Last week, Cloudflare announced in a blog post that it was implementing a new feature – allowing URL rewrites on the EDGE. This is pretty cool. But the post hid another change that I feel is more directly relevant to website owners, and those concerned about website security. Namely URL Normalization. Here’s why that’s important. […]
Category: Website Security
Why I Don’t Use Two Factor Authentication
This is going to be a controversial opinion. I’ve written a lot about website security on NameHero, and best practices for both shared and VPS hosting. So you might think that one of the first things I do is to enable two-factor authentication or 2FA wherever I can. NameHero itself offers the ability to enable […]
Filtering Out “replytocom” Bots On WordPress
I’m always monitoring my traffic to see which requests are causing the most impact on my origin server. I’ve already shown how to protect your WordPress login page using firewall rules and the challenges of rate-limiting. But you need to be on a constant lookout to see what new vulnerabilities are being exploited. If you […]
The Challenges Of Rate Limiting For Websites
I got up today and saw this traffic spike for my site: Sometime this morning, my server was suddenly hit with a flood of demands that bypassed Cloudflare’s cache and hit my server at WP-Tweaks.com directly. Given that I cache all my pages, I was naturally curious to see what this spike was and whether […]
Tips To Securely Access Your Site from Anywhere
The number of things to think about when setting up your website is tremendous. Many of them are contingent plans that won’t bear fruit immediately but might save your hide later down the line. Backup is one such example. Others will silently protect your site in the background, and you’ll never even notice how much […]
Paid SSL Is Simply Not Worth It Anymore
The developments since 2018 have dealt the death-knell for pretty much all paid SSL certificates. First the big news towards the end of 2018 that Google would be giving some (small) weightage to HTTPS websites in their search rankings. The second piece of news was from mid-2020, when Google and Apple decided to limit the […]
How Spam And Bots Can Kill Your Site
When I first started hosting on a relatively low-cost server, there came a point when my site suddenly slowed down. It became pretty bad. When I contacted my host, they suggested I upgrade to the next highest tier because I’d outgrown my existing plan. But I wasn’t yet convinced, because my traffic hadn’t suddenly increased […]
How to Have an Offsite Backup: Part 1
Offsite backups are important. Even though NameHero is one of the few hosting providers to allow free automatic and manual backups and restores, these are all still stored on the same servers and networks that host your website. They protect you if something goes wrong with your site, but not from a systemic system-wide outage. […]
3 Methods For Additional WordPress Security
As your site becomes more popular, the stakes get higher and higher. You find yourself thinking of more ways to secure your site. Now of course, you can do what everyone else does – plugins to defend against login attempts, strong passwords, and even 2FA. But in this article, I’m going to discuss three additional […]
How To Generate An AutoSSL In cPanel With NameHero
Way back towards the end of 2016, we at NameHero decided to offer free SSL certifications via a partnership with Let’s Encrypt. This was at least two years before Google pressured the rest of the web hosting industry into switching to HTTPS for hosting reasons. Like so many other things, NameHero was there well before […]
