WordPress Security

WordPress Site Security: Prevention vs. Response and the Truth About WordPress Malware Scanners

Challenging conventional thinking about the role of malware scanners and shining a light on security best practices that focus on prevention.

Jennifer Schramm

There are many tools and plugins that allow developers to provide security for a website. But there are only two ways to approach WordPress security strategically: with an emphasis on prevention or a process for clean up.

In a recent webinar, “The Truth About WordPress Malware Scanners,” Nathan Ingram hosted Dan Knauss from the SolidWP team to discuss common misconceptions about malware scanners as a preventative measure when, in reality, malware scanners are reactive tools. Dan sums it up well:

“Think about website security like a home. When you are using a cleanup tool like a malware scanner, the call [threat] is coming from inside your house. You’ve been compromised. You can no longer trust your security measures, and your scanners have actively been defeated.”

Learn more in Dan’s article, “Why Malware Scanners Are Worthless.”

The alternative – and indisputably the best practice – is to approach site security proactively, building a “moat” around what you seek to protect. Audience member Bonnie Burckel suggested a “three-moat” analogy, or what Stacy Clements of Milepost 42 pointed out is called a “Defense in Depth” strategy in the security industry.

When you have a good host and lock down WordPress in the areas that are targeted for breaches and attacks – compromised user accounts, themes, and plugins – the chances of getting hacked are “really, really, really, really low,” says Knauss.

Prevention is where Solid Security places its entire focus. That is why it does not include malware scanning capabilities in its feature set. “We don’t want our users focusing on cleanup or dealing with financial or reputational blowback from compromised sites. Let’s do everything we can to make sure the site doesn’t get infected in the first place,” says Timothy Jacobs, lead developer for Solid Security.

For an informative and eye-opening discussion on malware scanners vs. proactive site protection, watch the full webinar.