{"id":10972,"date":"2023-08-24T11:11:31","date_gmt":"2023-08-24T15:11:31","guid":{"rendered":"https:\/\/membermouse.com\/?p=10972"},"modified":"2025-06-06T19:38:23","modified_gmt":"2025-06-06T23:38:23","slug":"seguranca-do-site-de-associacao-wordpress","status":"publish","type":"post","link":"https:\/\/membermouse.com\/pt\/estrategias\/seguranca-do-site-de-associacao-wordpress\/","title":{"rendered":"Membership Site Security: How To Keep Your Site Safe & Secure"},"content":{"rendered":"<!-- wp:paragraph -->\n<p>The security of your website is of the utmost importance for two main reasons: the investment you\u2019ve put into your website and the privacy of the people who use your site. All sites on the internet are at risk and require specific steps to keep up with security and compliance. This is especially true for websites that house <a href=\"https:\/\/gdpr-info.eu\/issues\/personal-data\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">user data<\/a> like membership or eCommerce sites.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>If your website gets hacked, all of your users\u2019 data would be in danger. This data is your responsibility to protect and you can carry liabilities to those users. The hacked site could be used to cause damage to visitors\u2019 computers or used to bulk send spam messages. This would hurt your users directly and tarnish the reputation of your business. Perhaps worst of all, not being compliant (or getting hacked) can have your site de-indexed from the web search engines and <a href=\"https:\/\/sendgrid.com\/blog\/avoiding-email-blacklists\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">blacklisted from sending email<\/a>.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Yikes. Let's try and avoid that, shall we?<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>While it\u2019s nearly impossible to make your site 100% secure, we will do our best to show you some of the essentials to secure your site and keep up with modern compliance requirements. Managing security and compliance is a major part of a site build. If you or your team is unable to attend to the needs of security, you should consider hiring a professional to help get you compliant and safe.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:image {\"id\":15867} -->\n<figure class=\"wp-block-image\"><img src=\"https:\/\/storage.googleapis.com\/wpgcbucket\/wp\/2023\/08\/0dc26f0d-wordpress-membership-site-security.jpg\" alt=\"wordpress membership site security\" class=\"wp-image-15867\"\/><\/figure>\n<!-- \/wp:image -->\n\n<!-- wp:paragraph -->\n<p><\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":3} -->\n<h3 class=\"wp-block-heading\"><strong>An Overview of MemberMouse\u2019s Core Security Features<\/strong><\/h3>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>MemberMouse uses the latest standards and security protocols for passwords, licensing, and payment transactions. We also strive to integrate with any new releases of improved security features. Neither your MemberMouse website \u2013 nor our servers \u2013 will ever store your customers' payment details. Instead, that information is stored on your payment processor's servers.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Out-of-the-box, MemberMouse comes with several options to enhance the security of your website:<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:quote -->\n<blockquote class=\"wp-block-quote\"><!-- wp:heading {\"level\":4} -->\n<h4 class=\"wp-block-heading\"><strong>How MemberMouse Handles Security<\/strong><\/h4>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> <a href=\"https:\/\/membermouse.com\/docs\/account-sharing-protection\/\" target=\"_blank\" rel=\"noopener noreferrer\">Account Sharing Protection<\/a> allows you to limit the number of IP addresses that can access an account over a 24-hour period.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> <a href=\"https:\/\/membermouse.com\/docs\/configuring-stripe\/\" target=\"_blank\" rel=\"noopener noreferrer\">Stripe Elements<\/a> integration: The latest in <a href=\"https:\/\/membermouse.com\/docs\/activating-the-3d-secure-checkout-process-for-strong-customer-authentication-sca\/\" target=\"_blank\" rel=\"noopener noreferrer\">3D Secure checkout security<\/a> technology from Stripe. This carries the highest level of PCI compliance and is <a href=\"https:\/\/membermouse.com\/docs\/strong-customer-authentication-sca-compliance\/\" target=\"_blank\" rel=\"noopener noreferrer\">SCA-ready<\/a>. 3D Secure checkout is mandatory for customers in the European Economic Area (EEA) in order to be compliant. Credit card and billing information is sent directly to Stripe and never touches your servers.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> <a href=\"https:\/\/membermouse.com\/docs\/whats-the-difference-between-authorize-net-authorize-net-arb-and-authorize-net-cim\/\" target=\"_blank\" rel=\"noopener noreferrer\">Authorize.net CIM<\/a> integration: This will enable the customer information manager that stores customer details on the Authorize.Net servers. Additionally, the Accept.js token exchange has been incorporated into our Authorize.net CIM integration, so credit card and billing information is sent directly to Authorize.net and never touches your servers.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> <a href=\"https:\/\/membermouse.com\/docs\/configuring-braintree\/\" target=\"_blank\" rel=\"noopener noreferrer\">Braintree<\/a> integration: This includes 3D Secure checkout process using Hosted Fields \/ 3D Secure 2.0. and carries the highest of PCI compliance and is SCA-ready. 3D Secure checkout is mandatory for customers in the European Economic Area (EEA) in order to be compliant. Credit card and billing information is sent directly to Braintree and never touches your servers.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> <a href=\"https:\/\/membermouse.com\/docs\/using-limit-login-attempts-plugin\/\" target=\"_blank\" rel=\"noopener noreferrer\">Limit Login Attempts<\/a> plugin integration: By default WordPress allows unlimited login attempts. We have set up an integration with the plugin Limit Login Attempts that will allow you to configure your site to block an internet address from making further attempts after a specified limit on retries is reached, making a brute-force attack difficult or impossible.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":4} -->\n<h4 class=\"wp-block-heading\"><strong>Going One Step Deeper<\/strong><\/h4>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> When creating a user or doing a password reset, MemberMouse forces a minimum password strength requirement of 8 characters. MemberMouse also supports the addition of a <a href=\"https:\/\/membermouse.com\/docs\/membermouse-wordpress-filters\/\" target=\"_blank\" rel=\"noopener noreferrer\">custom filter<\/a> that allows the password to be evaluated based on custom requirements that you can define.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> Checkout can be configured to use <a href=\"https:\/\/membermouse.com\/docs\/configuring-recaptcha-v3\/\" target=\"_blank\" rel=\"noopener noreferrer\">V3 of Google ReCaptcha<\/a> which is the latest version of an invisible system that minimizes bot signups and scammers.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> <a href=\"https:\/\/membermouse.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">MemberMouse.com<\/a> does not store, nor have access to any of your user\u2019s data nor credit card information.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> Our platform is GDPR compliant and has <a href=\"https:\/\/membermouse.com\/docs\/how-can-membermouse-help-with-gdpr-compliance\/\" target=\"_blank\" rel=\"noopener noreferrer\">features to manage GDPR requests<\/a>.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> MemberMouse makes use of the standard WordPress password functionality, so you know you will always have the latest and greatest features within password storage and management.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-check-circle-o\"><\/i> MemberMouse is regularly updated and is compatible with the latest PHP versions.<\/p>\n<!-- \/wp:paragraph --><\/blockquote>\n<!-- \/wp:quote -->\n\n<!-- wp:image {\"id\":10991} -->\n<figure class=\"wp-block-image\"><img src=\"https:\/\/storage.googleapis.com\/wpgcbucket\/wp\/2021\/07\/47000aed-wordpress-security.png\" alt=\"wordpress security\" class=\"wp-image-10991\"\/><\/figure>\n<!-- \/wp:image -->\n\n<!-- wp:paragraph -->\n<p><\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":3} -->\n<h3 class=\"wp-block-heading\"><strong>The ABC\u2019s of Web Hosting Security<\/strong><\/h3>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>Most modern hosting has the basics required to keep your server secure with tools like <a href=\"https:\/\/en.wikipedia.org\/wiki\/ModSecurity\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Modsecurity or (WAF) web application firewalls<\/a>. That being said, you should never use cheap hosting \u2013 or low-level reseller hosting \u2013 because they may not have protocols in place to keep your server secured, or the ability to attend to emergency requests you may have.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Considering that your host should already have common protocols and modules to keep your server safe, much of the security responsibilities of your server fall on you. Unfortunately, it\u2019s common for many site owners to not consider the potential dangers involved when setting up their hosting package. To put that into perspective, poor hosting management is responsible for 41% of most hacks. To help keep your server secure, here are some common things which get overlooked that you can attend to stay safe:<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:quote -->\n<blockquote class=\"wp-block-quote\"><!-- wp:heading {\"level\":4} -->\n<h4 class=\"wp-block-heading\"><strong>How To Keep Your Site Safe<\/strong><\/h4>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Use a <a href=\"https:\/\/wordpress.org\/support\/article\/password-best-practices\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">strong password protocol<\/a> to log into your hosting plan with a mix of letters, numbers, and characters. Never use words that can be found in the dictionary.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Remove any FTP accounts while they are not in use. Many hosts allow FTP to be closed when not in use. Again, use strong password protocols when setting this up.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> All email accounts that are associated with the website, or are on the server should have strong password protocols. If these accounts get hacked, they can be used to access the site and cause damage, plus they can be used in spam email sending.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Check your file manager regularly for irregularities. Often backups or database files are located in the public_html making them publicly available. These backups can be downloaded easily and all your secure site information is within them, including database access and admin passwords. Keep your file system tidy and only store the necessary files required to make your site function.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":4} -->\n<h4 class=\"wp-block-heading\"><strong>Additional Tips<\/strong><\/h4>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Often check to be sure file and folder permissions are properly set. Files, including your .htaccess file and wp-config file, should be 644 while your folders should be 755. Files can get adjusted to the wrong permission when certain actions take place in your WordPress admin panel, so regularly checking them is important.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Be sure your server creates regular backups which you can access. Do not rely on plugins to handle backups as they are not reliable and often do not work with MemberMouse.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Do yearly audits of your server software to be sure you are using the latest compatible versions of PHP.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Never log into your server if you think your personal computer is compromised. You should be using compatible security software on any computer which you use to access your server and website. This is a very common method your site or server could get hacked.<\/p>\n<!-- \/wp:paragraph --><\/blockquote>\n<!-- \/wp:quote -->\n\n<!-- wp:paragraph -->\n<p>For further advice on choosing a hosting provider as well as minimum requirements for running MemberMouse, you can review our article on <a href=\"https:\/\/membermouse.com\/membership\/wordpress-membership-site-hosting\/\" target=\"_blank\" rel=\"noopener noreferrer\">WordPress Hosting Providers<\/a>.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:image {\"id\":10993} -->\n<figure class=\"wp-block-image\"><img src=\"https:\/\/storage.googleapis.com\/wpgcbucket\/wp\/2021\/07\/eac9e646-membership-site-security.png\" alt=\"membership site security\" class=\"wp-image-10993\"\/><\/figure>\n<!-- \/wp:image -->\n\n<!-- wp:paragraph -->\n<p><\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":3} -->\n<h3 class=\"wp-block-heading\"><strong>A Few Things You Should Know About WordPress Security<\/strong><\/h3>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>The WordPress Codex has a massive article on <a href=\"https:\/\/wordpress.org\/support\/article\/hardening-wordpress\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Hardening WordPress<\/a> that discusses vulnerabilities, setting secure file permissions, securing database and admin panel access, and more. This article is a must-read for any website owner who wants to learn more about the security required for your website. Most all of the recommendations are easy to accomplish and can seriously improve the health and security of your investment.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>The most important steps you can take to help protect your WordPress are:<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:quote -->\n<blockquote class=\"wp-block-quote\"><!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Passwords: Require all admin accounts to use a <a href=\"https:\/\/wordpress.org\/support\/article\/password-best-practices\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">strong password protocol<\/a>. Consider using <a href=\"https:\/\/wordpress.org\/support\/article\/two-step-authentication\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">2 Step Authorization<\/a> to prevent access to these accounts. A hacker who gains access to your administrator account is able to install malicious scripts that can potentially compromise your entire server, have your website banned from search engines, and destroy your website and its user\u2019s private data.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>The email account associated with the admin account should also have strong passwords and 2 Step Authorization because they can be used to easily access your WordPress installation.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Updates: 83% of websites that get hacked are not updated properly. It is the single most important step you can do to secure your website. Never let updates get behind by activating <a href=\"https:\/\/wordpress.org\/support\/article\/configuring-automatic-background-updates\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Automatic Updates<\/a> which is a feature built into WordPress.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Tidiness: Remove unused plugins and themes. You want to keep one default WordPress theme aside from your primary theme, but any unused plugins should be removed unless you plan to re-enable it soon.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":4} -->\n<h4 class=\"wp-block-heading\"><strong>Side Note<\/strong><\/h4>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>Heavily evaluate if you need a plugin. Less is better when it comes to plugin count and only install plugins that are regularly updated and come from a reputable seller.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>After migration plugins, database plugins, or file editing plugins are used, they should be removed promptly. Unauthorized access to these plugins can spell disaster as they provide a simple path to the needed areas a hacker requires.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-arrow-circle-o-right\"><\/i> Access: Always work on your site and server from a trusted network. Avoid cafe internet or public WIFI at all costs.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Use a <a href=\"https:\/\/www.wpbeginner.com\/plugins\/how-and-why-you-should-limit-login-attempts-in-your-wordpress\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Limit Login plugin<\/a> to limit unusual login attempts. It is very common to have your website login attacked on a daily basis. Sometimes thousands of times per day, so using a login plugin will block bad attempts at logins and prevent them from continually attempting access.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Remove unused admin accounts within WordPress.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><a href=\"https:\/\/www.wpbeginner.com\/wp-tutorials\/how-to-disable-theme-and-plugin-editors-from-wordpress-admin-panel\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Disable Theme and Plugin Editors from WordPress Admin Panel<\/a> to prevent file edits when your site is accessed without authority.<\/p>\n<!-- \/wp:paragraph --><\/blockquote>\n<!-- \/wp:quote -->\n\n<!-- wp:image {\"id\":15866} -->\n<figure class=\"wp-block-image\"><img src=\"https:\/\/storage.googleapis.com\/wpgcbucket\/wp\/2023\/08\/019d66bb-ssl-https-membership-site-security.jpg\" alt=\"ssl https pci membership site security\" class=\"wp-image-15866\"\/><\/figure>\n<!-- \/wp:image -->\n\n<!-- wp:paragraph -->\n<p><\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":3} -->\n<h3 class=\"wp-block-heading\"><strong>All About Acronyms: SSL, HTTPS, &amp; PCI Compliance<\/strong><\/h3>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>All websites, whether they take payments or not, should use an SSL and be secured with HTTPS. Login data, as well as the transference of information to your users, should be secured for everyone\u2019s protection.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>The <a href=\"https:\/\/www.pcisecuritystandards.org\/pci_security\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Payment Card Industry Data Security Standard<\/a> (PCI DSS) is a set of requirements intended to ensure that all companies that process, store, or transmit credit card information maintain a secure environment. This not only means that it is required by law to have a properly installed SSL on your site if you have a store or a membership site, but it also means that you need to go to greater lengths to secure your website and this article covers many of those steps you can take.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>If you would like to learn how to install an SSL to your site, we have a <a href=\"https:\/\/membermouse.com\/docs\/securing-your-site-with-https\/\" target=\"_blank\" rel=\"noopener noreferrer\">detailed article here<\/a> with directions on how to install one on your site.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Just having an SSL certificate and using HTTPS doesn't necessarily mean that you will be fully PCI compliant. The requirements vary based on your business type, technical setup, and\/or volume. If you have PCI compliance concerns, it is best to speak with your payment processor or a PCI-DSS expert. <a href=\"http:\/\/tomkconsulting.com\/news049-PCI-Overview.htm\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">This article is a good primer<\/a> on the subject and can help you understand what, if any, additional steps you'll need to take.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>These PCI FAQ guides are also succinct and helpful:<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-long-arrow-right\"><\/i> <a href=\"https:\/\/www.pcicomplianceguide.org\/faq\/#4\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">What are the PCI compliance \u2018levels\u2019 and how are they determined?<\/a><\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-long-arrow-right\"><\/i> <a href=\"https:\/\/www.pcicomplianceguide.org\/pci-saq-3-1-e-commerce-options-explained\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">PCI SAQ 3.1: E-Commerce Options Explained<\/a><\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":3} -->\n<h3 class=\"wp-block-heading\"><strong>Don\u2019t Forget About Domain &amp; DNS Security<\/strong><\/h3>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>Securing the account your domain is listed on (such as Godaddy, Namecheap, etc) should be protected using strong password protocols and when possible, 2 Stage Login. If unauthorized access is gained to your domain\u2019s DNS settings, a website can be changed or hijacked, and potentially the domain can be stolen. A yearly audit on your domain\u2019s account to be sure all contact information associated with the domain is up to date and accurate is good protection and it can help with maintaining ownership.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>DNS security is less often considered, but steep consequences can occur if your DNS is hijacked. These attacks can redirect a website\u2019s inbound traffic to a fake copy of the site, collecting sensitive user information and exposing businesses to major liability. One of the best-known ways to <a href=\"https:\/\/www.cloudflare.com\/learning\/dns\/dns-security\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">protect against DNS threats is to adopt the DNSSEC protocol<\/a>.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Many options are available for DNS protection, but <a href=\"https:\/\/www.cloudflare.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Cloudflare<\/a> is a great option as it will not only protect your DNS, but it can protect your site from bots and allow all your server resources to go to real users instead of attacking bots. The huge variety of options they offer are excellent for protecting your website and have a variety of pricing plans, including free.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:image {\"id\":10994} -->\n<figure class=\"wp-block-image\"><img src=\"https:\/\/storage.googleapis.com\/wpgcbucket\/wp\/2021\/07\/e496ee17-security-for-membership-sites.png\" alt=\"security for membership sites\" class=\"wp-image-10994\"\/><\/figure>\n<!-- \/wp:image -->\n\n<!-- wp:paragraph -->\n<p><\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":3} -->\n<h3 class=\"wp-block-heading\"><strong>Wrapping Up<\/strong><\/h3>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>Passwords and updates are the foundation of security and are so often overlooked or their importance ignored. Often people think their password is strong when in actuality, it\u2019s probably been leaked on the dark web hundreds of times and has no security at all. Try and get in the habit of regularly updating your passwords everywhere and using a <a href=\"https:\/\/cybernews.com\/best-password-managers\/\" target=\"_blank\" rel=\"noopener noreferrer\" title=\"reliable password manager\">reliable password manager<\/a>.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Attend to website software updates as timely as possible. Not only will this help keep you secure, but it often resolves problems you may be having with your software or plugins.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>If you do have an unfortunate run-in with a hack, use a reliable professional to resolve the hack, and never rely on a simple plugin to protect you or \u201cfix\u201d the issue. Aside from removing the malware, and preventing its return, many steps can be involved to repair these situations, including the need for documentation of the resolution to wipe out blacklisting on search engines and email providers.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>You may also have a legal liability to inform your site members of the breach and having a professional to assist with the tedious project of notifying your member base, required jargon and what was breached will prove invaluable.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Simply educating yourself on the importance of security is also a great starting point. Below we include references to data points used in this article, as well as other great resources for learning about security.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":4} -->\n<h4 class=\"wp-block-heading\"><strong>Additional Resources:<\/strong><\/h4>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p><i class=\"fa fa-long-arrow-right\"><\/i> <a href=\"https:\/\/blog.sucuri.net\/2021\/03\/how-do-websites-get-hacked.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">How Do Websites Get Hacked?<\/a><br><i class=\"fa fa-long-arrow-right\"><\/i> <a href=\"https:\/\/yourescapefrom9to5.com\/wordpress-security-infographic\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">How to Improve WordPress Security [Infographic]<\/a><br><i class=\"fa fa-long-arrow-right\"><\/i> <a href=\"https:\/\/wordpress.org\/support\/article\/hardening-wordpress\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Hardening WordPress<\/a><br><i class=\"fa fa-long-arrow-right\"><\/i> <a href=\"https:\/\/wordpress.org\/support\/article\/two-step-authentication\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Two-Step Authentication<\/a><br><i class=\"fa fa-long-arrow-right\"><\/i> <a href=\"https:\/\/wordpress.org\/support\/article\/configuring-automatic-background-updates\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Configuring Automatic Background Updates<\/a><br><i class=\"fa fa-long-arrow-right\"><\/i> <a href=\"https:\/\/wordpress.org\/support\/article\/password-best-practices\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Password Best Practices<\/a><br><i class=\"fa fa-long-arrow-right\"><\/i> <a href=\"https:\/\/wordpress.org\/plugins\/tags\/security\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">WordPress Repository - Plugins Tagged Security<\/a><\/p>\n<!-- \/wp:paragraph -->","protected":false},"excerpt":{"rendered":"<p>Neste artigo, voc\u00ea descobrir\u00e1 nossas principais dicas para manter seu site de associa\u00e7\u00e3o do WordPress seguro e protegido. Al\u00e9m disso, voc\u00ea saber\u00e1 por que isso \u00e9 t\u00e3o importante em primeiro lugar.<\/p>","protected":false},"author":18927,"featured_media":10990,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"_strive_editorial_status":"complete","_strive_copy_of":0,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_strive_checklists":"\"\"","_strive_active_checklist":"64949637c1a53","_strive_post_notes":"","footnotes":""},"categories":[117,35],"tags":[],"class_list":["post-10972","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mm-dash","category-strategies"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/posts\/10972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/users\/18927"}],"replies":[{"embeddable":true,"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/comments?post=10972"}],"version-history":[{"count":3,"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/posts\/10972\/revisions"}],"predecessor-version":[{"id":21187,"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/posts\/10972\/revisions\/21187"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/media\/10990"}],"wp:attachment":[{"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/media?parent=10972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/categories?post=10972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/membermouse.com\/pt\/wp-json\/wp\/v2\/tags?post=10972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}