
Keamanan WordPress Itu Penting!
🇺🇸 A massive supply chain attack just hit over 1.2 million WordPress websites, and the lessons are loud and clear: even deactivated plugins can leave you wide open. If you run a site (or host them for clients), this is your wake-up call to tighten up security before the next breach.
🔥 The attack targeted three popular marketing plugins — OptinMonster, TrustPulse, and PushEngage. Hackers didn’t hit the plugins directly. They compromised external scripts these plugins loaded. When an admin logged in, the malicious code got full administrator access.
🛡️ Attackers weren’t just messing around — they installed hidden backdoors for long-term control:
- Akun admin licik (seperti developer_api1 atau wpsecurebot)
- Malware disembunyikan dari dasbor
- Spam SEO, pembaruan browser palsu, dan bahkan penambang kripto
Kesimpulan utama: Menghapus atau menonaktifkan plugin saja tidak cukup. Jika pernah diinstal, pindai secara menyeluruh.
Cara Memeriksa & Membersihkan Situs WordPress Anda
- Tinjau Akun Admin — Jangan hanya percaya pada halaman Pengguna. Periksa tabel database wp_users (atau gunakan WP-CLI) untuk admin yang tidak dikenal.
- Periksa Folder Plugin — Cari di wp-content/plugins/ dan wp-content/mu-plugins/ apakah ada yang mencurigakan.
- Ubah Segalanya — Setel ulang semua kata sandi admin, buat ulang garam, perbarui kata sandi basis data, dan putar kunci API.
Praktik Keamanan Cerdas di Masa Depan
- Hapus sepenuhnya plugin dan tema yang tidak digunakan — Dinonaktifkan ≠ aman.
- Gunakan plugin log aktivitas yang solid (seperti WP Activity Log) untuk memantau perubahan.
- Tambahkan autentikasi dua faktor dan perlindungan brute force.
- Selalu perbarui semuanya dan jalankan pemindaian malware secara teratur.
🇺🇸 America-first take: In a digital world full of threats, real security comes from ownership and vigilance — not trusting third-party scripts or “set it and forget it” plugins. Self-hosted WordPress on reliable hosting (with server-level protections) gives you the control you need to protect your business and data.
Penyedia hosting seperti HostRite menambahkan lapisan tambahan (isolasi Host Penjara, pencadangan harian, pemblokiran tingkat server) namun pemilik situs tetap harus melakukan bagiannya.
Bagaimana menurut kalian? Terkena hal seperti ini, atau mendapat tips keamanan yang kuat untuk pengguna WordPress? Bagikan di bawah!
