How to Avoid Insecure or Hacked Plugins

One of the main reasons for virus or malware infection in WordPress, Joomla or most CMS are plugins, modules or components. Either because they have not been updated or because you have installed a plugin from unsafe sources.

In any case, you can make sure you install only plugins or secure components if you know some basic steps. We’ll explain them to you below.

What is an Insecure Plugin

It is sometimes easy to recognize an unsafe plugin or component. If you take some time to develop, some of these steps are sure to be internalized. However, it helps to have a checklist to avoid surprises such as infections or viruses. Some reasons to avoid installing a plugin are:

  • The plugin does not have a GPL license
  • It has not been updated for years
  • Does not comply with some of the official repository rules
  • Other plugins by the same author have some problem
  • The author requests that he withdraw
  • It is being investigated because it has generated some type of problem
  • It contains some unresolved security vulnerability

How to Avoid an Unsafe Plugin

In addition to checking the above list, you can carry out some actions that will ensure the integrity of your website. At least as far as plugins or components are concerned.

  • Install only frequently updated plugins or components. This ensures a periodic maintenance. Normally it is not advisable to install plugins that:
  • Do not have valuations or comments
  • Upgrade is more than 1 year
  • Not tested with your version of WordPress, Joomla or CMS
  • Scan frequently for vulnerabilities and malware
  • Making backups of your WordPress, Joomla, Drupal or web
  • Protect your website against possible vulnerabilities without solution, or change to a more secure and updated plugin. The typical problem of unpatched vulnerability. You can consider switching to another plugin or component that runs the same functionality or have extra protection.

All of these tips will help you to have a secure web before the thousands of attacks daily. So you will not have to recover and disinfect your website.

How to Avoid Insecure or Hacked Plugins was last modified: June 24th, 2017 by WeSecur