do I recommend? Plugins do add load to the website, so if your hosting server provides a backup function, I think it's better to use it.
*For hosting servers, also see the following article.
[With Recommendations] How to Choose a Web Server You Won't Regret [Stability, Price, Support] February 23, 2019
Is There an Easier, More Reliable Method?
Those, roughly speaking, are ways to protect your website.
However...

Many people probably feel that way.
There's an approach I'd like to suggest to them.
- Outsource WordPress's initial setup and ongoing maintenance.
- Use a next-generation owned-media platform such as note pro or Wix.
Put simply, leave it to the professionals.
The former costs around ¥50,000 per month, but you can also ask for domain management and other services that prevent your site disappearing because you forgot a renewal, so simply continuing to pay makes it much safer than operating it entirely yourselves.
For the latter, note pro and wix's providers manage the servers, so you don't have to do anything yourselves about vulnerabilities. Even if a problem occurs, a swift, appropriate response can be expected.
*For note pro, also see the following article.
[A New Direction] Could WordPress Be Unnecessary? How note pro Changes the Way We Build Owned Media March 13, 2019
I Offer WordPress Initial Setup and Ongoing Maintenance
I can undertake this too, so if you're interested, I'd appreciate your inquiry through the link below.
It depends on the scope, but an approximate price is ¥100,000 for initial setup and ¥50,000 per month.