As I shared the other day, while I was out of the country, some of my sites got hacked which made for a rather labor intensive Thanksgiving. Once I got things on the sites all cleaned up and restored back to normal, I began looking to see what might have been the place they got into my sites. With the help of Sucuri, (affiliate) we found that one of the vulnerabilities of my site was through TimThumb.
What I had found is that some of the plugins/themes on sites that I had were using versions of timthumb that were out of date. Unfortunately, one of the down sides to using free plugins/themes is that sometimes the developer does not keep things up to date for compatibility and security. Just like for all of us, sometimes life gets in the way, or a new direction opens and other things get left behind.
So, I went on a search to see what was the easiest way to scan everything on your site & find a way to update. I came across a great plugin called Timthumb Vulnerability Scanner that does a great job of scanning & updating. Here’s a quick video showing you just how easy it is:
So, keep your Custom WordPress Site safer and use this plugin to accomplish it! Also, make sure you are are backing up your WordPress site on a regular basis. If you do not know how, or want someone to handle it for you, you can always check out the WordPress backup service I offer.
Steven Stern
There’s a lot more than timthumb to scan for. Check out the WordFence plugin and every now and again, scan your site externally from sucuri.net.
Jeremy Blanton
Good stuff Steven. Yes, those are two other great steps to use to keep your site safe & secure.
Jeremy
Patrick Healy
I think Wordfence scans for timthumb as well.
Jeremy Blanton
I am not sure it does Patrick. I’ve got it installed on a few sites and it didn’t pick it up. This one will also update the timthumb to the most recent versions for you as well.
Patrick Healy
That’s what someone over at WordFence told me directly in an email when I was considering upgrading to Pro. Perhaps it was a sales tactic but I don’t think it was.
Jeremy Blanton
Maybe in the pro version it is an option Patrick. I haven’t used that one yet.
Patrick Healy
Perhaps.
Jeremy Blanton
http://realindianews.com/vsunmgt.php
Jeremy Blanton
http://realindianews.com/vsunmgt.php
Jeremy Blanton
http://realindianews.com/vsunmgt.php