Blog / security monday
Notes from the field.
Short, practical pieces on the problems we fix most often. No trends, no fluff.
4 min
Spam Sent From Your Email? Here's What to Do
What a compromised hosting mailbox looks like from the server side, and the order to work through locking it down, cleaning it up and keeping it shut.
4 min
What File Permissions Should WordPress Use?
The file permissions WordPress needs on a cPanel account, why 777 is never the fix, and a ten-minute check you can run today.
4 min
Old Site Copies Are a Security Risk
Abandoned staging folders, /old directories and backup zips are a common way into a hosting account. Here is how to find and clear them out.
4 min
Who Still Has Access to Your Website?
A quarterly access review takes about twenty minutes and closes the door on old developer accounts, stale FTP logins and shared passwords.
4 min
How to Spot Phishing Emails About Your Site
Phishing aimed at website owners is specific and convincing. Here is how we tell a fake renewal, host or plugin email from a real one.
4 min
How to tell if a WordPress plugin is safe
Plugins are a common way WordPress sites get broken into. How to vet one before you install it, and how to spot the ones going quietly stale.
4 min
How to keep your domain name from being stolen
Domain hijacking usually starts at the registrar, not the server. Here is how to lock your domain, protect the account email and stay on top of renewals.
3 min
What a hacked site looks like from the server side
The signs we see on our servers when a site is compromised, from outbound spam to rogue admins, and why cleanup fails without finding the way in.
3 min
SSL beyond the padlock
Getting a certificate is the easy part: this Security Monday covers redirects, HSTS in plain terms, mixed content and keeping renewals boring.
3 min
Backups that actually restore
A backup only counts if it restores, so this Security Monday covers restore testing, retention, offsite copies and what your host does and does not do.
3 min
Nothing is broken: why you still need updates
Most hacked sites we clean up were running software with a known, already-patched hole, so here is how to update without fear of breaking things.
3 min
Passkeys, 2FA and your hosting account
Your hosting account controls email, DNS and every file on your site, so here is how we lock ours down and who should still have access to yours.
3 min
The five WordPress security habits that stop most hacks
The five habits we see separating clean WordPress sites from hacked ones on our servers, and how to make each one part of your routine.
Nothing matched. Try a different word.