We recently launched our Monthly Security Reports that give you valuable information about what we’re doing to secure your site and highlight measures you may have overlooked. As we have seen a great interest in the reports and given the fact that website speed is just as important as website security, we’ve decided to provide you with yet another useful feature – Monthly Performance Reports. These reports will inform you about different areas related to your website speed and will help you identify things that may be improved.
What you’ll find in the Monthly Performance Reports
Each month we’ll automatically check a number of performance categories for your site: cache ratio, CDN usage, data center and network speed, WordPress optimization, and others. Then, you’ll receive a report with the results which will include your total website performance score, a breakdown score for each category, and actionable recommendations if some areas need improvement – straight to your inbox.
What are the benefits of the Monthly Performance Reports
Easy and regular access to information
With our Monthly Performance Reports you will be receiving regular information about your site status, delivered by email. It will include important areas that may be hard for our clients to check themselves on a regular basis. For example, we will be monitoring what percentage of your traffic is served from the cache each month (the higher the percentage, the faster your site is) and will inform you if this ratio is not optimal.
Actionable tips
On top of all that, you’ll get actionable tips in case any of the performance categories need improvement. We’ll let you know how to make the most of each optimization option that is available on our platform with clear and easy instructions. Let’s say that we identify you’re not using our Dynamic cache option, or our CDN, or our WordPress Optimization plugin. In such a case, we’ll notify you about this and provide you with information on why to use it and how to switch it on.
User-friendly structure
You’ll be able to quickly scan through the results and spot the tips in an easy-to-follow, color-coded structure of the report. You’ll also get an overall score for the month both in points and percentages, as well as a comparison of how it has changed from the previous month.
How to receive your Monthly Performance Reports
You get this feature for free and it’ll be available for you if you are a site owner of at least 1 active website.
We will gradually begin to proactively send the reports to all our clients, but you may sign up yourself today to be among the first to receive their report.
As of February 28th, 2023, all clients using our CDN have been migrated to its latest version, SiteGround CDN 2.0, providing faster and even more efficient site performance. Our in-house built CDN is included for free in all our plans, so all new clients will also be able to activate it.
Website loading speed may have a serious impact on search engine standings, bounce rates and sales conversions of your site. As a web hosting provider we are able to contribute to your website’s success by helping it load faster. That’s why at SiteGround we’re constantly implementing new speed-enhancing technologies that are more powerful and easier to use for our clients.
One of our latest products, that ensures faster sites for our clients, is our custom-built CDN. Just a few months after its launch, it is already used by hundreds of thousands of domains. We have seen the service has a considerable positive impact on our clients’ website performance and we are also receiving a steady flow of positive feedback from the users.
To improve the service even more, we have just deployed version 2.0 of SiteGround CDN. It employs the power of anycast routing and Google network edge locations and thus increases the website loading speed by 20% on average and may go up to 100% for visitors located in some specific parts of the world.
Why is the CDN 2.0 faster?
As you probably already know, the idea of the CDN (Content Delivery Network) is to keep a copy of your website on multiple locations called points of presence (PoPs) around the globe. When you have website visitors located far away from the original server that hosts your site, the CDN allows them to see a version of your site from the closest PoP. Thus the time needed for the data to reach your visitors is shorter than if it was served by the original server and your site loads faster. The closer your visitor is to a PoP the shorter the time it takes your site to load.
But apart from the geographical distance between the visitor and the PoP there are, of course, other factors that influence the speed with which the PoP is reached. It makes a difference if the data travels through the public network or through the much faster Google Cloud internal network.
In our initial CDN setup each PoP had its own unique IP address and required the central DNS system to calculate the distance between users and PoPs, determining the best routing through the public network. Now in the CDN 2.0 we have implemented an anycast layer which ensures that IP addresses remain the same for all our PoPs. This way we eliminate the DNS layer calculations and clients requests are automatically routed to the closest edge location of Google network. Once the request reaches the edge location, it enters the much faster Google Internal network and reaches the closest SiteGround CDN PoP almost instantly. So now the closer your visitors are to the network edge location, the faster your site loads.
The great news is that Google Cloud network already has 200+ edge locations around the globe, which means that most visitors are always very near one of these. Also whenever new such points are added by Google, they will naturally make our CDN faster in new regions.
What are the benefits of the CDN 2.0?
Faster sites and better TTFB
Due to the implementation of the anycast routing and the fact that we are able to take advantage of the extraordinary speed of the Google internal network, now millions of visitors of the sites that use our CDN service will have better experience and have the requested sites load faster.
Time to First Byte (TTFB) is a measurement of the time it takes for a browser to receive the first byte of response data from a web server after making a request. When comparing the first byte response times from more than 50 locations the TTFB improvement is around 20% on average and up to 100% in regions that were further from the SiteGround’s CDN PoPs.
Higher CDN reliability
CDN 2.0 is backed by cross-region load balancing, including automatic multi-region failover which allows them to react instantaneously to changes in users, traffic, network, backend health, and other related conditions. This helps to ensure that the content remains available, even in case any of the CDN PoPs goes down.
How to get the CDN 2.0?
Starting from the middle of February, we will gradually switch both the Free SiteGround CDN users and the Premium SiteGround CDN users to the new version of the service. The process wouldn’t require any action on the client’s end and will be fully automated. If you are still not taking advantage of our CDN, it is a great time to add CDN to your site now through your client area.
Do you know how secure your site is and if its security level is changing over time? Have you ever wondered how many actual attacks toward your site are being mitigated? Do you want to know if you have missed doing something easy that may protect your site from incidents?
Now with SiteGround’s Monthly Security Reports, you can get all that information and more – straight to your inbox. Just sign up and start receiving an actionable monthly report covering what SiteGround is doing to safeguard your site and highlighting security measures that you may have overlooked.
What’s in the Monthly Security Reports?
Each month we will perform automated security checks for your website covering malware protection, SSL certificates, software exploits, brute force attacks, and other security areas. Based on our checks, you’ll receive a digestible summary of the results – including a total site security score, breakdown score for each security check, and actionable tips if some area needs your attention. The monthly security reports will be your go-to place to get an overview of your website security status.
The benefits of the Monthly Security Reports
Site security information in one place
Performing website security checks manually can be an investment of valuable time, effort, and money that most website owners can’t commit. With the monthly security reports, SiteGround will handle the heavy lifting for you, performing all necessary security checks and delivering user-friendly reports straight into your inbox. So you get to know everything with no effort required on your side.
Easy to understand format
With our user-friendly design, you can quickly scan the report and easily identify areas that need your attention, if any. All you have to do is follow our straightforward color codes: green when everything is good; yellow: needs improvement; red: definitely needs attention. You also receive an overall score for the month and information how it has changed in comparison with the previous month.
Actionable advice when needed
If we have identified an area of your site security that may be improved, the report will include easy-to-follow instructions on what can be done. For example, if we detect that you don’t have an SSL certificate installed on your site, it will provide you with a link to the information on how to set it up.
Confidence that your website is protected
By signing up for our monthly security reports, you may easily monitor what we do on a regular basis to keep your website safe. Each month you will see information like: how many software vulnerability attacks have been prevented; how many malicious IPs were stopped from reaching your site; how many backups you may count on, etc. Making sure your site is secure is an enormous part of our job as a host, and with the reports you can keep an eye on this process.
How to get the Monthly Security Reports?
Starting from next year we will gradually begin to proactively send the reports to all our clients. However, you may hurry up and sign in yourself today and be among the first to receive their report in early January 2023.
The reports are sent out at the beginning of each month for sites that have been active for more than 30 days and have their domains pointed to SiteGround. You can see detailed information on subscription, content and score calculation in our Security Reports Explained article.
Sign up today and sleep soundly, knowing that all relevant site security information is right at your fingertips.
When you’re busy processing tons of emails each day, and we all are, the last thing you need is a bunch of spam messages sneaking into your inbox. Spam protection has always been an important part of our email service and in our strive to constantly improve it we are now introducing a new in-house built solution. It is designed to efficiently minimize the amount of SPAM emails delivered to your inbox, while constantly learning from your email reading behavior. It is also built specifically for our clients and works seamlessly as part of our hosting environment.
Efficient and easy to use for our clients
Less SPAM messages delivered to your inbox
Based on our multiple years of managing email services, we have created a system that decides with a high amount of accuracy which messages are legitimate and should reach your inbox, which are suspicious and should be delivered in your Junk folder, and which are outright dangerous and should not reach your email at all and will bounce instead.
Your email reading behavior trains the system
Your natural actions, while working with your mailbox will train the system. Whenever you move a message to or from your Junk folder you will improve its accuracy. Based on your action the system will add your personal perception of what is SPAM on top of its own underlying rules. Thus your feedback is taken into account seamlessly, without a need for you to use an additional SPAM management interface.
Easy interface to allow and block senders
And also, if you would like to tell the Spam protection system directly how to treat a certain sender, you can still use our easy interface to block or allow specific senders. By adding an email address or an entire domain to the Block or Allow List you indicate how you want this sender to be treated by the system. Check the following tutorial on how to use the Spam Protection service in Site Tools.
Better control and easier scalability for us
We may address our clients’ needs
By using an in-house solution we can more easily address our clients’ specific needs and introduce new features and improvements faster. For example, we have noticed that the current setup makes it difficult for our users to find out when a legitimate email is not delivered to them and is marked as spam by the system. This happens because the message is placed in a quarantine folder in a separate tool that is not part of the user’s natural email management. With the new solution we were able to address this issue by using the much more visible Junk folder instead.
We may handle email usage spike better
When we manage the spam protection system as part of our own infrastructure, we can easily scale it. Even if there is a steep global increase in the email traffic we can seamlessly add the resources needed for the evaluation of the excessive messages. Thus the email delivery will not be delayed for our clients, regardless of the unexpected usage spike.
How to use SiteGround Spam Protection?
All SiteGround clients have our state-of-the-art Spam Protection features enabled by default.
When changing your hosting provider, sometimes it is not only about moving your website and pointing your domain to the new server. If you also use email services as part of your hosting plan, the most challenging part of the process may be transfering your email accounts and messages without losing data or creating disruption to your business communication process. To address this challenge for people, who prefer to have everything hosted at one place, we have now added a new Email Migrator tool. It allows you to transfer your mail service from another server to our mail servers fast, easy and securely.
Why did we develop the Email Migrator
SiteGround clients who are transferring from other hosting providers already benefit from our automatic website transfer options. The Email Migrator tool streamlines this process even further, making the transfer of email services possible in just a few clicks, even by not so tech-savvy users. On top of that, the tool helps you keep your email communication intact and safely transfer all of it to our servers.
What are the benefits of our Email Migrator tool
In addition to making it easier to transfer your emails to SiteGround and have everything in one secure place, our Email Migrator has a couple of other added benefits:
Intuitive interface for easy migration start 🏗️
The tool interface guides you through the few steps needed to get the process started.
Secure and reliable transfer 🛡️
We’ll move your emails in a secure manner, ensuring privacy and data protection.
Fast migration 🚀
We’ve developed the tool in a way that the procedure won’t take too long. Yet, the exact time needed will depend on different factors, such as the size of the mailbox, remote server speed, and others.
Keeping the structure of the email account being migrated 📧
We’ll transfer your email account for you, including folders, messages and attachments.
No duplicates created 📑
We’ll make sure that there are no duplicates created during the migration process.
Automated process 🪄
There’s no manual work required on your end, as the migration happens in the background. You’ll need, though, to set up the systems that are beyond SiteGround control: point your MX records to make the new messages come to our server and reconfigure your email client to start receiving the messages from our server.
How to transfer your emails with the Email Migrator
To transfer your emails, you need to follow a few simple steps in your Site Tools > Email > Email Migrator. Read detailed instructions on how to transfer your emails and enjoy a hassle-free email migration to SiteGround!
The Email Migrator is basically the last piece of the puzzle that lets you have everything in one place. Transferring all things to SiteGround allows you to easily manage both your website and email in one account. Not only do you have everything in one place, but you’re counting on our proven expertise in both web hosting and email services.
Last week, we helped you get your website ready for the Black Friday traffic spikes. Now that you’re all set to handle the upcoming traffic, do you know how much of it is real and how much – non-human? According to Statista, in 2022 more than 40% of Internet traffic is from bots, and a significant portion of that is bad bot traffic. This kind of bot traffic hurts your online business and can lead to both financial and conversion losses. Let’s dig deeper into what bot traffic is, why most of it is so harmful, and how to avoid it during the busiest time of the year.
What is bot traffic and why it should be cut down to a minimum
Bot traffic is any non-human traffic that comes to a website or app. Some of it is good, when it originates from SEO crawlers (such as Google crawl bot), commercial, site-monitoring, or feed bots. Needless to say, all of these cause no harm to your site. On the other hand, bad bots come with malicious intent. These can leave spam comments, irrelevant backlinks, weird advertisements, collect private information, reuse your content, perform DDoS attacks, and other malicious activities.
How bad bot traffic affects your website
Bad bot traffic may have different consequences on your website and business, causing multiple damages:
Website security and availability damage
Bad bot traffic hurts your website security and availability. For instance, these massive amounts of traffic to your site are a way for hackers to cause a DDoS attack. During such an attack, the traffic is so massive that the server where your site is hosted cannot handle it. This can make your website slow, unreliable or even unavailable for your users.
Bad bots are also the main force of a brute-force attack – a way to guess your password/login details by trying numerous combinations of letters, numbers and symbols. If such an attack is successful, malicious hackers gain access to your account and/or private information.
Website speed issues
Even if it doesn’t cause massive hacker attacks, bad bots activity can make your website much slower or even unavailable for your real visitors, affecting their overall user experience. To have your visitors stay longer on your site and turn them into clients, you’d want them to have an excellent user experience. A huge part of that is your website loading speed being as fast as possible.
Analytics metrics and SEO rankings chaos
Bad bot traffic can also hurt your analytics metrics and SEO rankings. For example, too much bad bot traffic can bring your site down and cause 503 errors (“site is temporarily unavailable”). This directly negatively impacts your SEO rankings. What is more, bad bots can affect your analytics metrics, causing abnormally high pageviews and bounce rates, sudden drop/increase in session durations, and fake conversions. All these factors may confuse you as a site owner and you may not be able to make sense of your analytics data.
How we decrease bad bot traffic at SiteGround
At SiteGround we take multiple measures at different levels to reduce bad bot activity by default for the websites hosted on our servers, so you can have peace of mind.
Improved and advanced AI anti-bot system
Our AI anti-bot system has successfully been blocking millions of brute-force attempts per day. Recently, we improved it even further, resulting in 95% less bad traffic. Its core features are still there – analyzing and recognizing traffic patterns to eventually stop brute-force attempts. With each new brute-force attempt, the system’s knowledge expands and it gets better at preventing future attacks. As of recently, we’ve upgraded the system with a traffic validation feature that stops even more malicious non-human bots by minimizing the number of brute-force attacks. Currently, the system blocks a huge percentage of bad bots traffic towards our servers, allowing more capacity for your websites for legitimate traffic.
Combined with our enterprise-grade security system, these server-level security optimizations block the majority of all bad bot traffic and ensure website protection on a global scale. Let the numbers speak for themselves – 99,99% of bad traffic is blocked before it even reaches your website.
Smart, server-level WAF
Hacker attacks usually increase during the Black Friday season. A single outdated WordPress plugin, theme, or vulnerability can easily be used for massive damages during this busiest time of the year. That’s where our smart Web Application Firewall comes to the rescue. Our security experts closely monitor security bulletins and server activity 24/7, and in case of reported exploits, immediately add custom WAF rules (patches) into our server firewall to protect your site from current hacks and breaches due to outdated plugins, and other vulnerabilities. Our proactive security approach allows us to react much faster, often before the original plugin, theme or app developers have had the chance to release an official update. The most recent example of this was just last month, with two previous major ones not so far behind – a plugin vulnerability patched on day 0, and a Linux Kernel vulnerability patched within hours of detection.
DDoS protection
To address potential DDoS attacks from bad bots, we have a system of hardware and software mechanisms to protect your sites:
A hardware firewall that filters flooding traffic;
A local software firewall with more complex functions and traffic monitoring;
А limit to the number of connections a remote host can establish;
A check for a high number of failed login attempts from hosts and filtering them, if any.
24/7 server monitoring system
Again, in addition to all monitoring and prevention systems and checks in place, our expert system administrators team are monitoring our servers 24/7 for any system issues and in case of any, can react quickly to save the day.
How to identify that you have bad bot traffic coming to your site
Now, you probably wonder what are some signs and symptoms of bad bot traffic that will help you identify whether your site is in danger. Here are some of the red flags and ways to prevent them:
Check your site traffic stats
You also need to check your traffic statistics, especially the IP addresses and the sources of traffic. For example, regular and high number of visits from the same IP address or increase in traffic from other regions or countries, from which you didn’t have (much) traffic before, could be an indication of bad bot traffic. As a SiteGround customer, you can easily check your traffic statistics in Site Tools > Statistics > Traffic.
Keep an eye for unusual users’ behavior
Remember to monitor your users’ behavior regularly. In case there are increased spam comments under your posts, strange user registrations, and/or increased blocked login attempts, these are all red flags that you might be getting bad bot traffic to your site. WordPress users, who have the free SiteGround Security plugin installed, can monitor their site and login page for unauthorized visits and brute-force attempts from their Activity Log menu. What is more, they can easily block suspicious IPs and visitors.
Make regular speed tests
You probably already do that, but if you don’t, it’s a good idea to start making regular website speed tests. For this purpose, you can use a number of different tools to measure your site speed, such as Google PageSpeed Insights, Pingdom, GTMetrix, and others that generate results in all the major speed metrics.
In case you have the free SiteGround Optimizer plugin installed on your WordPress website, you can run a speed test within the plugin in its Speed test functionality. The check uses Google PageSpeed, provides information on the level of optimization in over 20 different areas, and gives you optimization suggestions.
If you identify that your site is experiencing page loading speed issues, dig deeper into the problem to find out the causes. These might not necessarily be bad bot traffic issues, but that’s one of the main potential reasons behind the slow speed results.
How to filter bad bot traffic yourself on SiteGround
Some of the traffic that reaches your websites may seem legitimate, even if it’s not. Thankfully, there are a number of ways and free services we offer to let you filter good from bad website traffic all by yourself:
Both options allow you to easily block suspicious or malicious traffic to your website. If you want to block a specific IP address from accessing your site, because, for example, you see it’s using too much bandwidth, you simply go to Site Tools > Security > Block Traffic, choose the domain for which you want to block access, then add the IP address (or a whole range in IP/IP Range), and finally click ‘Block’.
Similarly, if you notice that you get suspicious abnormal activity from a country you don’t usually operate in or have clients from, you can easily block traffic from it in a few clicks. You need to go to Site Tools > Security > Block Traffic > Block Country. There, you choose the domain for which you want to block access, pick the desired country to block in the Country dropdown, and finally click ‘Block’.
These two options will help you not only block bad bot traffic coming to your site, but they can also significantly improve your site performance by reducing the unwanted traffic and giving your site more capacity to handle real human traffic.
Improving your site capacity to handle more requests
In case you’ve identified that your site still gets some bad bot traffic which cannot be easily filtered or removed, you can decrease its negative impact by improving your website speed and performance, which will allow more capacity to handle any type of traffic altogether. Here’s how to do that:
We’ve developed a powerful caching system to help you cache as much content on your website as possible. Cached content is served much faster to visitors and thus improves your site capacity to handle traffic. Our system is comprised of three caching options that are all available in your Site Tools > Speed > Caching: NGINX Direct Delivery for caching static content, such as images and CSS files; Dynamic Caching for dynamic content to be stored in the server RAM, and Memcached for storing data and objects in memory (best for database-driven websites).
Use our other optimization services
We do a lot to improve website performance and you can make use of our premium solutions. Here are three of the main ones that can speed up your website and make room for more visitors’ requests.
Our in-house developed SiteGround CDN requires no configuration, it’s easy-to-manage with just a few clicks, and above all, makes your site load blazingly-fast for visitors around the world. Its Basic version comes completely free of charge and provides your site with all the essential features to handle international traffic from various international locations.
Another in-house developed speed tool is the free SiteGround Optimizer plugin for WordPress websites. It provides you with many different optimization options (media, frontend, environment) that can all be enabled in a few clicks.
Last, but not least, our unique ultrafast PHP setup makes your pages load up to 30% faster and allows the server to process your website’s visits quicker.
Wrap-up
While most people are busy selling and buying goods and services during the Black Friday period, bad bots are also more active than ever, “visiting” websites and causing all kinds of potential issues. If not addressed on time and in the proper manner, they can ruin a big chunk of your holiday conversions during that time of the year, when you worked hard to get the highest number of sales.
Building and maintaining a strong website security is a constant process that often gets neglected by website owners due to its complexity, time consumption and cost. As a hosting provider, we know better. Over 18 years of experience in hosting, maintaining and securing millions of websites has taught us that website security is absolutely critical for every online business. We have seen the devastating consequences a hack can have on a website and ultimately on a business, and we have dedicated serious efforts to preventing and minimizing the effects of hack attempts.
Over the years, we have optimized the security of our platform by developing sophisticated security systems, introducing a variety of security tools, plugins and features, and constantly analyzing and monitoring traffic and patterns to recognize potential threats. While all of this has made us one of the most secure and trusted web hosting providers in the world, we know that platform security on its own, is not enough. The involvement of webmasters and site owners is just as important for properly securing a website. That is why we have compiled a list of the most essential security features you can enable that can make the difference between a hacked website and peace of mind.
Use SSL
Today an SSL is absolutely essential for every website. An SSL certificate encrypts the connection between your visitors’ browsers and your website’s server so that the data transmitted between the two, such as personal information, credit card data, login credentials or else, cannot be hijacked by hackers.
SiteGround clients get free Standard and Wildcard SSL certificates with all hosting plans, regardless of the number of sites. Make sure you have your SSL installed and traffic properly redirected via HTTPS from Site Tools > Security > SSL to ensure the encryption of the connection.
If you have a business website or you’re processing online payments, you may consider our premium Wildcard certificates that come with $10,000 underwritten warranty and a dynamic site seal to create credibility and trust among your visitors.
Protect your login
Your login credentials are a gateway to your account and personal information (and when talking about websites, to your domain, site and emails, too). There are several things you can do to ensure that your login credentials are safe and secure, and that only you or the people you have authorized have access to your website:
Harden Your Passwords
Despite all the awareness created nowadays about weak passwords and the importance of never sharing login credentials with anyone, one of the most common credentials hacking is through guessing or brute-forcing easy-to-crack passwords. Having a long password, consisting of multiple characters and a combination of words, letters, numbers and symbols is an easy and super effective way to keep your accounts secure. Remember to use different passwords for different sites and apps, and never share your passwords with anyone, nor write them on publicly accessible places like post-it notes on your computer! Read more on the topic here.
Use 2-factor authentication
Regardless of how hard your password is, there’s still a possibility for a hacker to get to it through a brute-force attack, virus, malware or other. With 2-factor authentication enabled, a secondary step needs to be passed by anyone attempting to access your data. 2FA adds another layer of authentication, usually through a temporary dynamically generated code (accessible only from your phone or email, depending on the settings), which cannot be guessed or hacked and makes your login defense bulletproof!
For SiteGround Client Area, which is the gateway to your domains and sites, you can easily enable 2FA from Client Area > Login & Profile.
For your WordPress application login, you can install and activate the SiteGround Security plugin and enable the 2FA feature. Download the plugin here, or install it directly through your WordPress admin area.
Monitor your website
Scan for malware regularly
There are numerous ways a website may get infected with malware – through compromised login credentials, infected or fake plugins and themes, corrupted software and more. Malware can have a serious impact on your site and online business. The best prevention for it is a secure web hosting platform and constant monitoring. If you’re a SiteGround customer, you can activate Site Scanner – a service that crawls your website on a daily basis and notifies you of potential malware and other threats. Just recently, Site Scanner helped save thousands of WordPress sites from particularly nasty malware.
Block suspicious traffic
There are cases where only the person managing a site can notice specific patterns or suspicious activity. We have provided easy-to-use powerful tools for blocking specific IP addresses or whole countries, enabling our customers to control who’s accessing their website and prevent unwanted visitors.
Back up your site regularly
While backups don’t protect you from hackers directly, they keep you safe from other unexpected events – a site update that may have gone wrong, an infected site that has to be reverted to a clean version, and any other situation where a copy of your website is all you need to bring it back online. We know how often backups can save an otherwise dire situation, so we do automated daily backups of all sites hosted with us and keep them for up to 30 days. You can easily restore your website, files, or databases for free in just a few clicks from Site Tools > Security > Backups.
Take special care of your WordPress
Being the most popular CMS in the world, WordPress is also one of the most popular targets for hackers. While all of the advice above applies to WordPress, there are a few additional things you can do to ensure that your WordPress site is well protected from bad actors and malicious software.
Keep your WordPress up-to-date
Keeping your WordPress up-to-date is essential for your website security. If your site is hosted with SiteGround, we’ve got this covered for you. All WordPress sites hosted with us get automatically updated to the latest stable WordPress version (only after we have thoroughly tested it). Free plugins are also auto-updated, depending on the user settings.
Add an extra safety layer with a trusted security plugin
There are WordPress-specific exploits and vulnerabilities that are best handled within WordPress itself. Some of our best WordPress engineers have developed the (free for all) SiteGround Security plugin that consists of a number of tools and features designed to keep your WordPress safe and secure. It helps site owners to disable XML-RPC if you don’t need it, add XSS protection, protect system folders from being injected with malicious files with just 1 click, and many more.
Avoid common usernames like “Admin”
Your login consists of two pieces – a username and a password. On many occasions, the username is something automatically generated by the platform where you register and you have no control over it, but on others, such as your WordPress application, you are in full control of what your usernames should be. Except, all WP installations come with the user “Admin” by default. And hackers know that, which means they are one step closer to accessing your site! That is why we suggest you disable all Admin users on your sites and create users with different usernames and equal to the Admin rights. You can disable the use of Admin and other common usernames with the free SiteGround Security plugin.
Limit login attempts
A standard behavior of unauthorized users is to try and guess your password (or username and password) on the login form by making multiple consecutive attempts for that. You can easily cut them off by limiting the number of consecutive unsuccessful login attempts they can make. After they reach the set amount, the IP from which they log in gets blocked for 1 hour. Use the free SiteGround Security plugin to activate this feature for WordPress sites.
Use a trusted web hosting provider with a security-first approach
As we mentioned in the beginning, protecting your website is a team effort and on our platform your website’s security is our number one priority. Here we want to recap some of the things we do and in case you are not a SiteGround client, you may want to consider these security essentials for any hosting provider you work with:
Server-level Web Application Firewall
The web application firewall monitors the traffic and blocks the opportunity for hackers to exploit many common application security holes. Although there are many solutions such as WordPress plugins, or third-party services to address that need, a server-level WAF is of utmost importance since it works with big data and real-time. That is why our dedicated Security Team constantly monitors various security bulletins for exploits and vulnerabilities, and immediately creates custom security rules, which they add to our smart and in-house managed Web Application Firewall. It protects all sites hosted with us out-of-the-box.
Brute-force prevention
Siteground has a sophisticated AI-driven bruteforce prevention system that for years has been stopping millions of bruteforce attempts per day (even hour)! And while this on its own is impressive, we recently made it even better. After the recent system upgrade, we have managed to reduce the amount of malicious traffic reaching your site by 95% and thus significantly minimizing the actual bruteforce attempts! No action is required on our clients’ end, they’re already using it. 🙂
DDOS protection
DDOS attacks are frequently used by hackers to bring down sites for different reasons – ransom demands, economical or business competition, political motives or simple vandalism. We have a system of software and hardware mechanisms that divert DDOS attacks, mitigate their impact, and eventually stop them. And the best thing is that you don’t have to do anything – we protect all sites hosted on our platform!
Managed PHP
Keeping PHP up-to-date is essential for keeping your website safe. Older PHP versions are often a gateway for vulnerabilities and malware, and a lot of web hosting providers tend to overlook this in order to make PHP management easier. We have developed a secure managed PHP solution that helps our customers keep their PHP updated to the latest stable PHP version.
On-demand traffic blocking (IP and Geo-Blocking)
There are cases where only the person managing a site can notice specific patterns or suspicious activity. We have provided easy-to-use powerful tools for blocking specific IP addresses or whole countries, enabling our customers to control who’s accessing their website and prevent unwanted visitors.
Smart Client Area & Site Tools Login
All SiteGround accounts are protected behind a smart login we have developed to recognize suspicious behavior and enforce additional client verification when an irregular pattern is detected. Our login system learns from your behavior – like the devices you’re usually using or the locations you often log from, for example – and knows whether a login attempt is coming from you or an impostor. In the latter case, a challenge is introduced – one that is easy to pass for the real account owner and very hard for anyone else.
Monthly Security Reports
There’s one more thing that often gets overlooked, but it’s important to include it in your website security strategy. You need to make sure that you keep an eye on your site’s security status regularly, yet this can take you much time, effort, and money. SiteGround clients receive free monthly security reports straight into their inboxes.
We perform automated security checks of our clients’ websites and then provide them with summary results in a user-friendly format, along with actionable tips on reducing the risk of malicious attacks, if we identify any weak areas.
These are the features that are essential for your website security. If you have all of them enabled, we’re confident that your website is well protected and you can have peace of mind that you have done everything in your power to secure your online business. We’d love to hear which of these features you’re already using and which are the ones you just found out about.
How to secure your WordPress website? (Video tutorial)
We are happy to announce that we have increased the number of our data centers and CDN locations in the USA. Our clients may now choose among four US-based data centers to have their sites hosted as close as possible to their visitors. What is more, we already have six US-based CDN edge points, which help improve the website speed in the region as a whole for all our CDN users.
4 Data Centers in the USA
With the introduction of three new data centers, we now have four locations in the USA, all part of the modern Google Cloud infrastructure that ensures high redundancy, fast connectivity, and multi-layered security:
USA North in Council Bluffs, Iowa — best for websites that have visitors predominantly from the northern US and/or Canada
NEW: USA South in Dallas, Texas — best for websites that have visitors predominantly from the southern US and/or Central and South American countries
NEW: USA East in Ashburn, Virginia — best for websites that have visitors predominantly from the Eastern US states
NEW: USA West in Los Angeles, California — best for website that have visitors predominantly from the Western US states
When choosing which of our data center locations is best for you, you should take into consideration where the majority of your website traffic is coming from. In case you have a strictly local audience, it is best to have your hosting account placed in the data center closest to your audience.
You can check where an existing hosting account is currently placed and order a relocation if you think there is a better option for you through Client Area > Marketplace > Hosting services > Hosting relocation.
6 CDN edge points in the USA
We are also aware that many of our clients receive traffic not just from one state, but from many and it’s hard to choose one, most convenient hosting server location. For such cases, any US-based data center is a good choice for being the original home of your site. However, the best site loading results will be achieved by using our CDN. The CDN makes sure that a copy of your website is accessible from a location closer to your visitors from all over the USA, and even from all over the world.
We now have the following CDN locations in the USA: Council Bluffs (Iowa, USA), Moncks Corner (South Carolina, USA), The Dalles (Oregon, USA), Los Angeles (California, USA), Ashburn (Virginia, USA), Dallas (Texas, USA).
We encourage all our customers receiving traffic from different geographic locations to activate the CDN service. This can be done completely free of charge through your Site Tools > Speed > CDN.
There is a saying amongst tech companies that if you can’t afford to pay for security, you can’t afford a security breach. The consequences of a breach can be quite expensive in terms of data loss, human involvement, costs for business recovery, reputation damages, and many more. That is why big companies spend millions of dollars to protect their data and spend significant time in implementing and maintaining data safety procedures and security strategies. Naturally, small businesses cannot afford any of that and usually have a limited budget dedicated to security. That’s when and where using the services of a secure web hosting provider becomes critical.
Although web hosts cannot be solely responsible for your website security, the good ones can do a lot to help you stay safe and prevent the worst from happening. Here at SiteGround, we have developed a centralized, enterprise-grade security system to protect our clients’ sites, applications and data. Its complexity has grown over time and describing it in whole can be quite overwhelming, but in this post we’ll give you a glimpse on how we analyze and filter web traffic coming to your sites and how we prevent on a daily basis hundreds of millions attacks to the sites we host.
Effective security-building blocks
All our servers have essential security software installed on them and systems set to work locally per server – a network traffic firewall, Web Application Firewall, IDS/IPS (intrusion-detection/prevention-systems such as brute-force prevention), deep HTTP analysis of meta data, DDOS protection and more. These are classic and very effective means of filtering bad traffic and preventing brute-force attacks, malware injections, denial of service, and more, which we heavily rely on. Under the competent management of our DevOps engineers and System Administrators, these systems are constantly improved and all of them together filter roughly 1 TB of bad traffic and more than 300 million bad requests across our servers daily!
But if those systems operate stand-alone, on a server-level only, the following issues appear: in case a hacker threatens server A, even if the server’s individual security systems can keep the server safe, they can’t stop the hacker from attempting the same attack on servers B, C, etc. To ensure that all of our servers are protected at all times, we have built our Central Security System that constantly gathers and analyzes data from all individual server security systems, and distributes smart security rules that are applied to and protect all machines.
Centralized big data analysis
Our Central Security system relies on the big data it receives from all the other server-level systems and analyzes the various attack sources, detects bigger patterns, and blocks many more attacks globally on the whole platform.
Web Application Firewall Data Feed
As mentioned above, every server has a WAF, whose main responsibility is to protect web applications like WordPress, Magento, Joomla, Drupal and others from a variety of attacks such as cross-site scripting (XSS), SQL injection, and more. The moment we become aware of a security threat (software vulnerability), our security engineers write a new rule to patch it and add that rule to our local WAFs.
Every request that is not dropped at network level, is filtered by the server WAF. If the request is hitting the parameters of a WAF rule, the WAF sends information about it to the Central Security System. The Central System logs and analyzes all requests hitting WAF rules across all our servers (for example their IP and other metadata). If it detects a pattern, like multiple requests across many servers coming from the same IP address, the Central System will block that IP and distribute a rule to all the machines in our infrastructure. Depending on the specific case and the rule, the system may limit the suspicious IP requests to be challenged by captcha or entirely limit the traffic from it to any of our servers for a specific period (hours, days, weeks or even permanently).
Brute-force Prevention Traffic Patterns
As part of our brute-force prevention strategy, we have deployed local monitoring systems on all our servers. They monitor the login attempts to all applications hosted with us and report every failed one to the Central Security System. The system is notified of the attempt along with all important security information related to it, like an IP address, number of requests, IP history and more. Every 60 seconds the Central Security System reviews the aggregated data and analyzes the volume and frequency of repetitive metadata looking for patterns. When patterns are clearly identified, the system creates blocking rules that are distributed to all servers.
An example of this would be multiple failed login attempts on one or more servers, coming from the same IP address within a short period of time (different time thresholds are set for higher precision and effectiveness). In a case like this, our system would flagg the IP and the future requests coming from it towards any of our servers would be challenged with captcha.
Many more systems send data to our Central Security System
There are many more ways we feed our Central Security System with data – like monitoring login attempts to a server-level services like FTP, EXIM, Dovecot, etc; reviewing XML-RPC traffic of WordPress sites; inputting different traffic patterns from third-party systems, and more.
The more relevant data sources we input, the bigger the pool of data becomes, which significantly improves the analytical power and accuracy of the Central Security System. Over time the System’s capability of effectively preventing attacks grows bigger and bigger.
Enterprise-grade Protection on a Global Scale
And to wrap it up, here are some numbers that can help you understand the scale and effect of what the Central Security System does. On a daily basis over 260 million requests are challenged with captcha and less than40,000 actually pass the challenge. We have more than 50,000 IPs currently flagged as bad or suspicious and nearly half of them are completely blocked from reaching our servers. The number is changing daily, as new IPs are flagged and challenged due to suspicious activity, while previously flagged ones get cleared after successful verification or ban expiration.
All of these numbers and the comprehensive work involved in maintaining an effective Central Security System lead to the number that matters most – 99,99%of bad traffic blocked before it reaches your website.
In the middle of June, we launched our upgraded Site Scanner service. Little did we know back then how soon we would see the new functionality in full action. Just a few months after the upgrade the Site Scanner saved thousands of WordPress sites from a well-disguised attack, aiming to redirect traffic to bogus sites through a fake plugin, called Zend Fonts. Imagine all the reputation and other business damages a hack like this could have caused and take a read how our hero, the Site Scanner, saved the day.
How does the “fake Zend Fonts plugin” work?
The attack involved uploading an infected fake plugin called Zend Fonts through a backdoor. Once uploaded, the infected plugin would redirect site visitors to bogus scam sites without the site owner even suspecting it. The uploaded plugin file looks like that:
What makes the attack really bad is that this plugin file is hidden from the wp-admin or wp-cli plugin list, meaning the WP Admins would not be able to easily spot it, due to the following function:
Also it is configured to trigger the redirect only if the website is accessed by a normal user, not the site admin or editor:
//do redirect if user from REF and NOT Admin
if(isset( $_SERVER['HTTP_REFERER']) && !$isAdmin){
redirect();
}
All these factors make the attack pretty much invisible for the site owners/editors, while the normal visitors would be redirected to scam sites. This hack could easily result in significant losses of sales, reputation damages, and other harms such as bad standings in search engines and more.
How did SiteGround detect the attack?
Our System Administrators monitor the load and behavior of our servers 24/7 and soon after this exploit was launched, we observed an abnormally high number of malicious files detected by our Site Scanner service crawling for malware. Our Sys Admins started digging further and spotted a pattern – there was an attempt for a massive fake Zend Fonts plugin upload affecting by that time around 2000 of our clients’ WordPress installations.
How does Site Scanner protect the sites it’s on?
Usually, in attacks like the Zend Fonts one, for the sites with Site Scanner Basic, reports are received in less than 24 hours after the malware is detected (right after the scheduled daily scan) and for those with Site Scanner Premium, an alert is received immediately after the (attempted) upload, giving our clients the opportunity to quickly react and delete the malicious files before they can cause any damage.
Furthermore, for the sites with Site Scanner Premium where quarantine is switched on, the files never reach the attacked sites – they are safely quarantined for the site owners to review and delete when convenient. The quarantine effectively stops the attack and protects the sites from malicious hack attempts, and the business and reputation impact resulting from them. And the best part – the site owners don’t have to do anything.
Using Site Scanner data to protect all clients
Once our System Administrators had detected that the Zend Fonts plugin upload was not something isolated, but was happening across the whole platform, they deleted all malicious files from our servers. Furthermore, our Security Engineers added a new rule to our web application firewall (WAF) to prevent further attacks towards other WordPress sites hosted with us.
We are quite excited to see how our Site Scanner service is actively protecting sites from a variety of really bad attacks. For massive, large-scale attacks such as the Zend Fonts plugin one, the Site Scanner helps us detect a pattern and take actions to protect all our clients by implementing WAF rules or enhancing our monitoring system. While this is something that we will continue doing, updating a platform-wide system takes some time and will not include smaller, site-specific malware attacks. If you want to have an early-on, comprehensive malware detection for your site, we strongly recommend that you activate one of our Site Scanner plans. And if you’re looking to not only detect but proactively stop malware attacks, get the Premium Site Scanner with quarantine on.