How to avoid bad bot traffic during Black Friday

bots attacking a browser and finally cracking it

Last week, we helped you get your website ready for the Black Friday traffic spikes. Now that you’re all set to handle the upcoming traffic, do you know how much of it is real and how much – non-human? According to Statista, in 2022 more than 40% of Internet traffic is from bots, and a significant portion of that is bad bot traffic. This kind of bot traffic hurts your online business and can lead to both financial and conversion losses. Let’s dig deeper into what bot traffic is, why most of it is so harmful, and how to avoid it during the busiest time of the year.

What is bot traffic and why it should be cut down to a minimum

Bot traffic is any non-human traffic that comes to a website or app. Some of it is good, when it originates from SEO crawlers (such as Google crawl bot), commercial, site-monitoring, or feed bots. Needless to say, all of these cause no harm to your site. On the other hand, bad bots come with malicious intent. These can leave spam comments, irrelevant backlinks, weird advertisements, collect private information, reuse your content, perform DDoS attacks, and other malicious activities.

How bad bot traffic affects your website

Bad bot traffic may have different consequences on your website and business, causing multiple damages:

  • Website security and availability damage

Bad bot traffic hurts your website security and availability. For instance, these massive amounts of traffic to your site are a way for hackers to cause a DDoS attack. During such an attack, the traffic is so massive that the server where your site is hosted cannot handle it. This can make your website slow, unreliable or even unavailable for your users. 

Bad bots are also the main force of a brute-force attack – a way to guess your password/login details by trying numerous combinations of letters, numbers and symbols. If such an attack is successful, malicious hackers gain access to your account and/or private information.

  • Website speed issues

Even if it doesn’t cause massive hacker attacks, bad bots activity can make your website much slower or even unavailable for your real visitors, affecting their overall user experience. To have your visitors stay longer on your site and turn them into clients, you’d want them to have an excellent user experience. A huge part of that is your website loading speed being as fast as possible.

  • Analytics metrics and SEO rankings chaos

Bad bot traffic can also hurt your analytics metrics and SEO rankings. For example, too much bad bot traffic can bring your site down and cause 503 errors (“site is temporarily unavailable”). This directly negatively impacts your SEO rankings. What is more, bad bots can affect your analytics metrics, causing abnormally high pageviews and bounce rates, sudden drop/increase in session durations, and fake conversions. All these factors may confuse you as a site owner and you may not be able to make sense of your analytics data.

How we decrease bad bot traffic at SiteGround

At SiteGround we take multiple measures at different levels to reduce bad bot activity by default for the websites hosted on our servers, so you can have peace of mind.

Improved and advanced AI anti-bot system

Our AI anti-bot system has successfully been blocking millions of brute-force attempts per day. Recently, we improved it even further, resulting in 95% less bad traffic. Its core features are still there – analyzing and recognizing traffic patterns to eventually stop brute-force attempts. With each new brute-force attempt, the system’s knowledge expands and it gets better at preventing future attacks. As of recently, we’ve upgraded the system with a traffic validation feature that stops even more malicious non-human bots by minimizing the number of brute-force attacks. Currently, the system blocks a huge percentage of bad bots traffic towards our servers, allowing more capacity for your websites for legitimate traffic.

Combined with our enterprise-grade security system, these server-level security optimizations block the majority of all bad bot traffic and ensure website protection on a global scale. Let the numbers speak for themselves – 99,99% of bad traffic is blocked before it even reaches your website.

Smart, server-level WAF

Hacker attacks usually increase during the Black Friday season. A single outdated WordPress plugin, theme, or vulnerability can easily be used for massive damages during this busiest time of the year. That’s where our smart Web Application Firewall comes to the rescue. Our security experts closely monitor security bulletins and server activity 24/7, and in case of reported exploits, immediately add custom WAF rules (patches) into our server firewall to protect your site from current hacks and breaches due to outdated plugins, and other vulnerabilities. Our proactive security approach allows us to react much faster, often before the original plugin, theme or app developers have had the chance to release an official update. The most recent example of this was just last month, with two previous major ones not so far behind – a plugin vulnerability patched on day 0, and a Linux Kernel vulnerability patched within hours of detection.

DDoS protection

To address potential DDoS attacks from bad bots, we have a system of hardware and software mechanisms to protect your sites:

  • A hardware firewall that filters flooding traffic;
  • A local software firewall with more complex functions and traffic monitoring;
  • А limit to the number of connections a remote host can establish;
  • A check for a high number of failed login attempts from hosts and filtering them, if any.

24/7 server monitoring system

Again, in addition to all monitoring and prevention systems and checks in place, our expert system administrators team are monitoring our servers 24/7 for any system issues and in case of any, can react quickly to save the day.

How to identify that you have bad bot traffic coming to your site

Now, you probably wonder what are some signs and symptoms of bad bot traffic that will help you identify whether your site is in danger. Here are some of the red flags and ways to prevent them:

  • Check your site traffic stats

You also need to check your traffic statistics, especially the IP addresses and the sources of traffic. For example, regular and high number of visits from the same IP address or increase in traffic from other regions or countries, from which you didn’t have (much) traffic before, could be an indication of bad bot traffic. As a SiteGround customer, you can easily check your traffic statistics in Site Tools > Statistics > Traffic.

  • Keep an eye for unusual users’ behavior

Remember to monitor your users’ behavior regularly. In case there are increased spam comments under your posts, strange user registrations, and/or increased blocked login attempts, these are all red flags that you might be getting bad bot traffic to your site. WordPress users, who have the free SiteGround Security plugin installed, can monitor their site and login page for unauthorized visits and brute-force attempts from their Activity Log menu. What is more, they can easily block suspicious IPs and visitors.

  • Make regular speed tests

You probably already do that, but if you don’t, it’s a good idea to start making regular website speed tests. For this purpose, you can use a number of different tools to measure your site speed, such as Google PageSpeed Insights, Pingdom, GTMetrix, and others that generate results in all the major speed metrics. 

In case you have the free SiteGround Optimizer plugin installed on your WordPress website, you can run a speed test within the plugin in its Speed test functionality. The check uses Google PageSpeed, provides information on the level of optimization in over 20 different areas, and gives you optimization suggestions.

If you identify that your site is experiencing page loading speed issues, dig deeper into the problem to find out the causes. These might not necessarily be bad bot traffic issues, but that’s one of the main potential reasons behind the slow speed results.

How to filter bad bot traffic yourself on SiteGround

Some of the traffic that reaches your websites may seem legitimate, even if it’s not. Thankfully, there are a number of ways and free services we offer to let you filter good from bad website traffic all by yourself:

Both options allow you to easily block suspicious or malicious traffic to your website. If you want to block a specific IP address from accessing your site, because, for example, you see it’s using too much bandwidth, you simply go to Site Tools > Security > Block Traffic, choose the domain for which you want to block access, then add the IP address (or a whole range in IP/IP Range), and finally click ‘Block’.

Similarly, if you notice that you get suspicious abnormal activity from a country you don’t usually operate in or have clients from, you can easily block traffic from it in a few clicks. You need to go to Site Tools > Security > Block Traffic > Block Country. There, you choose the domain for which you want to block access, pick the desired country to block in the Country dropdown, and finally click ‘Block’.

These two options will help you not only block bad bot traffic coming to your site, but they can also significantly improve your site performance by reducing the unwanted traffic and giving your site more capacity to handle real human traffic.

Improving your site capacity to handle more requests

In case you’ve identified that your site still gets some bad bot traffic which cannot be easily filtered or removed, you can decrease its negative impact by improving your website speed and performance, which will allow more capacity to handle any type of traffic altogether. Here’s how to do that:

We’ve developed a powerful caching system to help you cache as much content on your website as possible. Cached content is served much faster to visitors and thus improves your site capacity to handle traffic. Our system is comprised of three caching options that are all available in your Site Tools > Speed > Caching: NGINX Direct Delivery for caching static content, such as images and CSS files; Dynamic Caching for dynamic content to be stored in the server RAM, and Memcached for storing data and objects in memory (best for database-driven websites).

  • Use our other optimization services

We do a lot to improve website performance and you can make use of our premium solutions. Here are three of the main ones that can speed up your website and make room for more visitors’ requests. 

Our in-house developed SiteGround CDN requires no configuration, it’s easy-to-manage with just a few clicks, and above all, makes your site load blazingly-fast for visitors around the world. Its Basic version comes completely free of charge and provides your site with all the essential features to handle international traffic from various international locations.

Another in-house developed speed tool is the free SiteGround Optimizer plugin for WordPress websites. It provides you with many different optimization options (media, frontend, environment) that can all be enabled in a few clicks.

Last, but not least, our unique ultrafast PHP setup makes your pages load up to 30% faster and allows the server to process your website’s visits quicker.

Wrap-up

While most people are busy selling and buying goods and services during the Black Friday period, bad bots are also more active than ever, “visiting” websites and causing all kinds of potential issues. If not addressed on time and in the proper manner, they can ruin a big chunk of your holiday conversions during that time of the year, when you worked hard to get the highest number of sales.

[subscribe_cta]

Your Website’s Essential Security Features. Are They On?

essential website security features

Building and maintaining a strong website security is a constant process that often gets neglected by website owners due to its complexity, time consumption and cost. As a hosting provider, we know better. Over 18 years of experience in hosting, maintaining and securing millions of websites has taught us that website security is absolutely critical for every online business. We have seen the devastating consequences a hack can have on a website and ultimately on a business, and we have dedicated serious efforts to preventing and minimizing the effects of hack attempts. 

Over the years, we have optimized the security of our platform by developing sophisticated security systems, introducing a variety of security tools, plugins and features, and constantly analyzing and monitoring traffic and patterns to recognize potential threats. While all of this has made us one of the most secure and trusted web hosting providers in the world, we know that platform security on its own, is not enough. The involvement of webmasters and site owners is just as important for properly securing a website. That is why we have compiled a list of the most essential security features you can enable that can make the difference between a hacked website and peace of mind.

Use SSL

Today an SSL is absolutely essential for every website. An SSL certificate encrypts the connection between your visitors’ browsers and your website’s server so that the data transmitted between the two, such as personal information, credit card data, login credentials or else, cannot be hijacked by hackers. 

SiteGround clients get free Standard and Wildcard SSL certificates with all hosting plans, regardless of the number of sites. Make sure you have your SSL installed and traffic properly redirected via HTTPS from Site Tools > Security > SSL to ensure the encryption of the connection. 

If you have a business website or you’re processing online payments, you may consider our premium Wildcard certificates that come with $10,000 underwritten warranty and a dynamic site seal to create credibility and trust among your visitors.

Protect your login

Your login credentials are a gateway to your account and personal information (and when talking about websites, to your domain, site and emails, too). There are several things you can do to ensure that your login credentials are safe and secure, and that only you or the people you have authorized have access to your website:

Harden Your Passwords

Despite all the awareness created nowadays about weak passwords and the importance of never sharing login credentials with anyone, one of the most common credentials hacking is through guessing or brute-forcing easy-to-crack passwords. Having a long password, consisting of multiple characters and a combination of words, letters, numbers and symbols is an easy and super effective way to keep your accounts secure. Remember to use different passwords for different sites and apps, and never share your passwords with anyone, nor write them on publicly accessible places like post-it notes on your computer! Read more on the topic here.

Use 2-factor authentication

Regardless of how hard your password is, there’s still a possibility for a hacker to get to it through a brute-force attack, virus, malware or other. With 2-factor authentication enabled, a secondary step needs to be passed by anyone attempting to access your data. 2FA adds another layer of authentication, usually through a temporary dynamically generated code (accessible only from your phone or email, depending on the settings), which cannot be guessed or hacked and makes your login defense bulletproof!

  • For SiteGround Client Area, which is the gateway to your domains and sites, you can easily enable 2FA from Client Area > Login & Profile
  • For your WordPress application login, you can install and activate the SiteGround Security plugin and enable the 2FA feature. Download the plugin here, or install it directly through your WordPress admin area.

Monitor your website

Scan for malware regularly

There are numerous ways a website may get infected with malware – through compromised login credentials, infected or fake plugins and themes, corrupted software and more. Malware can have a serious impact on your site and online business. The best prevention for it is a secure web hosting platform and constant monitoring. If you’re a SiteGround customer, you can activate Site Scanner – a service that crawls your website on a daily basis and notifies you of potential malware and other threats. Just recently, Site Scanner helped save thousands of WordPress sites from particularly nasty malware.

Block suspicious traffic

There are cases where only the person managing a site can notice specific patterns or suspicious activity. We have provided easy-to-use powerful tools for blocking specific IP addresses or whole countries, enabling our customers to control who’s accessing their website and prevent unwanted visitors.

Back up your site regularly

While backups don’t protect you from hackers directly, they keep you safe from other unexpected events – a site update that may have gone wrong, an infected site that has to be reverted to a clean version, and any other situation where a copy of your website is all you need to bring it back online. We know how often backups can save an otherwise dire situation, so we do automated daily backups of all sites hosted with us and keep them for up to 30 days. You can easily restore your website, files, or databases for free in just a few clicks from Site Tools > Security > Backups.

Take special care of your WordPress

Being the most popular CMS in the world, WordPress is also one of the most popular targets for hackers. While all of the advice above applies to WordPress, there are a few additional things you can do to ensure that your WordPress site is well protected from bad actors and malicious software.

Keep your WordPress up-to-date

Keeping your WordPress up-to-date is essential for your website security. If your site is hosted with SiteGround, we’ve got this covered for you. All WordPress sites hosted with us get automatically updated to the latest stable WordPress version (only after we have thoroughly tested it). Free plugins are also auto-updated, depending on the user settings.

Add an extra safety layer with a trusted security plugin

There are WordPress-specific exploits and vulnerabilities that are best handled within WordPress itself. Some of our best WordPress engineers have developed the (free for all) SiteGround Security plugin that consists of a number of tools and features designed to keep your WordPress safe and secure. It helps site owners to disable XML-RPC if you don’t need it, add XSS protection, protect system folders from being injected with malicious files with just 1 click, and many more.

Avoid common usernames like “Admin”

Your login consists of two pieces – a username and a password. On many occasions, the username is something automatically generated by the platform where you register and you have no control over it, but on others, such as your WordPress application, you are in full control of what your usernames should be. Except, all WP installations come with the user “Admin” by default. And hackers know that, which means they are one step closer to accessing your site! That is why we suggest you disable all Admin users on your sites and create users with different usernames and equal to the Admin rights. You can disable the use of Admin and other common usernames with the free SiteGround Security plugin.

Limit login attempts

A standard behavior of unauthorized users is to try and guess your password (or username and password) on the login form by making multiple consecutive attempts for that. You can easily cut them off by limiting the number of consecutive unsuccessful login attempts they can make. After they reach the set amount, the IP from which they log in gets blocked for 1 hour. Use the free SiteGround Security plugin to activate this feature for WordPress sites.

Use a trusted web hosting provider with a security-first approach

As we mentioned in the beginning, protecting your website is a team effort and on our platform your website’s security is our number one priority. Here we want to recap some of the things we do and in case you are not a SiteGround client, you may want to consider these security essentials for any hosting provider you work with:

Server-level Web Application Firewall

The web application firewall monitors the traffic and blocks the opportunity for hackers to exploit many common application security holes. Although there are many solutions such as WordPress plugins, or third-party services to address that need, a server-level WAF is of utmost importance since it works with big data and real-time. That is why our dedicated Security Team constantly monitors various security bulletins for exploits and vulnerabilities, and immediately creates custom security rules, which they add to our smart and in-house managed Web Application Firewall. It protects all sites hosted with us out-of-the-box.

Brute-force prevention

Siteground has a sophisticated AI-driven bruteforce prevention system that for years has been stopping millions of bruteforce attempts per day (even hour)! And while this on its own is impressive, we recently made it even better. After the recent system upgrade, we have managed to reduce the amount of malicious traffic reaching your site by 95% and thus significantly minimizing the actual bruteforce attempts! No action is required on our clients’ end, they’re already using it. 🙂

DDOS protection

DDOS attacks are frequently used by hackers to bring down sites for different reasons – ransom demands, economical or business competition, political motives or simple vandalism. We have a system of software and hardware mechanisms that divert DDOS attacks, mitigate their impact, and eventually stop them. And the best thing is that you don’t have to do anything – we protect all sites hosted on our platform!

Managed PHP

Keeping PHP up-to-date is essential for keeping your website safe. Older PHP versions are often a gateway for vulnerabilities and malware, and a lot of web hosting providers tend to overlook this in order to make PHP management easier. We have developed a secure managed PHP solution that helps our customers keep their PHP updated to the latest stable PHP version.

On-demand traffic blocking (IP and Geo-Blocking)

There are cases where only the person managing a site can notice specific patterns or suspicious activity. We have provided easy-to-use powerful tools for blocking specific IP addresses or whole countries, enabling our customers to control who’s accessing their website and prevent unwanted visitors.

Smart Client Area & Site Tools Login

All SiteGround accounts are protected behind a smart login we have developed to recognize suspicious behavior and enforce additional client verification when an irregular pattern is detected. Our login system learns from your behavior – like the devices you’re usually using or the locations you often log from, for example – and knows whether a login attempt is coming from you or an impostor. In the latter case, a challenge is introduced – one that is easy to pass for the real account owner and very hard for anyone else.

Monthly Security Reports

There’s one more thing that often gets overlooked, but it’s important to include it in your website security strategy. You need to make sure that you keep an eye on your site’s security status regularly, yet this can take you much time, effort, and money. SiteGround clients receive free monthly security reports straight into their inboxes.

We perform automated security checks of our clients’ websites and then provide them with summary results in a user-friendly format, along with actionable tips on reducing the risk of malicious attacks, if we identify any weak areas.

These are the features that are essential for your website security. If you have all of them enabled, we’re confident that your website is well protected and you can have peace of mind that you have done everything in your power to secure your online business. We’d love to hear which of these features you’re already using and which are the ones you just found out about.

How to secure your WordPress website? (Video tutorial)

[subscribe_cta]

Our USA Data Center and CDN Network Just Got Bigger

map of the USA with pins where SiteGround has data centers

We are happy to announce that we have increased the number of our data centers and CDN locations in the USA. Our clients may now choose among four US-based data centers to have their sites hosted as close as possible to their visitors. What is more, we already have six US-based CDN edge points, which help improve the website speed in the region as a whole for all our CDN users.

4 Data Centers in the USA

With the introduction of three new data centers, we now have four locations in the USA, all part of the modern Google Cloud infrastructure that ensures high redundancy, fast connectivity, and multi-layered security:

  1. USA North in Council Bluffs, Iowa — best for websites that have visitors predominantly from the northern US and/or Canada
  2. NEW: USA South in Dallas, Texas — best for websites that have visitors predominantly from the southern US and/or Central and South American countries
  3. NEW: USA East in Ashburn, Virginia  — best for websites that have visitors predominantly from the Eastern US states 
  4. NEW: USA West in Los Angeles, California — best for website that have visitors predominantly from the Western US states

When choosing which of our data center locations is best for you, you should take into consideration where the majority of your website traffic is coming from. In case you have a strictly local audience, it is best to have your hosting account placed in the data center closest to your audience. 


You can check where an existing hosting account is currently placed and order a relocation if you think there is a better option for you through Client  Area > Marketplace > Hosting services > Hosting relocation.

6 CDN edge points in the USA

We are also aware that many of our clients receive traffic not just from one state, but from many and it’s hard to choose one, most convenient hosting server location. For such cases, any US-based data center is a good choice for being the original home of your site. However,  the best site loading results will be achieved by using our CDN. The CDN makes sure that a copy of your website is accessible from a location closer to your visitors from all over the USA, and even from all over the world. 

We now have the following CDN locations in the USA: Council Bluffs (Iowa, USA), Moncks Corner (South Carolina, USA), The Dalles (Oregon, USA), Los Angeles (California, USA), Ashburn (Virginia, USA), Dallas (Texas, USA). 


We encourage all our customers receiving traffic from different geographic locations to activate the CDN service. This can be done completely free of charge through your Site Tools > Speed > CDN.

[subscribe_cta]

Enterprise-grade Security System Built in our Web Hosting Platform

several servers pointing to a security icon

There is a saying amongst tech companies that if you can’t afford to pay for security, you can’t afford a security breach. The consequences of a breach can be  quite expensive in terms of data loss, human involvement, costs for business recovery, reputation damages, and many more. That is why big companies spend millions of dollars to protect their data and spend significant time in implementing and maintaining data safety procedures and security strategies. Naturally, small businesses cannot afford any of that and usually have a limited budget dedicated to security. That’s when and where using the services of a secure web hosting provider becomes critical. 

Although web hosts cannot be solely responsible for your website security, the good ones can do a lot to help you stay safe and prevent the worst from happening. Here at SiteGround, we have developed a centralized, enterprise-grade security system to protect our clients’ sites, applications and data. Its complexity has grown over time and describing it in whole can be quite overwhelming, but in this post we’ll give you a glimpse on how we analyze and filter web traffic coming to your sites and how we prevent on a daily basis hundreds of millions attacks to the sites we host.

Effective security-building blocks

All our servers have essential security software installed on them and systems set to work locally per server – a network traffic firewall, Web Application Firewall, IDS/IPS (intrusion-detection/prevention-systems such as brute-force prevention), deep HTTP analysis of meta data, DDOS protection and more. These are classic and very effective means of filtering bad traffic and preventing brute-force attacks, malware injections, denial of service, and more, which we heavily rely on. Under the competent management of our DevOps engineers and System Administrators, these systems are constantly improved and all of them together filter roughly 1 TB of bad traffic and more than 300 million bad requests across our servers daily!

But if those systems operate stand-alone, on a server-level only, the following issues appear:  in case a hacker threatens server A, even if the server’s individual security systems can keep the server safe, they can’t stop the hacker from attempting the same attack on servers B, C, etc. To ensure that all of our servers are protected at all times, we have built our Central Security System that constantly gathers and analyzes data from all individual server security systems, and distributes smart security rules that are applied to and protect all machines.

Centralized big data analysis

Our Central Security system relies on the big data it receives from all the other server-level systems and analyzes the various attack sources, detects bigger patterns, and blocks many more attacks globally on the whole platform.

Web Application Firewall Data Feed

As mentioned above, every server has a WAF, whose main responsibility is to protect web applications like WordPress, Magento, Joomla, Drupal and others from a variety of attacks such as cross-site scripting (XSS), SQL injection, and more. The moment we become aware of a security threat (software vulnerability), our security engineers write a new rule to patch it and add that rule to our local WAFs. 

Every request that is not dropped at network level, is filtered by the server WAF. If the request is hitting the parameters of a WAF rule, the WAF sends information about it to the Central Security System. The Central System logs and analyzes all requests hitting WAF rules across all our servers (for example their IP and other metadata). If it detects a pattern, like multiple requests across many servers coming from the same IP address, the Central System will block that IP and distribute a rule to all the machines in our infrastructure. Depending on the specific case and the rule, the system may limit the suspicious IP requests to be challenged by captcha or entirely limit the traffic from it to any of our servers for a specific period (hours, days, weeks or even permanently).

Brute-force Prevention Traffic Patterns

As part of our brute-force prevention strategy, we have deployed local monitoring systems on all our servers. They monitor the login attempts to all applications hosted with us and report every failed one to the Central Security System. The system is notified of the attempt along with all important security information related to it, like an IP address, number of requests, IP history and more.  Every 60 seconds the Central Security System reviews the aggregated data and analyzes the volume and frequency of repetitive metadata looking for patterns. When patterns are clearly identified, the system creates blocking rules that are distributed to all servers. 

An example of this would be multiple failed login attempts on one or more servers, coming from the same IP address within a short period of time (different time thresholds are set for higher precision and effectiveness). In a case like this, our system would flagg the IP and the future requests coming from it towards any of our servers would be challenged with captcha.

Many more systems send data to our Central Security System

There are many more ways we feed our Central Security System with data – like monitoring login attempts to a server-level services like FTP, EXIM, Dovecot, etc; reviewing XML-RPC traffic of WordPress sites; inputting different traffic patterns from third-party systems, and more. 

The more relevant data sources we input, the bigger the pool of data becomes, which significantly improves the analytical power and accuracy of the Central Security System. Over time the System’s capability of effectively preventing attacks grows bigger and bigger. 

Enterprise-grade Protection on a Global Scale

And to wrap it up, here are some numbers that can help you understand the scale and effect of what the Central Security System does. On a daily basis over 260 million requests are challenged with captcha and less than 40,000 actually pass the challenge. We have more than 50,000 IPs currently flagged as bad or suspicious and nearly half of them are completely blocked from reaching our servers. The number is changing daily, as new IPs are flagged and challenged due to suspicious activity, while previously flagged ones get cleared after successful verification or ban expiration. 

All of these numbers and the comprehensive work involved in maintaining an effective Central Security System lead to the number that matters most – 99,99% of bad traffic blocked before it reaches your website.

[subscribe_cta]

Our Site Scanner Saved Thousands of WordPress Sites from a Massive Security Attack

site scanner services saves sites from attacks

In the middle of June, we launched our upgraded Site Scanner service. Little did we know back then how soon we would see the new functionality in full action. Just a few months after the upgrade the Site Scanner saved thousands of WordPress sites from a well-disguised attack, aiming to redirect traffic to bogus sites through a fake plugin, called Zend Fonts. Imagine all the reputation and other business damages a hack like this could have caused and take a read how our hero, the Site Scanner, saved the day.

How does the “fake Zend Fonts plugin” work?

The attack involved uploading an infected fake plugin called Zend Fonts through a backdoor. Once uploaded, the infected plugin would redirect site visitors to bogus scam sites without the site owner even suspecting it. The uploaded plugin file looks like that:

./wp-content/plugins/zend-fonts-wp/zend-fonts-wp.php

What makes the attack really bad is that this plugin file is hidden from the wp-admin or wp-cli plugin list, meaning the WP Admins would not be able to easily spot it, due to the following function:

//hide plugin
add_filter('all_plugins', 'hide_plugins');
function hide_plugins($plugins) {
        unset($plugins['zend-fonts-wp/zend-fonts-wp.php']);
        return $plugins;
}

Also it is configured to trigger the redirect only if the website is accessed by a normal user, not the site admin or editor:

//do redirect if user from REF and NOT Admin
        if(isset( $_SERVER['HTTP_REFERER']) && !$isAdmin){
                redirect();
        }

All these factors make the attack pretty much invisible for the site owners/editors, while the normal visitors would be redirected to scam sites. This hack could easily result in significant losses of sales, reputation damages, and other harms such as bad standings in search engines and more.

How did SiteGround detect the attack?

Our System Administrators monitor the load and behavior of our servers 24/7 and soon after this exploit was launched, we observed an abnormally high number of malicious files detected by our Site Scanner service crawling for malware. Our Sys Admins started digging further and spotted a pattern – there was an attempt for a massive fake Zend Fonts plugin upload affecting by that time around 2000 of our clients’ WordPress installations.

How does Site Scanner protect the sites it’s on?

Usually, in attacks like the Zend Fonts one, for the sites with Site Scanner Basic, reports are received in less than 24 hours after the malware is detected (right after the scheduled daily scan) and for those with Site Scanner Premium, an alert is received immediately after the (attempted) upload, giving our clients the opportunity to quickly react and delete the malicious files before they can cause any damage. 

Furthermore, for the sites with Site Scanner Premium where quarantine is switched on, the files never reach the attacked sites – they are safely quarantined for the site owners to review and delete when convenient. The quarantine effectively stops the attack and protects the sites from malicious hack attempts, and the business and reputation impact resulting from them. And the best part – the site owners don’t have to do anything.

Using Site Scanner data to protect all clients

Once our System Administrators had detected that the Zend Fonts plugin upload was not something isolated, but was happening across the whole platform, they deleted all malicious files from our servers. Furthermore, our Security Engineers added a new rule to our web application firewall (WAF) to prevent further attacks towards other WordPress sites hosted with us. 

We are quite excited to see how our Site Scanner service is actively protecting sites from a variety of really bad attacks. For massive, large-scale attacks such as the Zend Fonts plugin one, the Site Scanner helps us detect a pattern and take actions to protect all our clients by implementing WAF rules or enhancing our monitoring system. While this is something that we will continue doing, updating a platform-wide system takes some time and will not include smaller, site-specific malware attacks. If you want to have an early-on, comprehensive malware detection for your site, we strongly recommend that you activate one of our Site Scanner plans. And if you’re looking to not only detect but proactively stop malware attacks, get the Premium Site Scanner with quarantine on. 

To celebrate the Site Scanner success, this #CyberSecurityMonth we offer 3 months free for any new Site Scanner activation (both Basic and Premium) made until the end of October.

[subscribe_cta]

What is Phishing and How to Protect Yourself from It

Stay Safe From Phishing Attacks

With the rapid development of technology, the complexity of phishing attacks improves. The more technologically advanced people become, the more advanced the phishing attacks. Last but not least, now that everybody spends more time online, the number of phishing attacks also rises. Here is our short guide on simple things to remember in order to stay safe from phishing attacks, while browsing online.

What is Phishing?

Born circa 1995, just 4 years after the first site appeared, phishing refers to the practice of using deceptive emails and websites to illegally get personal and corporate information from users. That information – usernames, password, credit cards – is later used to steal either money or more information. 

The word “phishing” itself is a combination of “fishing” and “phreaks” which was what hackers used to call themselves. The practice of phishing is considered a form of social engineering, which is a term for manipulating people by falsely representing oneself in the context of web security. 

Types of phishing techniques

Spear phishing

What is spear phishing? Spear phishing targets a specific person or organization rather than random users. This scam usually intends to steal sensitive data or information from the specific victim, such as account passwords or financial information for malicious purposes. It requires specific knowledge about the victim such as some personal details. The cybercriminals use this information, usually in an email, to pretend they’re a trustworthy organization or person and acquire the data they need.

Spear phishing vs phishing

Both of them are online attacks that intend to steal sensitive information. However, phishing is the more general term for this type of attack, as this is basically any attempt to trick victims to share sensitive data. 

As per the spear phishing definition, it is personalized to the specific victim. It requires more thought, time and knowledge to achieve its goal. Since spear phishing’s messages are personalized, it’s more difficult to identify these types of attacks.

What helps protect from spear phishing is generally being careful with your online presence. Here are a few tips to follow in order to avoid spear phishing:

  • Be careful what personal information you post on the internet
  • Use smart and strong passwords
  • Update your software regularly
  • Watch out when opening emails and clicking on links

Microsoft 365 phishing

These types of attacks are phishing emails that target Microsoft 365 users. One of the most common things that attackers usually do is tricking victims into downloading a file by disguising its extension. Attackers use a special Unicode character, the right-to-left override. It allows them, for example, to disguise an “.exe” file as a “.txt” file. As a result, the victim downloads the “.exe” file which installs malicious software on their computer or laptop.

Whaling phishing

Whaling phishing is a highly targeted attack. This type of phishing attack targets particular individuals, such as senior executives, and disguises as a legitimate email. It attempts to encourage victims to do a particular action, usually related to transferring money or giving out specific information. Whaling phishing emails often target large financial institutions and are more complicated than general phishing emails because they target C-level executives.

These emails usually contain personalized information about the organization/C-level executive, create a sense of urgency, comply with the business tone, and they encourage you to do some of the following:

  • Click on a link that eventually brings malware
  • Transfer money to the attacker’s bank account
  • Provide further information about the business or individual

Voice phishing

Voice phishing is an attack which tricks individuals to provide important financial or personal information over the phone to third parties. You can become a victim of a voice phishing attack over various channels and devices, such as voice email, smartphone, landline phone, voice over IP, etc.

The message of such an attack usually informs the victim of a suspicious activity, related to their bank account/credit or debit card, etc. Then the attacker encourages the victim to call a phone number and provide more personal information or verify their account/identity. 

To protect yourself from such an attack, the best approach is to call the given institution via a valid contact channel you have and make sure that your account has not been compromised.

Business email compromise (BEC)

Business email compromise is an email message that appears legitimate, requests a particular action, and targets a specific company. The request in the message is usually about transferring funds to the attacker’s bank account that:

  • Pretends to be the “regular supplier” that has sent an invoice from an updated mailing address
  • Pretends to be the CEO of the company
  • Pretends to be an employee of the company and has hacked their email address
  • Pretends to be the lawyer of the company

Social media phishing

Social media phishing is related to attacks via social media such as Facebook, Instagram, Twitter, LinkedIn, etc. It aims at stealing your personal information or taking over your social media account. Such an attack can also result in financial loss due to getting data for access to financial accounts. To protect yourself from a social media phishing attack, follow these simple rules:

  • Don’t add/accept strangers as friends
  • Don’t click on links to update your personal information
  • Don’t use the same username and password for all your accounts
  • Use the latest version of your operating system

How Can You Prevent Phishing?

Because phishing can truly cost you a lot – from stolen money to huge data breaches in your company – taking proper safety precautions is a must. We’ve put together a shortlist of the things you need to keep in mind in order to stay safe online.

1. Pay Attention To The Sender and The URL in Your Emails

One of the most common phishing scams is to spoof a big brand by sending an email with their name (and usually color palette), and say there is something wrong with your account and ask you to log in “to fix it”. Usually, the look of the email is very similar to the original brand, however, there is a sure way to distinguish whether you’re looking at the real deal. 

A good way to identify phishing emails is to check the email address: scammers cannot create email addresses with the actual domain name of the company, so instead of help@bigbrandname.com it will usually look like bigbrandname@somethingelse.com. Look carefully at the email address and not just the name appearing in your email client!

Check the email sender and hover over the link to see the destination

You should also check the URL before clicking. This can be done by hovering the mouse over the URL provided in the email, it will usually reveal the domain it’s pointing at, so you can see where this email actually wants to take you. If it’s not the official domain of the brand, don’t click on it.

2. Avoid Downloading Email Attachments You Don’t Expect

Sometimes the email looks like legitime business emails, and they don’t pretend to be a big company, but instead send over an attachment containing some sort of malware. The email is often structured as a business offer or аn email sent by the recipient’s own company/management containing files with sensitive information.

If you don’t know who the sender is, definitely don’t open any attachments. If you know the sender, but you don’t expect anything from them, or there is something fishy about it, it’s better to be cautious. Call the sender and ask them if they meant to send you anything, as sometimes scammers hack into people’s email boxes and use them for phishing attacks by spamming their contacts.

Be watchful of the mail title, recipient and body

The most common format for the attachments is zip (.exe is usually not allowed), however, even Microsoft Office files can contain viruses, which can contain macros that need to be enabled. Overall, keep an eye for all kinds of attachments.

3. Always Check The Site You’ve Landed On

If you happen to click on a phishing link (usually via email or through instant messages), it will often take you to a website with a form of some sort. The purpose of these forms most often aim to gather your most sensitive information – usernames and passwords.

In order to be sure you’re at the correct site and before filling in any data, check the website address in the browser address bar.

Scammers can create a website closely resembling the design of the respective brand, but they can’t use their official domain or have the brand name in the domain (assuming the brand is trademark protected). So, often, these domains may resemble a brand’s name, but will never be the original one, and will have additional symbols, letters, or words. 

Usually, the scammy domains look completely nonsensical and sometimes the design and flow also feels odd, especially if it’s a known brand that you often see.

For example, when signing into Gmail, Google will never ask you to select your email provider or enter both your email and password on the same screen. So the flow you will often see on phishing sites is designed to resemble the original one, but it’s not. 

Always check the destination URL and site design before you enter your credentials

4. Ignore Money Requests

Another type of online scam that social engineers often use is misrepresenting themselves and asking for money under some form. An example of such phishing emails is a person in trouble, asking for financial help; you’re asked to send a small amount of money with the promise you’ll get way more in return. 

Sometimes these scams can take the form of extortion. A popular one was an email circulating in the past couple of years, stating that users have been recorded through their own webcams watching adult content and asking for money. Actually, this scam attack was so scary, it made the news as people were terrified – understandably so!  

Either way, if you are getting a money request under any form by strangers, it’s usually a scam; never give out money or financial information no matter how the situation is presented.

What should you do if you receive a phishing email?

Every time you receive an email, you need to be extra careful of the email address, the URL, their spelling, etc. After checking these and identifying that the email is actually a phishing email, you need to follow all of the steps below:

  1. Don’t click on any links & don’t open any attachments & don’t reply;
  2. Contact the alleged sender via official channel for communication;
  3. Report the email to your company & email provider & government body & the organization that allegedly sent the email;
  4. Mark the sender as junk or spam;
  5. Delete the email & remove from recycle bin/deleted items folder.

How to report phishing emails?

As previously mentioned, you need to report the phishing email to several people/institutions. Here we’ll show you how to report the email both to the email provider and to the government body.

How to report phishing emails to your email provider 

Let’s take as an example, Gmail accounts. Next to the “Reply” option in Gmail, click the “More” option and select “Report phishing”.

If you are an Outlook user, you need to select the phishing email message from the message list and above the reading pane, select Junk > Phishing > Report.

Other email providers have similar easy to use options for reporting phishing emails.

How to report to a specific institution, based on the country you’re in

The Anti-Phishing Working Group (APWG) is an international coalition that attempts to eliminate cybercrime. If you receive a suspicious or malicious email, forward it to this organisation at reportphishing@apwg.org. Below you can see some other country-specific institutions that can help you too:

  • For the USA, forward phishing emails to the National Cybersecurity Communications and Integration Center (NCCIC) at phishing-report@us-cert.gov.
  • For the UK, report the phishing email to Action Fraud, the UK’s fraud and cyber crime reporting center.
  • If you’re living in a European Union country, here you can find the reporting website, corresponding to your country, in case you are a victim of a cybercrime.

Final thoughts

Now that you know what is a phishing attack, you are much better prepared to protect yourself from it with our simple actionable advice. You can further explore our blog for similar topics and read how to protect your reputation by protecting your email.

[subscribe_cta]

Build in Security from Day 1 to Prevent Website Hacks

website hacks prevention

Website security should be on the mind of every site owner. It doesn’t matter if your site is large or small – if it is important to your business, you need to keep it safe and secure. As a site owner myself – and primarily a WordPress site owner – I’ve come up with a checklist I go through every time I spin up a new website for myself or a client. Let me share it with you in hopes that you will pick up a few new ideas. Let’s look at what it takes to secure a website.

Choosing A Secure Web Host

It should go without saying, but security starts with your web hosting company. I’ve used everything from ‘do it yourself web hosting’ to ‘concierge level hosting’. The trick is to find the level you need and the support you are comfortable with.

Check their support

The first thing I do when considering a new web host is to check their support and response time. I’ll sign up for a free trial, put up a site, and then ping support to ask a question. How quickly they respond and how well they understand the question gives me clues as to what I can expect from them if I host with them.

Check their security features

I’ll then check their website and hosting plans to see what security tools and features they provide. I’ll look for essential things like an SSL certificate to encrypt and protect my website data, domain privacy to hide my personal information from public Whois databases, 2-factor authentication to protect my website from unauthorized access, geographically distributed backups to have a safe copy of my website in case something goes wrong.

Other key security measures I’d like my website hosting provider to have in place is a Web Application Firewall – software that sits in front of my website and protects it from known bad traffic – to keep my host server safe from software exploits, DDOS and brute-force attacks protection, and the option for automatic updates to the latest PHP and WordPress versions to keep your site secure from malware.


If the host provides yet more security tools, that would be even better. For example, on top of all these features, available on the SiteGround platform, they also offer an in-house developed Site Scanner service and a free in-house built SiteGround WordPress Security plugin to make sure that your website would be as secure as possible.

Check their blog

Step 3 when selecting a web host is always to read the last 5 entries in their blog. 

  • Are they recent?
  • Do they talk about security?
  • Do the blog posts seem helpful?

No, not all blog posts are going to be about security, but I’d better be able to find a recent one. The Security landscape changes quickly so they need to be posting regularly.

Check their price

Finally, I check their pricing tiers and figure out where my site will fall. Price is the last thing I check because if the first two boxes aren’t checked then the price doesn’t matter. They could be giving it away for free and I wouldn’t use them.

Build Your Site Securely From The Beginning

Once you’ve laid a secure foundation for your website, it’s time to start framing it and building it out. At every step, you need to make sure that security is “baked in” not “bolted on”.

Security is baked in when you think about it before you start building your website

Security is bolted on when you build out your entire website and then decide to just add a security-focused plugin to cover your bases.

Baked in is always better.

What does it mean to bake in security?

Install an SSL certificate as soon as you get the website set up

Don’t wait until you are ready to deploy your website before you remember to install your SSL certificate. These days a secure website is just a few clicks away. Take the time to do it now and then make sure you force all traffic to be https after it is installed. For those users hosting with SiteGround, your Site Tools makes setting up and enforcing SSL easy. Just a few clicks and you are in business.

Set a strong password policy before you start adding users

Passwords are the lock on the front door to your site. When building out your site, put a strong lock on the front door by requiring all users to use strong passwords. Doing this before you let users start coming into your site will make sure that no users set up weak passwords.

Require Two-Factor Authentication (2FA) for any user that will have admin-level rights in the system.

Two Factor Authentication is the deadbolt on the inner office of your site. Yes, a strong password is important for anyone to get into the site, but to get to things like financial information or user management, you want a strong deadbolt as well. Keep your system secure by implementing 2FA for all your admins. The SiteGround Security plugin makes setting up 2FA very easy.

Set up a backup system that will regularly backup your entire website and store those backups securely.

You need a 30-day backup system implemented from day 1. Not 1 day, not 7 days, 30 days. The reason is, that if your site gets hacked, you may not notice immediately. Once you do notice, you want to clean your site and one of the best ways to do that is to restore your site from a clean backup. 

SiteGround’s Site Tools provides an intuitive tool for scheduling nightly backups and restoring from them when needed. 

While we are talking about backups. Don’t forget to force a backup before any upgrade, major site redesign, or installing a new plugin. It never hurts to have a fresh backup in case things go bad.

Adhere To The Principle Of Least Privilege

Before you start letting users into your system, think about the roles that they will play. A role is a set of permissions or privileges and you want to give each user the absolute minimum level of privilege they need to use your site.

There are several good role editors for WordPress and I suggest you install one, learn how to use it, and then audit the roles you have in your site to make sure they have only those privileges they need to use your site. 

On a regular basis – at the very least once a year – review these privileges to make sure they are still valid and to make sure that no role has been granted a privilege it does not need. 

Most users are not trying to do bad things, but we have to assume they would if they could. Adhering to the Principle of Least Privilege will help make sure that bad actors, or curious users, can’t do things to your site they aren’t supposed to.

Only Use Software From A Trusted Source

In software development – as in building a house – your supplier’s reputation is critical to your project’s success. If you use a cut-rate supplier for the framing materials of your house, the entire project will suffer. Worse yet, it will cost you more later on to fix these problems than it would to just buy good materials to begin with.

Building your website with quality materials like plugins and themes from reputable vendors will usually cost you money in the short run. However, knowing that you have companies standing behind their products and updating them when issues arise is worth the money.

Yes, you can choose a free plugin or theme to build a critical feature of your website. However, what do you do if you discover that there is a security flaw? Worse yet, what do you do when you discover that flaw and then discover that the author has abandoned the project? At that point you have 2 options, neither good.

  1. Hire a developer to fix the security flaw
  2. Rip out the plugin, find another one that does the same thing, implement it and make any changes to your process that are necessary.

Both of these can be expensive propositions that could be avoided by simply choosing wisely in the beginning.

SiteGround recently looked at the data from a lot of compromised websites. What they found was that the majority of the compromised websites were compromised because they had unpatched plugins that had security flaws in them. Much of the time these were the free versions of paid plugins downloaded from untrustworthy sources. Only download plugins and themes from trusted sites like WordPress.org or vendors you trust.

The WordPress plugin repo is a reputable source. WordPress.org has implemented a review process – both human and scanning software – to help filter out plugins that have potential security issues or otherwise violate WordPress policy.

Scan Your Site Regularly

Just like you build a security system into your house, you want to set up a security scanner for your website as soon as you build it. Security scanners look at your site both internally and externally to make sure that there are no known vulnerabilities. It will check your website for viruses as well. No security scanner is perfect, just like no home security system is perfect. But your website is more secure with one.

A good scanner will look for things like cross-site scripting vulnerabilities among other things. These vulnerabilities can allow your site to be used in the attack of other sites or attacks on the end user themselves.

SiteGround has a great scanning system available. I get regular emails from it telling me which sites it has scanned and either that they are all clear or that there is an issue I need to address…immediately.

Once you’ve built a new house, you don’t hand out keys to anyone who asks, even if they claim to have a good reason for wanting in. Similarly, you want to make sure that if you get an email that says it is from your site, you don’t automatically click on the link.

You should know every email your system is capable of sending. When you get one that you don’t remember setting up, you need to investigate. Don’t click, start looking at it. Check the headers, look at the exact URL any links go to. Most importantly, quarantine the email using your virus detection software. 

Unknown emails purporting to come from your site are just another way that bad actors try to get into your site. These phishing attacks come from servers that are not under your control, so you can’t stop them. You can, however, be aware so that when you get them, you delete them. In almost all cases, if you don’t click, the email itself can’t do any damage.

Tools I Regularly Use To Bake Security Into My Sites

Keeping a WordPress website secure doesn’t have to be a full-time job if you bake security into it from the beginning. To do this, there are a couple of tools I use on almost every WordPress website I have.

The SiteGround Security Plugin is the first plugin I install on any new website I spin up. I install it, I install an SSL certificate, and I configure everything to be secure before I do anything else. If I get this part right, everything else is easier. 

The SiteGround Optimizer plugin is a great way to make my site faster, but it is also where I check the “HTTPS Enforce” checkbox. This way all the traffic on my site goes over HTTPS even if it wasn’t originally. Having an SSL certificate is important, enforcing it on all traffic is equally important. 

SiteGround’s Site Tools have a lot of great options to make managing a website easy. The one tool I use in setting things up though is the Backup tool. After I get SiteGround Security and SiteGround Optimizer setup and configured, I have my foundation laid – I force a backup. This is my fallback in case I mess something up while building out my site. 

Then before I install each plugin or theme, I create a new one. I name these backups “BEFORE “ + the plugin or theme name. This way I can roll back to any point in the process.

Wrap Up

If you lay a secure foundation for your website and then think about security at every turn, then you can rest easy at night, knowing that your site is as secure as possible. No website, however, is bulletproof. Therefore, the last step is to build your Disaster Recovery plan. What steps do you take when your site has been hacked?

The SiteGround Security plugin has a series of steps you can take just for that situation. It is not a complete disaster recovery plan but when you combine it with 30 days of backups, you are well on your way to having one.

[subscribe_cta]

95% Less Bad Traffic with Enhanced Brute-force Prevention

brute force system improvement

We have been talking about brute-force attacks in the past, but the truth is that many of our clients don’t even realize how real and how common the threat of these attacks is for anyone with a website. Based on our experience of hosting millions domains, we fully understand the destructive potential of brute-force and we have set defence mechanisms to prevent and mitigate such attempts directed at the websites we host. For years our AI brute-force prevention system has been successfully blocking millions of attacks every day. Now, we are happy to announce that the system got even better – by constantly learning from thousands of brute-force attempts per day and adding new functionality for traffic validation, it now filters 95% more of the bad queries!

Advanced AI system that recognizes & blocks brute-force attempts

Analyzing traffic behaviour and recognising patterns is the core feature that makes our AI brute-force prevention system so effective. When a behaviour that matches a certain pattern associated with brute-force is detected (like too many unsuccessful login attempts from an unrecognized location for example), the suspicious source is immediately challenged with a CAPTCHA page that only a real human can pass. This effectively stops brute-force attempts, adds up to the system knowledge and enables legitimate users who have accidentally mimicked a suspicious behaviour to reach the requested location by completing the captcha. The beauty of this constantly evolving system is that it gets better with every brute-force attempt it stops, it keeps sites under attack safe and it ultimately protects the other websites hosted on our servers by blocking bad traffic before it even targets them.

NEW: Traffic validation that minimizes the number of brute-force attacks

We have recently upgraded our system to become even more powerful.  We are now able to more efficiently block the great majority of malicious non-human bots – e.g. incoming brute-force attacks or data hunting agents which aim to profile your site and later hack you through future software exploits. That significantly boosted the system success rate and reduced bad visits by roughly 95%. 

The best example to illustrate how the system works is with the XML-RPC, a file in the root directory of every WordPress installation. Many (WordPress) hosts block its usage because it’s known to be insecure and blocking it is the easiest way to avoid XML-RPC-related hacks. However, XML-RPC also has many legitimate use cases for communicating with external systems and software. That is the reason we don’t aim at stopping XML-RPC – we want to empower our clients to use the tools and services they need to get the best of their websites. Instead of blocking it, we have looked for ways to harden its security and significantly decrease the potential for brute-force attacks. After our latest AI brute-force prevention system upgrade, we now validate all traffic coming through XML-RPC to stop all recognized malicious visits and eventually reduce the overall hits reaching the clients’ sites through XML-RPC by 99%. This means that we successfully filter potential brute-force sources before an attack is even attempted.

Less resource consumption, lower carbon footprint

The impact of this upgrade to our AI bruteforce prevention system is enormous. Not only are we further minimizing the chances for our sites to get brute-forced and potentially hacked, but we significantly reduce resource consumption (like CPU and RAM) generated by traffic coming from bots and brute-force attempts. Lower resource consumption effectively means more resources available for your legitimate visitors and a lower carbon footprint of your site. 

Preventing brute-force attempts is just one of the many ways we constantly protect the websites we host, along with our Smart Web Application Firewall, DDoS protection, 24/7 server monitoring and many more. We believe that security is one of the foundations for any successful website, and we continuously develop new prevention and mitigation solutions, improve existing ones and keep adding new security features to our hosting, so you can have the peace of mind that your website is in good hands and focus on what’s important – your business.

[subscribe_cta]

You Can Now Block Country Traffic to Protect your Website

traffic blocking tool announcement

The security of our clients’ websites has always been one of our top priorities and something that we continuously improve on. The latest tool in our website protection arsenal, available for FREE on all hosting plans, is the option to easily block the traffic coming to your site from specific countries. This will not only increase your website security, but can also help website performance by decreasing resource usage when blocking the traffic coming from locations you would rather not get traffic from.

When to consider blocking the traffic from a specific country?

There are different reasons why someone would like to block the traffic from a specific country to their site, but the most common are the following:

  • To Stop Malicious Traffic

If you notice abnormally high traffic from a country that your site is not targeting as audience, or you start receiving too many spam comments from such a country on your blog posts, or you identify any other behavior you consider suspicious, coming from a geographic region that’s not your main user target, it may be a wise idea to block the traffic from this location.

  • To Streamline Your Business

There are various reasons due to which you might not be willing or able to do business with certain countries. Some examples are expensive and/or complicated deliveries; legal requirements that prevent you from providing your service, heavy taxation requirements, etc. Now, if you need to stop access to your site from a specific country due to such reasons, this can be easily done through your Site Tools.

How does SiteGround country block work?

Adding a country to your Blocked list is easy. You need to go to your Site Tools > Security > Blocked Traffic  > Block Country section:

Once a country is blocked, all visitors coming from an IP address that we identify as being located in this country will start seeing our default Country Block HTML page.

The tool allows you to block multiple countries, and also to block certain countries from accessing your main domain, or specific sub-domains. You can review the list of all countries you have denied access to, and/or add or remove countries from it with a click of a button at any time. 


Our new Country blocking option is also fully compatible with our SiteGround CDN and visitors from blocked countries would not be able to access your website pages whether you have our CDN service activated or not.

[subscribe_cta]

Sell Digital Products and Grow Your Online Business with Managed EDD Hosting

image announcing the partnership between SiteGround and Easy Digital Downloads

At SiteGround we’re constantly working to add even more value to our services and respond to our customers’ growing business needs. Now, we’ve made it easier than ever to sell digital products online by partnering with Easy Digital Downloads – the leading WordPress-based eCommerce platform for selling digital products. You can now take advantage of a powerful managed eCommerce hosting platform for EDD to launch a ready-to-go eCommerce WordPress website in minutes and grow your online business even further!

Selling Digital Products Online Is a Growing Trend

Digital products are booming nowadays because of their numerous benefits. They provide high profits, as their production costs are low. Unlike physical items, there’s no limit to the inventory and no delivery costs. Digital buyers get what they need easily and immediately – in just a few clicks. Let’s take eBooks as an example. They are the top-trending digital item, and their industry is projected to reach $13.62 billion revenue in 2022. Other digital products in high demand include audio books, podcasts, videos, music, photography, software, web designs, and many more.

All You Need to Easily Start, Manage, and Grow an Online Store

If you want to join this growing trend and start selling digital products on WordPress, we’ve got you covered. Our new Managed EDD eCommerce hosting solution dramatically simplifies the process for setting up a WordPress eCommerce site by combining the premium hosting services of SiteGround and the eCommerce functionality of Easy Digital Downloads. You get WordPress pre-installed with the Vendd theme – a full-featured marketplace theme for EDD that gives you many options and features, together with the EDD plugin – the complete eCommerce solution for selling digital products on WordPress. On top of that, we add our powerful WordPress speed and security boosters – our top-rated SiteGround Optimizer and SiteGround Security plugins.

All you need to do to get all that is visit our Managed EDD Hosting page and choose the best hosting plan option for your online business. With no technical skills required, you’ll have your eCommerce site ready and fully equipped with premium features in a few clicks:

  • Sell online any digital products, such as eBooks, photos, videos, PDFs, plugins, software licenses, and more.
  • Build an amazing online store in minutes – with SiteGround WordPress Starter wizard pre-installed.
  • Have payment flexibility and accept credit card payments using Stripe, Apple Pay, Google Pay, and PayPal. Besides, you get flexibility on recurring payments and additional payment gateways.
  • Manage customers easily by keeping a record for each customer and tracking customer lifetime values. What is more, the managed hosting platform includes a built-in Customer Area so you can easily access the purchased digital goods and keep track of purchases.
  • Create and manage promotional campaigns by choosing the type of discount, specifying the products, setting an automated time period (start and end dates), and more.
  • Get full data reporting with the built-in reporting feature for stats viewing and custom reports creation. You can filter, track and export data about specific products, earnings, downloads, sales and more.
  • Enjoy tried-and-true website speed and security solutions – our top-rated  SiteGround Optimizer and SiteGround Security guarantee the best performance and security for your eCommerce website.
  • Enhance your store functionality with tons of extensions, such as a simple plugin installation or marketing integrations to improve your store and your visitors’ user experience and respond to your needs and budget growth.
  • Get top-rated, 24/7 live support for your eCommerce site.

Why Easy Digital Downloads (EDD)?

We’re already offering plenty of ecommerce features, like a free SSL, free CDN, business email, premium support, and more, but we were looking to simplify the online store management experience even further. We only partner with services that complement our own with the highest standard of quality and best in their class, and we’re committed to long-term partnerships with trusted providers we’ve been working with and using throughout the years.

Easy Digital Downloads is the most popular and useful WordPress-based eCommerce platform for selling digital products for WordPress online and is already used by more than 50,000 website owners. It was recently acquired by Awesome Motive, the leading software and media company helping shape the web for billions worldwide. Collectively, their software powers over 20 million websites and includes many of the well-known website tools such as OptinMonster, WPForms, MonsterInsights, All in One SEO, etc., and now also Easy Digital Downloads.

Syed Balkhi, CEO of Easy Digital Downloads, who’s also contributed to our expert round-up How to start your online business on a budget, commented, “EDD’s partnership with SiteGround offers small businesses around the world an easy way to start their eCommerce website and have peace of mind when it comes to on-site payments, security, and performance. Because EDD is open-source, it also helps small business owners retain full control and freedom over their online business vs. getting locked into a proprietary SaaS eCommerce platform”.


To start selling digital products easily on WordPress, go to Managed EDD Hosting, purchase the hosting plan that best suits your business needs, and get your eCommerce website ready-to-go in no time.

[subscribe_cta]