Category: WordPress how-to's

How to Detect and Prevent Unauthorized Access in WordPress

Published on March 27, 2025

This article was originally authored by Robert Abela of Melapress, a Patchstack partner specializing in WordPress security and user management solutions. Unauthorized WordPress access is more common than you might think. Learning how to detect and prevent WordPress unauthorized access can help you avoid security incidents. And if they do happen, you’ll be able to […]

Read more →

How & Why You Should Remove Unused WordPress Plugins

Published on January 14, 2025

As a seasoned WordPress developer, you might have spent countless hours perfecting your WordPress site by carefully selecting themes and plugins to create an outstanding experience. But did you stop and think about all the plugins that you no longer need? If you have numerous plugins installed on your WordPress site, you should consider removing […]

Read more →

How to Fix the WordPress Redirect Hack

Published on December 24, 2024

As a WordPress site owner, dealing with the aftermath of a redirect hack can be a daunting and frustrating experience. Malicious actors are constantly finding new ways to exploit vulnerabilities and hijack your website, redirecting your visitors to spammy or malicious destinations without your knowledge or consent. In this comprehensive guide, we’ll walk you through […]

Read more →

How to Configure the X-Frame-Options Header in WordPress

Published on December 22, 2024

When you visit any website on the internet, the server delivering the web page instructs your browser on how to process this information by passing meta-data called headers. In this post, we’ll explore the importance of the X-Frame-Options header in WordPress and how to configure it. Additionally, we will consider a modern replacement for X-Frame-Options, […]

Read more →

How To Protect WordPress Against Cross-Site Scripting Attacks (XSS)

Published on December 22, 2024

Cross-site scripting (XSS) is an exploitation technique that allows hackers to run arbitrary code on a compromised website. Needless to say, it is a serious risk for any web application, and our experts at Patchstack regularly receive notifications about new XSS vulnerabilities being discovered. In this post, we will discuss what cross site scripting is […]

Read more →

Understanding Cookie Stealing Attacks: How They Work and Their Impact on WordPress Users

Published on December 21, 2024

If you stay up to date with cyber security news, you might have heard of Google’s Threat Analysis Group discovering a financially motivated phishing campaign targeting YouTubers. Researchers found that attackers lured creators with fake collaboration opportunities (such as anti-virus software demos or VPN offers). Once the target agreed, they sent malware disguised as software […]

Read more →

The Last WordPress Security Checklist You’ll Ever Read

Published on December 1, 2024

Is your WordPress site secure? You might think so, but are you prepared for the unexpected? The whitehat researchers at Patchstack found that most WordPress vulnerabilities arise not from the core platform but from overlooked weaknesses and easily preventable mistakes. While the WordPress Core is secure, plugins, themes, and user practices can introduce vulnerabilities. Securing […]

Read more →

Protect Your Store: The Ultimate WooCommerce Security Checklist

Published on November 15, 2024

When you get hacked, it’s too late to think about security. However, getting started with securing your WooCommerce store (or the stores you create as a developer) isn’t always easy. So in this checklist, I’ll give you actionable pointers for understanding security and moving through the actions to ensure you cover all the bases. Ready? […]

Read more →
Page 1 of 3 Next