
WordPress 安全很重要!
🇺🇸 A massive supply chain attack just hit over 1.2 million WordPress websites, and the lessons are loud and clear: even deactivated plugins can leave you wide open. If you run a site (or host them for clients), this is your wake-up call to tighten up security before the next breach.
🔥 The attack targeted three popular marketing plugins — OptinMonster, TrustPulse, and PushEngage. Hackers didn’t hit the plugins directly. They compromised external scripts these plugins loaded. When an admin logged in, the malicious code got full administrator access.
🛡️ Attackers weren’t just messing around — they installed hidden backdoors for long-term control:
- 偷偷摸摸的管理員帳戶(例如developer_api1或wpsecurebot)
- 隱藏在儀表板中的惡意軟體
- SEO 垃圾郵件、假瀏覽器更新,甚至是加密貨幣礦工
重點:刪除或停用插件是不夠的。如果曾經安裝過,請徹底掃描。
如何檢查和清理您的 WordPress 網站
- 檢查管理員帳戶 - 不要只信任使用者頁面。檢查 wp_users 資料庫表(或使用 WP-CLI)以尋找未知管理員。
- 檢查插件資料夾 - 在 wp-content/plugins/ 和 wp-content/mu-plugins/ 中尋找任何可疑內容。
- 更改一切 — 重設所有管理員密碼、重新產生鹽、更新資料庫密碼以及輪換 API 金鑰。
未來的智慧安全實踐
- 徹底刪除未使用的外掛程式和主題-停用≠安全。
- 使用可靠的活動日誌外掛程式(如 WP 活動日誌)來監視變更。
- 新增雙重認證和暴力保護。
- 保持一切更新並定期執行惡意軟體掃描。
🇺🇸 America-first take: In a digital world full of threats, real security comes from ownership and vigilance — not trusting third-party scripts or “set it and forget it” plugins. Self-hosted WordPress on reliable hosting (with server-level protections) gives you the control you need to protect your business and data.
HostRite 等託管提供者添加了額外的層(監獄主機隔離、每日備份、伺服器級封鎖),但網站所有者仍然必須盡自己的一份力量。
你們覺得怎麼樣?遇到過類似的事情,或者為 WordPress 用戶提供了強大的安全提示?下面分享一下!
