Get your WordPress on PHP 7.0 now!

We have just released a new version of our WordPress plugin 3.2.1 the SiteGround Optimizer, which allows you to move to PHP 7.0 with a click.  We encourage all SiteGround customers to utilize this great option and make their WordPress installation run on PHP 7.0 now. PHP 7.0 has been available on our servers for over a year and it is high time that all of our customers take full advantage of the considerable performance boost it provides.

Continue reading “Get your WordPress on PHP 7.0 now!”

SG Site Scanner powered by Sucuri

The service has been gone through multiple upgrades since its launch and is no longer powered by SUCURI. Current information about it can be found on its sales page in Client Area: https://my.siteground.com/marketplace/hosting/sitescanner.

Having a website regularly scanned for security issues is something we have always highly recommended to our customers. Our site scanning service (known as HackAlert until recently) has always been among the best sellers and is used by thousands of our customers to check their websites and inform them in case of malware. Today, we are happy to announce that we have introduced a number of improvements to these services. It is now called SG Site Scanner, it is powered by one of the most prominent web security experts – Sucuri.net, and it is simply awesome!

Why Sucuri?

There are several reasons to change our scan partner from Armorize to Sucuri. First, Sucuri is one of the most respected companies in the website security field. In addition, we have been working in partnership with them for several years. We have relied on their expertise for solving numerous complex security issues. And last, but not least, many of our clients’ websites have also been cleaned by Sucuri from malicious code over the years. That is why it was only natural that we extend this already successful partnership and make it cover the daily site scans too.

What is so good about SG Site Scanner?

More efficient scanning and reporting

We now scan all the pages that are linked on your website homepage (or any other page of your choice) on a daily basis. This has proven to work more efficiently than the previous system of scanning a limited number of 10 random pages. If any issue is detected, the site owner immediately receives a notification email.

More convenient interface

The SG Site Scanner report page is part of your SiteGround Customer Area now. It is no longer needed to log into another interface to access information on the security status of your site. In case of an issue all infected URLs and/or blacklists are conveniently listed in the interface. It also allows you to push an unscheduled scan with a click and you can easily switch on and off the weekly email status reports.

If you already have HackAlert, no action is required on your part — it has already been replaced with the SG Site Scanner. If you are still not using any regular scanning service, we strongly recommend that you start today. You can order the SG Site Scanner for any domain of your choice in your Customer Area.

[subscribe_cta]

NextGEN Vulnerability Patched on SiteGround Hosting

Yesterday, our partners from Sucuri discovered a serious SQL injection vulnerability in one of the most popular WordPress gallery plugins – NextGen Gallery. Our security team started working immediately on the issue and created a rule in our web application firewall (WAF) to block any potential attempts to exploit this vulnerability. However, we strongly recommend that all NextGen Gallery users update their plugin to version 2.1.79 which fixes the core of the issue in the plugin code.

[subscribe_cta]

Cloudflare HTTPS and WAF Update

UPDATE

Since the launch of our own in-house built Content Delivery Network – SiteGround CDN, we are no longer providing Cloudflare services as part of our hosting plans.

Since we launched our integration with Cloudflare in 2012 we have seen thousands of our customers benefit from its CDN and the site security functionalities. Today we are happy to announce two improvements in the Cloudflare packages we provide. First, the SSL is now supported in the free plan of the service. Second, we have included a very cool security feature – the Cloudflare Web Application Firewall, in our Plus plan.

Continue reading “Cloudflare HTTPS and WAF Update”

WordPress AutoUpdater Restarted

We first launched our WordPress AutoUpdater in 2012. Some tweaks were made to the system a year later when the original AutoUpdate feature was included in the WordPress core, but we continued to rely primarily on our own system for our customers. The SiteGround AutoUpdater has been used successfully for the last 5 years and has kept a lot of our customers up-to-date and safe from hacks. Thanks to it, more than 70% of the WordPress installations on our servers have been constantly using the latest software version. However, we have been thinking for a while how to get this percentage even closer to 100. The recent security issues with WordPress REST API motivated us to introduce a change into the system that increased the upgrade rate to more than 90%.

Continue reading “WordPress AutoUpdater Restarted”

Are You Ready to Get Hacked?


In the security world, the following advice seems to be gold: keep templates and plugins up to date; use secure passwords and captchas; be careful whom you give access and to what; use a security-conscious web host.

While those are all great tips and we encourage them, your website is still (and always will be) hackable. We’ve seen and helped clients with numerous hacks over the years, so we wanted to share some advice that goes beyond following security best practices.

As your user base and reputation grow, getting hacked becomes more likely and it really can happen to anyone. Therefore, the best thing you can do is to have a hack recovery plan. In case of disaster, you’ll know exactly what needs to be done, and who can do it for you. You won’t panic and make hasty decisions that may turn a crisis into a catastrophe.

1. Be the First to Know

You don’t want to find out about a hack from a random visit to your own site. You don’t want to see the red screen of death, with an unwelcoming message like “Danger: malware ahead!” or “This website may harm your computer”. You don’t want to see your homepage defaced (at the time of writing, a WordPress REST API Vulnerability is at large and defacing thousands of websites).

The worst thing about finding a hack by accident is that you probably won’t know how long it’s been there. You won’t be able to put the damage into perspective.

The solution is to set up one or several proactive tools that detect hacks and notify you.

Front-end/Source Code Monitors
There are tools that monitor the front-end of your site for uptime and content changes, such as Pingdom. There are also tools that monitor the source code of your website for hacks, such as our own HackAlert service. Both can be set up to send various notifications and the options here are endless.

Google Search Console Alerts
Although you cannot count on it for an early warning, Google’s Search Console detects a plethora of hacks. Set up your site and make sure to enable email alerts in the preferences. It’s a good idea to keep an eye on Google’s security status regarding your site. Best of all, it’s free.

2. Make a Backup

You will need a backup copy of the hacked site to be used later when removing malicious code. Make a backup and save it before going into maintenance mode.

That being said, make sure your site is backed up regularly and several copies are kept at all times. A clean copy can also be of help when later recovering your site. Your web host will usually make backups for you, but there are plenty of tools and plugins to set up backups yourself.

3. Get the Access Logs

Another thing to be used in the recovery of your site is access logs. Talk to your host whether they can provide them and how far back in time. Some attacks are difficult to find and may require logs from 6 months ago. If your host cannot provide that, set up log keeping yourself. At SiteGround, and probably other hosts, access logs can be downloaded from the Statistics tool.

4. Have Maintenance Mode Ready

Going into maintenance mode as soon as possible is important. Search engines constantly check the HTTP status of your site and what content it is serving to visitors. Having your site down or serving malicious content will obviously damage your rankings.

This is why it’s a good idea to have a simple HTML maintenance page ready before you ever get hacked. You’ll be able to enable it quickly, while your site is being cleaned, minimizing damage in the eyes of both visitors and search engines.

The best way to enable maintenance mode is by using .htaccess to redirect all requests to an html page. This way, any malicious files left on your domain will become inaccessible and will forward to the said page.

5. Clean the Website and Vulnerability

To clean your website, you can either restore from a clean backup or remove the malicious code from files and databases. Whatever the method of cleaning, you will have to make sure the vulnerability is eliminated afterward.

Restoring a Clean Backup
This is the fastest, easiest and cheapest option that most people will be able to perform on their own with their backup tool. However, it comes with some disadvantages. If you are running a website that is updated frequently, you may lose some data (e.g. an online store might lose some orders). Also, you can never be sure that the backup you are restoring is completely clean.

Remove the Malicious Code From Files and Database
This is the more effective option, but it can prove extremely difficult depending on the hack. If you are not completely sure what you are doing, it’s best to use a 3rd party cleaning service. Identifying and removing attacks is well beyond this blog post.

Eliminate the Vulnerability
This is where the access logs come into play, however, once again this can become a difficult task that you should be confident with when performing it on your own. At the end of the day, you need to know the malicious code was removed from your files and database, together with the vulnerability used to access and modify those files and databases.

SiteGround customers can order a thorough malware cleanup, by going to Client Area -> Contact us -> Expert Care Service -> Malware Cleanup.

6. Return to Live

At the end of the process, you should change all passwords of all users, tools, and devices that have access to your site (control panel, FTP, SSH, etc.). Make sure the same is done by all website collaborators. Do this before you go live.

Another thing you should consider at this point is your website users and visitors. Analyze the situation and find out if any of their data was exploited during the attack. If yes, it’s a good idea to communicate it, along with a password change and any other needed actions to users.

How to secure your WordPress website? (video tutorial)

[subscribe_cta]

HTTPS for WordPress With a Click

UPDATE: If you’re using CloudFlare with your website, make sure you set the SSL Option in our CloudFlare tool in cPanel to Flexible,  then configure WordPress to work through HTTPS and finally, switch the option in CloudFlare to Full Strict. This way, you will not have any downtime during the reconfiguration process. Check out our CloudFlare tutorial for additional information on that matter.

A month ago we made the first step to increase the adoption rate of SSL certificates amongst our customers by starting to issue automatically Let’s Encrypt certificates for all domains hosted on our servers. However, there still remained a manual step to configure all applications to use the certificates we’ve made available. We knew that if we really wanted to see a rise in the HTTPS usage we not only needed to provide the SSLs, but also make it easy for our clients to implement them. Today we are happy to announce that we have achieved this second goal for a large group of our customers — the WordPress users.

Continue reading “HTTPS for WordPress With a Click”

Our Affiliate Program in 2016 – Founded on Product Quality and Trust


2016 was the most successful in the history of SiteGround. We kept growing in terms of clients and employees and we worked on many new projects that improved further the quality of our service. One of the key factors for our success is the relationship with our affiliate partners. During the past year, we welcomed 63% more affiliates and witnessed a 60% increase in the number of affiliate sales. We have distributed nearly $6 million in commissions.

Continue reading “Our Affiliate Program in 2016 – Founded on Product Quality and Trust”

2016: See Our Recap of Another Great Year!


2016 marked another great year for us – our 12th in the hosting business. We kept growing our team, became a distributed company, upgraded our platform for even more security and stability and did a bunch of other great things! We gathered it all in our annual recap to share our moments of hard work, achievement, and joy with all of you. Join us in celebrating our milestones of 2016!

See our year in review

[subscribe_cta]

Happy HTTPS 2017 to you!

Last year we made a big step towards making the SSL certificates more widely used. We backed financially the super cool open SSL project Let’s Encrypt and we provided an easy cPanel interface, from where all our users can issue free Let’s Encrypt certificates with a single click. This has resulted in more than 40 thousand new SSL installations on our servers. However, there is still a long way to go before we see HTTPS protocol completely replace the insecure HTTP.  Now, in the very beginning of 2017, we are happy to announce that we have taken the next big step in this direction — we have started to automatically issue Let’s Encrypt certificates for every domain that is hosted on our shared servers.

Continue reading “Happy HTTPS 2017 to you!”