{"id":30818,"date":"2017-11-07T16:32:11","date_gmt":"2017-11-07T22:32:11","guid":{"rendered":"https:\/\/wpengine.com\/?p=30818"},"modified":"2025-11-25T10:22:19","modified_gmt":"2025-11-25T16:22:19","slug":"11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you","status":"publish","type":"post","link":"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/","title":{"rendered":"11 Top WordPress Security Concerns &amp; How WP Engine Takes Care of Them For You"},"content":{"rendered":"\n<p><span style=\"font-weight: 400\">Security is a major concern for sites of all shapes and sizes. <a href=\"https:\/\/ung.edu\/continuing-education\/news-and-media\/cybersecurity.php\" target=\"_blank\" rel=\"noreferrer noopener\">According to the University of North Georgia<\/a>, a cyberattack takes place approximately every 39 seconds, and 95% of successful attacks are able to gain access to information due to human error.<\/span> <\/p>\n\n\n\n<p><span style=\"font-weight: 400\">At WP Engine we do a lot behind the scenes to ensure your site is safe and secure! <\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Vulnerable Site Code<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">Between WordPress core, plugins, and themes, there\u2019s a lot of site code to keep track of. What happens when a vulnerability is discovered? How do you know if sites are affected and how do you update them? <\/span><b>Easy.<\/b><\/p>\n\n\n\n<p><b>WP Engine handles automatic WordPress updates.<\/b><span style=\"font-weight: 400\"> We automatically update sites to the latest secure patched branch when WordPress releases them. WP Engine monitors shared and private vulnerability feeds to ensure the platform is hardened against new vulnerabilities.<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Unauthorized Disk Writes<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">What if a plugin with vulnerable code is installed? That plugin might try to write files to the server, which may be vulnerable to attackers. If exploited, this could continue in a vicious cycle until your site completely unusable. <\/span><b>Not with WP Engine.<\/b><\/p>\n\n\n\n<p><b>WP Engine limits disk write capabilities.<\/b><span style=\"font-weight: 400\"> That means only authorized users can write files to the server, limiting the extent of the damage.<\/span><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1005\" height=\"340\" src=\"https:\/\/wpengine.com\/wp-content\/uploads\/2017\/11\/post-exploits-.jpg\" alt=\"a red skull icon overlaid onto a screenshot of the admin dashboard view of a WordPress site page\" class=\"wp-image-30843\" srcset=\"https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/post-exploits-.jpg 1005w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/post-exploits--300x101.jpg 300w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/post-exploits--768x260.jpg 768w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/post-exploits--303x103.jpg 303w\" sizes=\"auto, (max-width: 1005px) 100vw, 1005px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Common Issues<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">Some users may be aware that the XMLRPC.php file on your WordPress site exists to help remote apps make WordPress posts. Unfortunately, some attackers know about this file and try to exploit it by making fake POST requests to this service. That means attackers could be trying to hack into your site using this file. <\/span><b>We\u2019ve got you covered.<\/b><\/p>\n\n\n\n<p><b>WP Engine blocks XMLRPC attacks.<\/b><span style=\"font-weight: 400\"> WP Engine automatically detects malicious requests trying to take advantage of XMLRPC misconfigurations.<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Database Containment<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">Best practice when creating a WordPress site is to manage all separate users for your WordPress sites. This is a \u201ccontainment\u201d strategy which states that, should one database become compromised, the others are not at risk. But managing many usernames and passwords and salts and keys can be confusing and frustrating! <\/span><b>We take care of it.<\/b><\/p>\n\n\n\n<p><b>WP Engine maintains separate databases and users for all sites.<\/b><span style=\"font-weight: 400\"> We maintain all the security aspects of users, passwords, and salts to make it easy for you. Your WP Engine site is automatically connected to the correct database, as is your WP Engine User Portal.<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Unauthorized Configuration Changes<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">Some of the most important settings on your site are controlled by a select few configuration files. Those files should never be accessible or even worse, editable, to the outside world. It may be concerning to think about how to control who can access these sensitive files. <\/span><b>With us, there\u2019s no need to worry.<\/b><\/p>\n\n\n\n<p><b>WP Engine protects your site\u2019s configuration files and uploads. <\/b><span style=\"font-weight: 400\">We automatically place server-level protections for your configuration files for WordPress and the server itself, as well as your site\u2019s uploads folder.<\/span><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"2008\" height=\"683\" src=\"https:\/\/wpengine.com\/wp-content\/uploads\/2017\/11\/passwords.jpg\" alt=\"Weak password options with a large black X overlaid on them\" class=\"wp-image-30844\" srcset=\"https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/passwords.jpg 2008w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/passwords-300x102.jpg 300w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/passwords-768x261.jpg 768w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/passwords-1024x348.jpg 1024w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/passwords-303x103.jpg 303w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/passwords-1300x442.jpg 1300w\" sizes=\"auto, (max-width: 2008px) 100vw, 2008px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Insecure Passwords<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">Site managers often have the headache of ensuring all users on their sites are using secure passwords. Making sure users choose secure and unique usernames and passwords can be a chore in and of itself. <\/span><b>We make it easy.<\/b><\/p>\n\n\n\n<p><b>WP Engine requires all Administrators, Authors, and Editors to use strong passwords.<\/b><span style=\"font-weight: 400\"> While Subscribers and Contributors don\u2019t have this requirement, this means anyone who has the ability to publish content on your site must have a strong password.<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Encryption of User Data<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">You might also be concerned about the data users enter when they\u2019re on your site. Whether your users are filling out a form, building a profile, commenting, or entering their personal details in checkout, you have to be sure that data is secure. <\/span><b>We\u2019re here for you.<\/b><\/p>\n\n\n\n<p><b>WP Engine offers free Let\u2019s Encrypt SSL Certificates.<\/b><span style=\"font-weight: 400\"> SSL is a layer of encryption that sits in front of your site and ensures the user data entered on your pages is not vulnerable to anyone who might be listening in.<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">File Transfer Encryption<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">You may also wonder what protection is in place when transferring files to and from the server. If those files are not encrypted, it could allow anyone \u201clistening\u201d on your network access to those private site files. <\/span><b>Your files are safe with us.<\/b><\/p>\n\n\n\n<p><b>WP Engine forces secure file transfers.<\/b><span style=\"font-weight: 400\"> We use Secure File Transfer Protocol (SFTP) for all local connections to your websites. That means your data is encrypted both when uploading and downloading content to and from your site.<\/span><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"2009\" height=\"680\" src=\"https:\/\/wpengine.com\/wp-content\/uploads\/2017\/11\/brute-forceFINAL.png\" alt=\"multiple usernames and passwords being attempted simultaneously, indicating a brute force login attempt\" class=\"wp-image-30845\" srcset=\"https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/brute-forceFINAL.png 2009w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/brute-forceFINAL-300x102.png 300w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/brute-forceFINAL-768x260.png 768w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/brute-forceFINAL-1024x347.png 1024w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/brute-forceFINAL-303x103.png 303w, https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/brute-forceFINAL-1300x440.png 1300w\" sizes=\"auto, (max-width: 2009px) 100vw, 2009px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Brute Force Login Attempts<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">When an attacker tries to \u201cbrute force\u201d your site, this means they repeatedly try username and password combinations until they find one that works. You may think that this method would take ages to break into your site, but you\u2019d be wrong. A bot using brute force methods can try thousands of combinations in a matter of seconds. That prospect can be pretty scary to consider, but <\/span><b>don\u2019t stress.<\/b><\/p>\n\n\n\n<p><b>WP Engine blocks brute force login attempts. <\/b><span style=\"font-weight: 400\">Our system identifies when a login attempt is not coming from a real user and returns an empty response.<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Spambots<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">Bots can be tricky to track down. They are automated devices programmed to hit sites for any number of purposes. They can be invisible to you because these devices don\u2019t load JavaScript, including your Google Analytics scripts. Some bots are specifically targeted to spam sites with extra traffic. <\/span><b>Not on our watch.<\/b><\/p>\n\n\n\n<p><b>WP Engine blocks misbehaving bots.<\/b><span style=\"font-weight: 400\"> We identify and block bad behavior so you don\u2019t have to.<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Secure Backups<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">What if your site contained a vulnerability in its code and was hacked, defaced, or worse? In the event of the unthinkable, it\u2019s good to know what your options are. If you haven\u2019t been making regular backups of your site, it\u2019s too late. <\/span><b>So we do it for you.<\/b><\/p>\n\n\n\n<p><b>WP Engine makes nightly backups of your site.<\/b><span style=\"font-weight: 400\"> You can restore part or all of your site with a single click in your User Portal. Not only is this good in case of security issues, it\u2019s good practice in general. If an update or a code mistake leaves your site down, restoring to a backup is quick and easy. <\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Best Practices for Security<\/h2>\n\n\n\n<p><span style=\"font-weight: 400\">Knowing what WP Engine does to keep your site secure is a huge relief for users. But there is no single, simple answer for security. With the freedom to use your own plugins and themes also comes a great responsibility when it comes to security. Security is a partnership WP Engine shares with our customers. <\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Always Be Updating<\/h3>\n\n\n\n<p><span style=\"font-weight: 400\">By a wide margin, most security vulnerabilities are introduced by poor coding or outdated plugins and themes. As of Q3 2016, <a href=\"https:\/\/sucuri.net\/website-security\/hacked-reports\/2016-q3-hacked-website-report\" target=\"_blank\" rel=\"noreferrer noopener\">Sucuri reported<\/a> 18% of all hacked WordPress sites were a result of three primary outdated plugins: Gravity Forms, TimThumb, and RevSlider. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400\">Each of these plugins has released secure versions at least a year ago which would have prevented infection. It is important to keep on top of all WordPress plugin and theme updates to ensure your site is secure. Additionally, WordPress has a thorough <a href=\"https:\/\/wordpress.org\/documentation\/article\/hardening-wordpress\/\" target=\"_blank\" rel=\"noreferrer noopener\">hardening guide<\/a> with great information spanning security concepts as well as methods to keep your site protected. <\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Adhere to the &#8220;Least Privilege&#8221; Principle<\/h3>\n\n\n\n<p><span style=\"font-weight: 400\">The \u201cLeast Privilege\u201d principle simply states that users and code as well should only be given the access to the assets needed to perform their core function, nothing more. As a WordPress Administrator, your role is to ensure other users are only granted the access level needed to perform their role. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400\">As a WordPress Developer, your role is to ensure your code is adhering to <a href=\"https:\/\/make.wordpress.org\/core\/handbook\/best-practices\/coding-standards\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress Coding Standards<\/a> and working properly within the security confines of WordPress itself. <\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Cover All Your Bases<\/h3>\n\n\n\n<p><span style=\"font-weight: 400\">The principle of \u201c<a href=\"https:\/\/blog.sucuri.net\/2016\/10\/accounting-for-defense-in-depth-in-website-security.html\" target=\"_blank\" rel=\"noreferrer noopener\">Defense at Depth<\/a>\u201d states that the best defense strategy is to ensure protection from as many angles as possible. This concept says that the most thorough defense is a layered approach to security, rather than a one-dimensional approach. Securing your site on multiple layers is key. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400\">A multi-layered defense could look like: Securing your logins, staying on top of updates, coding according to best practices, using trusted plugins, and using monitoring, all in combination. <\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Get Your Code From Trusted Sources<\/h3>\n\n\n\n<p><span style=\"font-weight: 400\">Don\u2019t download plugins or themes from unknown sources. Downloading from the <a href=\"https:\/\/wordpress.org\/plugins\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress Plugin Repository<\/a> or other authentic sources that <a href=\"https:\/\/developer.wordpress.org\/plugins\/wordpress-org\/detailed-plugin-guidelines\/\" target=\"_blank\" rel=\"noreferrer noopener\">require the integrity and security of code<\/a> is extremely important. When you download a plugin or theme, you should also check the interval of updates. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400\">Be sure to choose plugins which are regularly maintained and updated by the author. These plugins will be more likely to release timely plugin updates should any vulnerabilities be discovered.<\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Double Down on Authentication<\/h3>\n\n\n\n<p><span style=\"font-weight: 400\">Securing entry to your site is important. While having a secure username and password combination is certainly a great step, you can take it one step further by using Two-Factor Authentication. Two-Factor Authentication means securing your site by the traditional username and password, and securing with a secondary method. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400\">For example, plugins can verify users by having them enter a temporary code sent to their verified device. Services like <a href=\"https:\/\/wordpress.org\/plugins\/miniorange-2-factor-authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Authenticator by miniOrange<\/a> offer extra security by adding this secondary authentication layer on your site. <\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Stay Aware<\/h3>\n\n\n\n<p><span style=\"font-weight: 400\">Uptime monitoring and Integrity monitoring are key ways to ensure that if your site is ever compromised, the effects are as minimal as possible. Knowing there is an issue right away enables your team to take action as quickly as possible. Uptime monitoring services like <a href=\"https:\/\/uptimerobot.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">UptimeRobot<\/a> will check to see if your site is responding properly at all times. But you may also want to maintain Integrity monitoring. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400\">Services like <a href=\"https:\/\/wordpress.org\/plugins\/stream\/\" target=\"_blank\" rel=\"noreferrer noopener\">Stream<\/a> and <a href=\"https:\/\/wordpress.org\/plugins\/sucuri-scanner\/\" target=\"_blank\" rel=\"noreferrer noopener\">Sucuri Security<\/a> are great plugins to use to track file changes and\/or WordPress Admin Dashboard activity. Last, external tools like <a href=\"https:\/\/search.google.com\/search-console\" target=\"_blank\" rel=\"noreferrer noopener\">Google Search Console<\/a> can help with reputation and health monitoring to ensure your site doesn\u2019t end up on any blacklists. Remember, you always have the ability to <a href=\"https:\/\/wpengine.com\/support\/restore\/\" target=\"_blank\" rel=\"noreferrer noopener\">restore your site<\/a> to a healthy state in one click with backups in the User Portal. <\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Secure Your WordPress Sites with WP Engine<\/h2>\n\n\n\n<p>Our global team of <a href=\"https:\/\/wpengine.com\/wordpress-hosting\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress hosting<\/a> experts are available 24\/7\/365 to help you ensure your site is as secure as possible from modern cyber threats. Check out <a href=\"https:\/\/wpengine.com\/plans\/\" target=\"_blank\" rel=\"noreferrer noopener\">our plans<\/a> or <a href=\"\/contact\/\">speak with a representative<\/a> today to find the WP Engine solution that best fits your needs!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security is a major concern for sites of all shapes and sizes. According to the University of North Georgia, a cyberattack takes place approximately every 39 seconds, and 95% of successful attacks are able to gain access to information due to human error. At WP Engine we do a lot behind the scenes to ensure<span class=\"tile__ellipses\">&hellip;<\/span><span class=\"tile__ellipses--animated\"><\/span><\/p>\n","protected":false},"author":156,"featured_media":146974,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[85],"tags":[1005,1007,1006,1008,1009],"class_list":["post-30818","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-2","tag-brute-force-attacks","tag-database-containment","tag-disk-writes","tag-file-transfer-encryption","tag-spam-bots"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How WP Engine Protects Your WordPress Security<\/title>\n<meta name=\"description\" content=\"At WP Engine, we do a lot behind the scenes to ensure your site is safe and secure to ensure site uptime and brand integrity.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How WP Engine Protects Your WordPress Security\" \/>\n<meta property=\"og:description\" content=\"At WP Engine, we do a lot behind the scenes to ensure your site is safe and secure to ensure site uptime and brand integrity.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/\" \/>\n<meta property=\"og:site_name\" content=\"WP Engine\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/wpengine\" \/>\n<meta property=\"article:published_time\" content=\"2017-11-07T22:32:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-25T16:22:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/security-11-header.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1100\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Janna Hilferty\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"How WP Engine Protects Your WordPress Security\" \/>\n<meta name=\"twitter:description\" content=\"At WP Engine, we do a lot behind the scenes to ensure your site is safe and secure to ensure site uptime and brand integrity.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/security-11-header.png\" \/>\n<meta name=\"twitter:creator\" content=\"@wpengine\" \/>\n<meta name=\"twitter:site\" content=\"@wpengine\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janna Hilferty\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/\",\"url\":\"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/\",\"name\":\"How WP Engine Protects Your WordPress Security\",\"isPartOf\":{\"@id\":\"https:\/\/wpengine.com\/case-studies\/#website\"},\"datePublished\":\"2017-11-07T22:32:11+00:00\",\"dateModified\":\"2025-11-25T16:22:19+00:00\",\"author\":{\"@id\":\"https:\/\/wpengine.com\/case-studies\/#\/schema\/person\/01ebdba350bf1adf031a63d8c0814a58\"},\"description\":\"At WP Engine, we do a lot behind the scenes to ensure your site is safe and secure to ensure site uptime and brand integrity.\",\"breadcrumb\":{\"@id\":\"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/wpengine.com\/case-studies\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"11 Top WordPress Security Concerns &amp; How WP Engine Takes Care of Them For You\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/wpengine.com\/case-studies\/#website\",\"url\":\"https:\/\/wpengine.com\/case-studies\/\",\"name\":\"WP Engine\",\"description\":\"Managed Hosting for WordPress\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/wpengine.com\/case-studies\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/wpengine.com\/case-studies\/#\/schema\/person\/01ebdba350bf1adf031a63d8c0814a58\",\"name\":\"Janna Hilferty\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/wpengine.com\/case-studies\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ecd4219dd1e2de924c1a4a45ba5cb05db66b34185e5fc175cc1df0650f6a341a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ecd4219dd1e2de924c1a4a45ba5cb05db66b34185e5fc175cc1df0650f6a341a?s=96&d=mm&r=g\",\"caption\":\"Janna Hilferty\"},\"description\":\"Janna Hilferty loves both technical and free-form writing, hiking with her dog, and painting with all the colors of the wind. In her free time you can find her blogging, smoking a cigar, or watching cheesy documentaries.\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How WP Engine Protects Your WordPress Security","description":"At WP Engine, we do a lot behind the scenes to ensure your site is safe and secure to ensure site uptime and brand integrity.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"How WP Engine Protects Your WordPress Security","og_description":"At WP Engine, we do a lot behind the scenes to ensure your site is safe and secure to ensure site uptime and brand integrity.","og_url":"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/","og_site_name":"WP Engine","article_publisher":"https:\/\/www.facebook.com\/wpengine","article_published_time":"2017-11-07T22:32:11+00:00","article_modified_time":"2025-11-25T16:22:19+00:00","og_image":[{"width":1100,"height":500,"url":"https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/security-11-header.png","type":"image\/png"}],"author":"Janna Hilferty","twitter_card":"summary_large_image","twitter_title":"How WP Engine Protects Your WordPress Security","twitter_description":"At WP Engine, we do a lot behind the scenes to ensure your site is safe and secure to ensure site uptime and brand integrity.","twitter_image":"https:\/\/wpengine.com\/case-studies\/wp-content\/uploads\/2017\/11\/security-11-header.png","twitter_creator":"@wpengine","twitter_site":"@wpengine","twitter_misc":{"Written by":"Janna Hilferty","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/","url":"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/","name":"How WP Engine Protects Your WordPress Security","isPartOf":{"@id":"https:\/\/wpengine.com\/case-studies\/#website"},"datePublished":"2017-11-07T22:32:11+00:00","dateModified":"2025-11-25T16:22:19+00:00","author":{"@id":"https:\/\/wpengine.com\/case-studies\/#\/schema\/person\/01ebdba350bf1adf031a63d8c0814a58"},"description":"At WP Engine, we do a lot behind the scenes to ensure your site is safe and secure to ensure site uptime and brand integrity.","breadcrumb":{"@id":"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/wpengine.com\/case-studies\/11-top-wordpress-security-concerns-how-wp-engine-takes-care-of-them-for-you\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wpengine.com\/case-studies\/"},{"@type":"ListItem","position":2,"name":"11 Top WordPress Security Concerns &amp; How WP Engine Takes Care of Them For You"}]},{"@type":"WebSite","@id":"https:\/\/wpengine.com\/case-studies\/#website","url":"https:\/\/wpengine.com\/case-studies\/","name":"WP Engine","description":"Managed Hosting for WordPress","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wpengine.com\/case-studies\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/wpengine.com\/case-studies\/#\/schema\/person\/01ebdba350bf1adf031a63d8c0814a58","name":"Janna Hilferty","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/wpengine.com\/case-studies\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/ecd4219dd1e2de924c1a4a45ba5cb05db66b34185e5fc175cc1df0650f6a341a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ecd4219dd1e2de924c1a4a45ba5cb05db66b34185e5fc175cc1df0650f6a341a?s=96&d=mm&r=g","caption":"Janna Hilferty"},"description":"Janna Hilferty loves both technical and free-form writing, hiking with her dog, and painting with all the colors of the wind. In her free time you can find her blogging, smoking a cigar, or watching cheesy documentaries."}]}},"acf":[],"_links":{"self":[{"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/posts\/30818","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/users\/156"}],"replies":[{"embeddable":true,"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/comments?post=30818"}],"version-history":[{"count":0,"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/posts\/30818\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/media\/146974"}],"wp:attachment":[{"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/media?parent=30818"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/categories?post=30818"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpengine.com\/case-studies\/wp-json\/wp\/v2\/tags?post=30818"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}