
WordPress 安全很重要!
🇺🇸 A massive supply chain attack just hit over 1.2 million WordPress websites, and the lessons are loud and clear: even deactivated plugins can leave you wide open. If you run a site (or host them for clients), this is your wake-up call to tighten up security before the next breach.
🔥 The attack targeted three popular marketing plugins — OptinMonster, TrustPulse, and PushEngage. Hackers didn’t hit the plugins directly. They compromised external scripts these plugins loaded. When an admin logged in, the malicious code got full administrator access.
🛡️ Attackers weren’t just messing around — they installed hidden backdoors for long-term control:
- 偷偷摸摸的管理员帐户(例如developer_api1或wpsecurebot)
- 隐藏在仪表板中的恶意软件
- SEO 垃圾邮件、虚假浏览器更新,甚至加密货币矿工
要点:删除或停用插件是不够的。如果曾经安装过,请彻底扫描。
如何检查和清理您的 WordPress 网站
- 检查管理员帐户 - 不要只信任用户页面。检查 wp_users 数据库表(或使用 WP-CLI)以查找未知管理员。
- 检查插件文件夹 - 在 wp-content/plugins/ 和 wp-content/mu-plugins/ 中查找任何可疑内容。
- 更改一切 — 重置所有管理员密码、重新生成盐、更新数据库密码以及轮换 API 密钥。
未来的智能安全实践
- 彻底删除未使用的插件和主题——禁用≠安全。
- 使用可靠的活动日志插件(如 WP 活动日志)来监视更改。
- 添加双因素身份验证和暴力保护。
- 保持一切更新并定期运行恶意软件扫描。
🇺🇸 America-first take: In a digital world full of threats, real security comes from ownership and vigilance — not trusting third-party scripts or “set it and forget it” plugins. Self-hosted WordPress on reliable hosting (with server-level protections) gives you the control you need to protect your business and data.
HostRite 等托管提供商添加了额外的层(监狱主机隔离、每日备份、服务器级阻止),但网站所有者仍然必须尽自己的一份力量。
你们觉得怎么样?遇到过类似的事情,或者为 WordPress 用户提供了强大的安全提示?下面分享一下!
