In this episode, guest hosts Dan Knauss and Rob Cairns emphasize the need for a reliable hosting company that can handle security and performance issues and discuss the importance of choosing a host that can adjust resources based on performance to prevent site crashes during high-traffic periods.
Their recommendations include using two-factor authentication, regularly updating and vetting plugins, and conducting regular backups. They also warn against the risks of social engineering and suggest using an uptime monitoring service.
Thanks to our sponsor
The best time to migrate is before you’re under pressure. Omnisend moves everything essential for you now, so you’re fully ready when you plan for that large campaign. Use the code OpenChannels and get 30% off your first 3 months of any paid plan.
Lastly, they advise against making major changes close to a critical period and stress the importance of performance and security.
Links
- Stunning Digital Marketing
- SolidWP
- Dan on X
- Rob on X
- Dan on LinkedIn
- Rob on LinkedIn
- WordPress Global Community on LinkedIn
Episode Transcript
Rob (00:00):
Hey everybody, I’m Rob Cairns over at Stunning Digital Marketing. If you don’t know me, and we are pleased to do the Woo show today and we’re going to talk all things WordPress, security and WooCommerce. And I’m here with Dan now of StellarWP. How are you today, Dan?
Dan (00:16):
Hey, very good, Rob. Nice to talk again.
Rob (00:19):
Again. Yes, we’ve become very close friends very quickly in a hurry. It’s all good. So I thought we’d jump right in and we talk about security going into the holiday season and I think it’s one of the things that people run websites don’t get that hack attempts actually go up as a holidays. Come on. What do you think about that?
Dan (00:42):
Yeah, boy, I don’t know if I could quote some stats offhand to demonstrate that, but I’ve personally experienced it and it’s not the time you want it to happen, especially with an e-commerce site where you’re making a lot of business at that point or your clients. Yeah, I had an American Thanksgiving one year that was pretty well ruined by a hosting company that was severely compromised long time ago, but it wasn’t my fault, but it doesn’t matter if you have things go down and yeah, it’s just not what you want when you have things in the oven and people you want to be unplugged probably.
Rob (01:24):
Yeah. So let’s talk hosting companies for a minute. StellarWP who you work for is owned by Liquid Web, one of the big WordPress host. There’s other good WordPress host, and I think you and I have talked about this offline, but it’s worth mentioning on the podcast hosting companies need to be your partner in all of this, not your vendor. Do you have any thoughts around choosing a good host?
Dan (01:48):
Yeah, you’ll know the difference between one, you have a relationship with real people and their support teams because you actually may get to talk to them, but yeah, thinking them as a partner, especially for your business and any business you’re doing and any businesses you’re supporting. If you’re a freelancer working with an agency, you want them to be doing the heavy lifting and things that happen best on the server side and a lot of that security, a lot of that’s performance and working together well is a good thing. I think often at times, unless ideal hosts, you might find yourself working at odds with them. They’re trying to clamp down resources and people install all kinds of things that maybe they aren’t aware of the performance and security implications and yeah, going into a big sales period in the holidays is definitely a time when you want all that squared away and working well,
Rob (02:52):
And as we’re talking about performance, I think one of the things that comes in handy for big WooCommerce sites and any big site actually is hosts that variably adjust your resources based on performance. So some hosts do that automatically where if you get a big hit of sales one day, for example, they’ll bump your resources up so your site doesn’t go down. Isn’t that an advantage A little bit?
Dan (03:17):
Yeah, absolutely. A good managed WordPress and managed e-commerce packages that will do that for you. That’s why penalizing most decent hosts have realized why hurt your customers when they’re doing their best. So yeah, extending those resources when you need them as your capacity goes up, that’s a great resource to have. You’re not going to get that on the old traditional shared hosting generally. Yeah, and just the kind of vigilance too, there was a, there’s security issues that come up at the network level that you can’t even, they’re not even on the scope of people working with WordPress sites and that’s what you rely on your server text to be on top of and sometimes I look and something will come out like this HTTP two, there’s a pretty big vulnerability just in the standard for that and that’s something Google and CloudFlare has clamped down right away.
(04:22):
Nothing you can do about it unless you’re running the network and the physical hardware. And I’ll go and search our larger company Slack and see what’s going on this server side and invariably someone a customer has asked and a particular bug something out there and it’s always reassuring to see that doesn’t affect us, we’re on top of that or we never were open to that. You definitely need hosts who are working like that with you and ahead of you and all the stuff you don’t even know or think about is being handled perfectly as perfectly as possible.
Rob (04:58):
A bit of a shameless plug for your employer. You’ve rebranded to solid WP the I think site and Solid WP has one of the best security newsletters with vulnerabilities every week they come out Wednesday. I would encourage anybody to get on that with newsletter. Two of my big Go-to spots three actually is your newsletter, GoDaddy Security Newsletter and Patch Stacks newsletter. They’re typically three spots I go and between the three of you av exactly what’s going on in the WordPress security space, I think last week the newsletter was around 120 or 130 vulnerabilities. They seem highly lately. I think the friends, the hackers are a little busy. What do you think about that?
Dan (05:46):
Yeah, thanks for that. I’m really interested in feedback from people who are getting that newsletter because we’re experimenting with changing that a bit. Yeah, I’ve spent most of my time at Stellar, WP is about a dozen different WordPress product brands from Learn Dash and give WP to what was formally I themes and I’ve spent most of my time working with that transition to now solid WP and our security and backup and site management product there. The weekly security vulnerability report is now primarily it’s data coming from our partners at Patch Deck who are really great and providing virtual patching. If you’re a solid security pro user, that’s really the last seven days with a little lag, like the most recent stuff has restricted the pro users. If you’re inside your security pegan or using Stack, you can see the up to the minute closures of vulnerabilities.
(06:48):
So we’re usually looking at the last seven Monday to Monday and then that will go out Wednesdays and this year it’s often, I think we’ve hit over around 300 sometimes. So it’s been a seven day period and it’s often around a hundred or over a hundred and it was again, this year we’re already double what we saw total for the previous year and the year before. So it’s an unprecedented time for many more disclosed vulnerabilities. I don’t at least we know about them. It’s not necessarily that they didn’t exist at that rate before, but what’s a little concerning is that in the WooCommerce ecosystem there’s been more incrementally more, it’s nice to see and like others, Elementor has been clamping down, they’ve been less going on. Those are big ADD-on ecosystems. WooCommerce is a very secure supported platform, but there’s so many extensions for it.
(07:51):
Those have often been this year in the lists. And the other concerning trend is that I think at the beginning of the year we started off with at the time of vulnerabilities are disclosed, there’s a patch, there’s an existing fix and you can upgrade for around it was around 80% and now it’s fallen 50 sometimes in below 50%, so you may have 60 that have no patch when we announced that and 60 that do. And what do you do then if there’s not an immediate patch and you need to take some action? That’s where our security plugin and patch stacks, virtual patching, little firewalls that blocks any attempts to exploit and actively exploited vulnerability that still doesn’t have an official patch for. So we’re happy to have that
Rob (08:41):
And having used your security plugin for a long time with my clients now, believe it or not, over 400 in that space, it works really well. So I would tell anybody to look at the product, it’s easy to configure, it’s easy to set up, it does everything so you don’t have to run like a separate two FA plugin for two factor or stuff like that. It does it for you. I would encourage anybody in a WooCommerce site to set up two factor authentication. Please, please do it now and if you haven’t done it, reach out to Dan or Ryan and say help because you need to factor and then start with that and go from there
Dan (09:22):
And you can ease that in gently if you’ve got an existing site with a lot of customers who have accounts they can log into. One of the nice features of solid security is that you can force them to change all their passwords now and turn on two FA if you need to. Maybe you only want to do that for administrators, maybe you only want to do that for the people with higher authority. You don’t want to create friction for your regular customers, but you can make it an option so when they come and log in, it will say give ’em a little nudge and you could do this. You could set this up and secure your account. You’ve probably run into that. I’ve done that sometimes and yeah, I use this a lot. I will make a note of that and then make sure my online e-commerce accounts are slightly more buttoned up than I would’ve otherwise if I hadn’t gotten that opportunity. So that’s a nice one there. And yeah, we just a few minutes ago rolled out new version release, little minor update for solid security Pro and tomorrow the basic version will brush up a few features.
Rob (10:20):
The other thing too is since Do the Woo has a big developers falling, I would tell any developers that are using MainWP, which is a self-managed management console, which I use or a managed WP, which is a GoDaddy product or any other products, please make sure that you have two FA and a highly complex password set up on those console managements because once somebody gets into the consult management, they have the keys to the entire jailhouse and then the inmates start to run the asylum and that’s not a good situation, so to speak.
Dan (10:57):
Yeah, that’s really a key central hub if you’re running an agency or a bunch of clients that you’re managing from a central control panel like that, the solid central is our integration for that online SaaS and you can
Rob (11:17):
Same idea. Yep,
Dan (11:18):
Definitely want to keep that secure and manage who’s got access to it. Surprising sometimes teams, someone’s not really watching who’s minding the store and yeah, you periodically want to make sure that former team members and whoever’s an administrator at that level should be vetted and taken care of there. Who’s using that?
Rob (11:45):
No question. And while you’re talking about vetting the administrators, you should actually vet all your users. Let’s stop this in WordPress where we give access admin because a client asks, and I’ll share a very story. I had a client who insisted his intern get admin access and I fought the client and the client said, I don’t care, it’s my website, do it. And I made the client sign a document that said that the intern caused problems, he would be billable. The intern went into the site and read an article that said security plugins and backup plugins caused boat. So what did he do? He remove solid backup, he removes security. He turned off two FA by doing that and within hours, not days, hours, some thought maliciously went in and found a backdoor into the website and we need to start going back to the way enterprise does security and that means if you work for a bank, you only get access to accounts you needs, et cetera. We need to do that, that in the WordPress space.
Dan (12:55):
Yeah, it’s surprising at a lot of levels how trust is a good thing. You need to verify people as well and there’s a lot of liability there that should be thought through before you give people privileges and yeah, the principle of the least privilege is what we try to encourage thinking about that if you use solid security, it’s going to give you plenty of opportunities to create custom user groups and set up different policies that you can enforce. So maybe you don’t force the regular customers to use two FA, but you nudge ’em about it for six months and then send ’em an email saying after this point we’re going to require it, but you can set it up yourself at your own leisure within this window, but your admins do it now, if you’re going to set up account or you’re already in there, you can go, it’ll tell you this user doesn’t have a strong password.
(13:54):
Every time there’s a scan, we’re not just looking for insecure plugins or themes, but users that have a weak password, something suspicious about the nature of the way they’ve logged in, and yeah, you can individually examine the risk level with users and it certainly goes up if you have an admin user, you temporarily give privileges to someone who needs to do some work from outside your team. They will, if you forget about that, sometimes hosts will traditionally have a support account on your site or something like that. I was never too comfortable with that and would delete those pretty quickly, but solid security will allow you to create an automatically canceled admin account for cases like that where someone needs to only get in there to that level as an admin for a short period of time.
Rob (14:49):
Let’s jump into backups for a sec, Dan, because this is what causes controversy all over the WordPress ecosystem and I think you had sent me over the weekend before we recorded this, a text that basically was saying we should turn off all internal processes for optimal performance and backups was one of those things that was pointed out and identified as a process that is heavy. Some people believe you should do backups at the host level, some people believe you should do it at the site level. You have a backup product called solid backup, which used to be backup buddy, which I adore by the way. I should say that Shameless plug. I do backups at both levels and say if the performance is too low then I need to find another host. Where do you sit in that whole discussion?
Dan (15:47):
I guess it really depends on the particular case of the site and what you’re trying to accomplish. A really complicated complex site with a lot of activity, a lot of customers, it’s an e-commerce site, anything of high value, you should have really good hosting and a standard for managed WordPress hosting and most now would be that there are at least daily snapshots and maybe you could increase that, but you may have sales activity and things that are happening just up to the minute and that requires something much more robust at the server level. But you could do that with something like with solid backups also rolling out a new release to improve that. We have solid stash is our kind of cloud-based option and backup method where instead of running the whole archive all at once of your file system and your database, it will incrementally back things up as they change.
(16:48):
So it’s just looking at what’s changed within WordPress now, so customer sale record of that changes and then pushing that up to the cloud. So those are getting, that’s always been a trick and it’s a great product because it will work on almost any host and this is a valuable thing to have if it’s not provided by your hosting service, but maybe you want very specific fine grain control over how your backups work or they’re sent, it’s the stash live is a particularly nice thing to have and working on making that more efficient is going to focus now. So just released some performance improvements for that. I was writing about that yesterday and working on that a little bit this morning. So those are really, they can be server intensive processes. It’s a real trick to figure out how to make sure that everything’s getting backed up and you’re not missing anything.
(17:53):
It isn’t stalling and you’re also not compromising the overall server performance because there’s so many backup, so many processes working in the background. Depending on what someone is installed, you might have several things going on at different schedules and if that’s competing with the front end traffic, that’s not good. So there’s always a trade off and yeah, I don’t know if you want to totally turn off, if I agree with that completely turning off everything that you might be better off with a headless type of site setup if you’re that concerned about front-end traffic, overwhelming things, but conventional WordPress setup. Yeah, there’s the more going on in the backend and the admin that isn’t cached usually and that’s putting more load on the processor memory and database and can compete with your front end traffic.
Rob (18:58):
So what I think you need to do is schedule your backups if you’re going to do ’em at the site level for an off peak time, so figure out when your low traffic time is and do it then and you don’t impact the other thing. And you and I have had this conversation offline, online, please test your backups before you need them because the backups only as good as the ability to restore. I’ve seen it in my days in enterprise where people go to pull a backup tape and the tape is blank or not complete. I’ve seen it happen and these are companies that know better. There’s a reason why banks and insurance companies and mortgage companies, investment companies all have what we call disaster recovery days to test their disaster recovery and the agency should really do the same thing as test the more test.
Dan (19:48):
Yeah, absolutely. There’s so much that can go into a backup and it’s a very unique thing. So a certain type of site may have complex backup requirements, there might be multiple WordPress sites that are packaged together, multi-site network or you have an extra set of directories that for some reason you want to be included or excluded and maybe that changes over time and someone doesn’t think to update, we no longer need to include this or we do. There’s this whole other piece of software alongside WordPress that, oh, we forgot to include that in the archive. There’s just so many scenarios and it’s something that has to be thought about consciously well before you need it. Otherwise then you realize, oops, we didn’t plan for something or this wasn’t configured properly or we’re just not in practice. We are not quite sure how to recover. So when you have that high stress moment of having to do a disaster recovery, yeah, it’s better to have trained for it ahead of time and have documented that and definitely give a client a secure document somewhere that says, here’s what his primary assets are, here’s here’s what you need.
(21:06):
If everything were to go sideways.
Rob (21:10):
I agree with you. One of the good things that WordPress has done is we no longer do version updates in December. That started last year. Since we moved towards Black Friday, cyber Monday, the Christmas shopping season, all of us guys like me used to cringe. December would roll around the first week and we’d have a massive update. I would encourage people to try and do their updates long before Black Friday, cyber Monday and just let’s stay away from your busy season because if something goes, it’s going to go.
Dan (21:46):
Yeah, and there’s a very important human side to that. Hosting companies too often, I remember some have had articulated their policies on holidays. They tell you they have human employees too who want to go home and travel and are doing all of that. So how many, they’re in a 24 7 business. They’re your partners. You trust them to be working all around. There’s some degree of vigilance that in certain jobs and roles like that, people are pulling maybe difficult hours and hazardous duty pay or something comes in or something, but knowing that, paying attention to that, what their holiday hours are, what the level of support is really important. And I like to see that when they do have a policy about it and they care about their employees enough that we’re thinking intentionally about this. We’re not all going to be here in the normal way, but here’s how we’re going to provide for that because it can be, things can go wrong at that point.
Rob (22:48):
I have spent many a holiday slaved over a server when I was in healthcare or over a workstation in the OR doing that. So I appreciate employers who do that because having been there and done that, it’s not fun, let me tell you.
Dan (23:03):
No. Yeah, it’s not what you want to be doing on holidays. And I think that’s just true around across the board, not just Western end of year holidays. Not everyone’s on the same calendar. Not everyone has the quite the same holiday thing. So I think you have to be a little mindful too of different audiences and hopefully the more people who think that way about the people they’re partnered with working in open source, it’s a global project and I’m glad that they did that because there was a lot of stress coming down on people, and everyone, even if you’re just going to run updates. So getting a version out and tested and then pushed out to everyone and then we go, do we update now or do we wait until the new year or there’s some security issues here. It was, yeah, kicking that down into the new year is definitely a stress saver I
Rob (24:00):
Think. And by the way, before you do an update, please do a backup right before the update People, I’ve seen so many agencies, they go into main wp, they push the update all button, oh, I’m done. And then they start getting calls saying, oh, this plugin broke, this plugin broke, and then they’re into troubleshooting mode. Why not just take a snapshot back up ahead of time and save yourself that whole aggravation really,
Dan (24:27):
And you can roll back quickly if something goes wrong or do a test first if you can on a staging site and make sure things aren’t going to go wrong before you push that out. It’s amazing how it works as you can get away with that a lot of the time maybe. But yeah, another useful case for having a backup plugin where you can take that archive before you change anything on that site and bring it back. Just a little rollback. I’ve used the rollback plugin for a long time and I think that’s been, I hope to see it eventually in core that’s been improved where if you have a single plugin update that goes wrong or for some reason you want to roll back to an earlier version, you can just do that internally.
Rob (25:12):
What I will say, kudos to your team. The solid backup is even better on tough Chrome job sites since the last couple updates and it’s ever been, and I’ve noticed that. I’ve got some big sites, I’ve got some big sites have managed WordPress hosts, different ones across the board that managed Chrome jobs differently and solid backup runs much better on those. So your team has done a really good job in cleaning up some stuff, so kudos to them.
Dan (25:42):
That’s good to hear. That’s been the focus, that’s been the goal. Yeah, they’re using the action scheduler and actually their lease just coming out now adds a little part, a little admin screen under the tool section where you can go and look at all the, it’s an alternative to kron and a more efficient way of doing tasks in the background that have to run at a different schedule. And anyway, you can go in there and look and see what’s going on, where if all the work the backup backups is doing in the background for you and make sure it’s working right, but seems like it’s gotten a lot of love lately and doing better than ever, but yeah, there’s so many different hosting configurations. Yeah, cron jobs aren’t accessible for a lot of site setups, so this is one way to get around that.
Rob (26:32):
What I thought also, we’ve touched on backups, we touched on host, we’ve touched on two FA. We have to touch on plugins and plugins can be the major pain in our backside, so to speak. We know that with the iThemes list. We also know a lot of developers and designers gear at them don’t clean up their plugin list very well, so I’ve seen sites with 30 and 40 plugins by the time I get them, they’re already in trouble. And then it’s like, what do I do here? And they leave stuff they’re not using, they don’t update stuff which they need to do and then they haven’t figured out that deactivating or plugin is not the same as removing it and plugins are not using, we should just clean up the code base and get it out of there. Where do you sit on plugin hygiene
Dan (27:31):
Yeah, there’s never really been a strong standard for that. Usually you find that there’s a lot of database tables left behind after you’ve uninstalled things. It’s pretty rare, but some plugins when we’ll give you at least a setting somewhere to wipe out all its database tables, I think the convention that’s evolved is let’s hope that they come back, they reactivate the plugin or they reinstall it and then we’ll still have their original settings in here and it’ll be less disruptive or I don’t know why they end up airing on the side of let’s leave all the existing plugin data in the database and that will slow things down considerably over time. If you have a bunch of tables that don’t need to be there anymore or if they’ve used added to post meta or something, there are a couple of plugin tools that will help you hunt down orphaned database tables and remove them, which I’ve done at many points, but that’s a little dicey.
(28:38):
It’s always hard to, you’re trying to identify what exactly here do I need or not, and it’s not always that clear. You might drop some tables that turn out to be critical, always backup before doing that kind of thing, but I really wish there was a standard on when you click uninstall on the plugin list, that right there, it gives you an option. Drop all the custom tables that this plugin has created, if it has created any, and identify those to you. You can make a smart decision or hook into something that the developer provides so that you don’t fail to export something you need.
Rob (29:19):
And then as we move forward, the other thing I would suggest and we really haven’t talked about is use an uptime monitoring service and choose one. Jetpack got one, there’s Uptime robot, there’s several others. They’re not foolproof and they generate some of them false positives, we know that, but at least they give you an idea when sites are going up and down. I can always tell on my managed server when my data center does the maintenance to say they’re going to do for 30 seconds or does a reboot because I see a whole pile of down sites and I see a whole pile of up sites. So do use something, know what sites are up or down. It’s a good idea.
Dan (29:59):
Yeah, that’s a feature we have had baked into Solid Central for a long time and I think there’s some that’s on the roadmap for adding to that and improving that. I’ve used a lot of different services for that. One I’m trying out lately is Better Stacks Uptime Monitor and there’s all different ones out there. Sometimes you want something that notifies multiple parties, provides an app or the kind of thing that you don’t want buzzing off and sending you alerts over the holidays, but that’s what it’s for.
Rob (30:33):
And then the last thing is, and I know you talked about with Nathan Ingram on solid wps, don’t use a malware scanner baked into WordPress because we all know the way malware scanners work is even if you use one on a PC or a Mac that’s in there, if the Pier Mac has compromised, there’s a good chance the malware scanners compromised. I should tell everybody at risk as a bit of a security guy, I don’t run a malware scanner on my Windows pc, so there you go, bring it on because I don’t think they’re a good idea. You need to run something outside of the ecosystem. And you and Nathan talked about that. Can you share a quick summary, some thoughts on that?
Dan (31:19):
Yeah, it’s come to light and beyond any doubt that the malware now is sophisticated enough to see that you’re running a security plugin like solid security or word fence or something like that. And if it’s on there, it can identify that and defeat those scanners in a number of ways. Wait list itself or neutralize your plugin, your security plugin, so it’s not going to help you. So since that’s already ineffective, it’s you need to get ahead of that at the server level. Hosting level scanning is going to be helpful and it’s also if that’s happening further up the upstream and on the network, it’s not going to compete with your server resources for your customers. So I don’t know that people using plugins with kind of virus like scanner, malware, scanner stuff in it, understand that is coming at a big trade off. If you have that running constantly or during business hours, it’s competing with your main purpose for your site, which is to load for customers and whoever’s visiting it. I would never use those either. I think it’s been a very long time since I’ve had one on a PC or something like that too. It’s just inherently insecure because if someone has gotten past your burglar alarm and they’re in the house, you can have no confidence of any further alarms helping you. It’s too close at that point.
Rob (32:57):
I love that analogy and it’s funny. And then the last thing people need to be really aware of, we’ve talked about all the WordPress mechanics, what do we do about security? What do we do about hosting? There is a human element and there is a thing called social engineering and being a bit of a student, even though I played in this space, one of the guys that talks about a lot about social engineering in this space is the late legendary hacker, Kevin Mitnick. He wrote about a book called The Art of Deception about how to you pick up the phone and how you call a business owner and you convince them, they give you their password and then they give you their password and then they wonder why two hours later the site’s down or worse there’s pharma scam or Bitcoin spam going on that site, redirecting everything else for us. So we got to make sure we’re aware of that as well.
Dan (33:52):
Absolutely. I do know that the stats are up on that and that because of AI making it easy to be write fairly fluently in a language you may not know, you can’t count on scams being low quality and invisible in that way. They can be very much more convincing. Now I’ve seen stuff where just the graphics involved faking a PayPal or some other official emails there.
Rob (34:18):
Roger’s communications in Canada, there’s scams out there where hackers have put Roger’s logos right in the scam. Come on guys.
Dan (34:28):
That’s a particularly vulnerable one because I am using Rogers now because I had Shaw and they bought Shaw and that transition wasn’t too awesome last week of my Internet went down. Yeah, unfortunately our CRA is notorious for yeah, there are systems like that that maybe your ISP is shady looking to begin with. You’re not too sure what’s going on. That doesn’t help. I really appreciate it when you get those messages that say we will never send you this. It will look like this. I think we need more of that going out. We probably need to be aware with that with a WordPress, this is what a legitimate WordPress core update looks like or that kind of thing. Actually I have a nonprofit in Milwaukee that I’ve taken through a number of different CMSs I think since 2006. And they’re a housing related organization and I’ve just done their web stuff for a long time. So their team has grown and changed over time and there’s new people. I have solid security on there and I sometimes hear from people that are new on the team.
(35:48):
There was someone I didn’t recognize, I matched a name up with an admin user on here who had been added. I saw a call coming in and it said New Brunswick and it was actually New Jersey and I thought, she’s not in Canada. I was thinking this was coming from the Maritimes and left a message that the recording was a little hard to hear and English accent and I was like, I setting off these, this is, I don’t know. And then checked her out on LinkedIn and and then matched up phone numbers and made sure I was talking to the right person because it was about domain access, control of domain registration, that kind of thing. And if you’ve freelanced or worked with managing domains for anyone for very long or even your own, there’s some pretty sophisticated ones. They’ll send paper out in the mail that happened that’s been going on for years where it’s maybe even borderline legal in the US or something where you’re actually signing over your ownership of the domain and they act like it’s a bill and that they’re the registrar and they’re not. But getting hold of domain access is really sensitive. Anyone asks for that. I want to make sure nowadays that I know who this person is. We’ve double checked it. Someone else in the Oregon,
Rob (37:05):
There’s one in the Mayo. I haven’t seen one those in a couple years, but they are out there and that’s a big deal and that comes with that social re-engineering. And the last topic I wanted to talk on the security side is forms spam and Ford form hacking. So I have to give a plug to my good friend Mr. Mark Westguard. He’s the founder over at WS Forms. It’s the form package I use on multiple sites. And what I do is I set up he has an interface with CloudFlare Turnstile and one of the cool things with CloudFlare turnstile is it stop so lot of the forms spam, the form hacking, that kind of stuff. What do you think about, and I think it’s a better end user experience than going to a cap show users dread captures. Have you ever sat with that stupid capture and tried to get
Dan (37:58):
It doesn’t work very well? Yeah, and it’s the terrible on a phone. I don’t know. The Google ones have all kinds of issues and I failed them many times either because I can’t see, I’m at my glasses like leaning over
(38:14):
Where is that part of the motorcycle or not and it’s dumb and you end up doing two or three of those or somehow it’s not implemented. No, captcha is great. I love that it’s another acronym instead of it’s a type of captcha, but I think CloudFlare invented that term. No captcha. So I was really happy when we implemented turnstile, CloudFlare turnstile as an option you can use on your site on login form and contact forms and things like that with solid security. And that’s a really good pick. I think it will probably spread and Mark smart to put that in there because you don’t even see it. There’s a couple of options, but you can set this up where it’s doing browser fingerprinting and other things like that and just being smart enough using ai. There’s some machine learning going on in that way. Way back at the beginning, I wasn’t a big fan of Cloud Flare. I found it difficult to use and bringing things down here and there, but they’re gotten so sophisticated and useful in so many of their services. This is probably one of the better new ones because your users won’t even see it if it’s working at its intended way. You just do your normal login and it’s identifying suspicious activity. So it will challenge bots and bad actors, but most people they will identify as the other. Okay, we’ve seen them.
Rob (39:43):
No kidding. Before we wrap up, as we go into the Christmas shopping season coming up Black Friday, cyber Monday, Christmas month, what would be your top three wins that a site owner could do today to make their site better security-wise going into the holiday season?
Dan (40:02):
Yeah, just it may be a little too close now to make major changes. I wouldn’t do that. You don’t want to commit to changing things that you haven’t tested well too close to a critical period like that. So the sooner the better, but not any really major changes. But performance I think is really the key here. And yeah, doing a plugin audit there is anything that really accesses the backend or makes Ajax calls to the heartbeat features where you’re actually loading the backend, making more intensive queries. Some plugins do that really poorly in inefficiently. There’s a number of guides. Kinta has a good one on identifying that. WP Rocket has a plugin actually for managing the, it’s a nice feature baked into WordPress for quite some time now where you’re checking the heartbeat, keeping live sessions and it can be used by developers a lot of different ways.
(41:07):
And if you have too many plugins that are pinging that and potentially making database queries, loading the backend, that can often be a source of slowdown. So you should know what all your plugins are and what they’re doing and how expensive they are in terms of query costs. If there’s a page that is slow loading now when a lot of people are on, it would be so much the worse load testing is a good to do early ahead of time before you have a big spike. So yeah, I see performance and security as pretty closely related because a poorly performing site is a down a site that’s gone down, which the same end result as getting hacked, at least in the sense you’re losing business if this is a commercial enterprise or simply for your brand going down is the common feature of failed performances as well as securities. I’d weigh those two things together and not run backend processes that don’t need to be like the malware scanner we talked about and don’t hang around in the admin if you’re running WooCommerce. Yeah, you don’t just, if everything is well tested and performant and running, well just let it run business over the holidays. You’re getting notifications elsewhere or checking through the app, but offloading as much as possible from WooCommerce to maybe a shipping platform, things like that. The less that your server has to do, the better really.
Rob (42:48):
I would agree with that. If somebody wants to get ahold of you, Dan to talk about your work at Stellar or anything else, how’s the best way to find you?
Dan (42:58):
Yeah, Dan, K-N-A-U-S can on Twitter still or whatever you want to call it, but I don’t know how much longer that’s going to hang on. But I’ve really loved the WordPress community there for a long time. I’m using Bob, I’m using LinkedIn more for myself and also getting our solid WP Company pages going. I interact with people there a lot. If that works for you. It’s often a good place to talk about deeper things in security and you just email me too, dan@liveinithemes.com address. So I’m always happy to chat with customers. And yeah, I’m really interested in what kind of feedback we might have from anyone who’s subscribing to the weekly vulnerability email. We made some changes to it that got some, I knew we get negative feedback. We had a little bug where our table of contents was out for a week or so and that’s where you just skimm and look at the ones you want and skip down.
(44:00):
So it was huge time saver and had that, unfortunately have that out for a week and people noticed. So I was glad they’re reading that they care that much and brought that back of course. But we’d like to bring more trend analysis into it and maybe we’ll always have that posted on the site each week, but the newsletter, maybe bring in some more content and talk about security trends and other things. But what would be most useful to our readers is a question I’ve had for a while and I’d love to hear from anyone who has thoughts on that.
Rob (44:31):
Awesome. And I’m Rob Cairns. You can find me at Rob Cairns on x, formerly Twitter, LinkedIn as well. I co-manage the WordPress Global Product Community Group. Come join us. There’s over 10,000 WordPress in that group now. And say hello. Rob Cairns here for Dan Knauss. Thank you very much for joining us and thank you to Bob Dunn, Bob WP for having us. Have an amazing day everybody.
Dan (44:56):
Yeah, thank you. Thanks Rob.







