I have had two WordPress blogs hacked into in the past. That was at a time when I was doing very little internet marketing, and until I found time to address the situation (months later), these sites were penalised in the search engines. They were not removed, but the rankings were reduced.

Finally, clean hacked wordpress site will tell you that there is not any htaccess from the directory. You may put a.htaccess file within this directory if you desire, and you can use it to control access to the directory from IP address or address range. Details of how to do that are available on the net.

The approach, and the one I personally recommend, is to use one of the creation and storage plugins available for your browser. I think after a trial period, you have to pay for it, although RoboForm is liked by Lots of people. I use the free version of Lastpass, and I recommend it for those who use Firefox or Internet Explorer. That will generate passwords for you.

Move your wp-config.php file one directory up from the WordPress root. WordPress will look for it if it can't be found in the root directory. Also, nobody else will have the ability to read the document unless they've FTP or SSH access to your server.

You don't always consider needing security Whenever your site is new but you do need to protect yourself and your investment. Having a site go down and not being able to restore it may mean a major loss of consumers who can not find you and probably won't remember to search for your site again later. Do not let this happen to you. Back up your site after you get it started, and schedule frequent backups for as long as the website is operational. This internet way, you will have WordPress security and peace of mind.

