site keeps getting hacked, don’t know who to believe
-
I don’t do much with web sites anymore, but I do maintain the site for where I work and the sites for two or three clients. One of those sites keeps getting hacked and I don’t know what to do. My gut feeling is that the first time the site got hacked it was due to another user’s password not being secure, because one day I randomly got an email saying my password had been changed but I didn’t change it. When I finally got back in to the Dashboard (after some tech support help from the hosting company) I found that my account email had been changed to haniawan96 at gmail.com. After that I enabled 2-factor authorization through the WordFence plugin for all users.
The hosting company is telling me that the hacking will keep happening unless the site owner pays $30/month for their site security plan which includes a firewall. We are already using the WordFence plugin and I know it includes a firewall, but the hosting company says plugins are useless.
I tried talking to a colleague, but she designs sites and uses someone else for hosting so she referred me to him. He was very nice and wanted to help, but the site would have to be moved to his servers and the owner would have to commit to his managed hosting plan for $40/month.
I don’t know enough to be able to tell if the hosting company is telling me the truth, or if they’re just trying to sell their security service. Is it possible the hacking keeps happening because of malware-infected plugins? Or is it happening above the WP level and the site really DOES need the host’s security service? Would it do any good to recreate the site with a fresh install at another hosting company?
The site is frederic-mi.com; it works intermittently right now so you may be able to see some things, or you may not.
- The topic ‘site keeps getting hacked, don’t know who to believe’ is closed to new replies.