Got a WordPress website? These are my top 3 ‘must have’ WordPress plugins that I make sure I install on every site I build. All 3 plugins have free versions which are adequate for 99% of my clients.
Wordfence is my favourite security plugin.
Wordfence is an Endpoint firewall. It runs at the endpoint – your server. Unlike cloud firewalls, it doesn’t break encryption, cannot be bypassed and cannot leak data.
Its Malware scanner blocks requests that include malicious code or content. It protects your site from brute force attacks by limiting login attempts, enforcing strong passwords and a range of other login security measures.
The Security Scanner checks WordPress core files, themes and plugins for malware, bad URLs, backdoors, SEO spam, malicious redirects and code injections. It compares your files with what is in the WordPress.org repository and reports any changes to you. You can repair files that have been changed with clean, original version and you can easily delete any files that don’t belong. It Also checks for known security vulnerabilities and abandoned plugins that may be putting your site at risk and checks your website content to make sure there’s no dangerous URLs or suspicious content.
The threat defense feed arms your site with the newest firewall rules, malware signatures and malicious IP addresses it needs to keep your site safe
Wordfence protects over 2 million WordPress websites which gives them unmatched access to information about how hackers compromise sites, where attacks originate from and the malicious code they leave behind.
It has leaked password protection, which blocks login attempts for admins using known compromised passwords.
You can monitor live visits and hack attempts in real time including their origin, ip address and time of day.
It has Advanced manual blocking. You can block entire networks or any human or robot activity that looks suspicious based on pattern matching and ip ranges.
In the last 30 days, Wordfence blocked 3, 393, 031, 957 attacks, and over 196,000 malicious IP addresses were blacklisted.
2. Updraft Plus
For backing up your WordPress website.
Your website can become corrupted by server crashes, hacking or plugin updates. It’s Important to always have a backup you can restore in case the unthinkable happens.
Updraft Plus is trusted by over 2 million WordPress websites including Microsoft, NBA, NASA, Proctor & Gamble.
- It’s easy to use. You can backup and restore with a single click on a schedule that suits you.
- Tested in more scenarios, installed on more servers and rated higher than other plugins
- Complete, general purpose backup and restore with more features than other plugins.
- Backup to remote locations like dropbox, google drive, one drive or send the backup via ftp or email.
- Can also clone and restore to move whole websites to another server.
- Can do Incremental backups to only backup changes made since the last backup.
- Fast, personal support
- You can choose to do Pre- update backups which backup your site before performing any wordpress, theme or plugin updates
- You can Backup non WordPress files
- Backup Network/multisites
- Set exact backup times to create, retain or delete backups
- Encrypt sensitive databases
- Send backup Reports by email
- Importer – restore backups from other plugins
- Lock access to UpdraftPlus via password
3. Yoast SEO
Improve your site’s SEO!
- Get more visitors from Google and Bing
- Attract more visitors from social media
- Increase your reader’s engagement
- Super Easy to setup – no need to hire an expert
- Allows you to enter a keyword or keyphrase for each page
- Preview your page in google
- Checks readability of your page
- Takes care of the technical stuff in the background. No need to worry about robots.txt or .htaccess files, permalink urls or sitemaps…Yoast rolls out the red carpet for search engines
- Always updated for Google’s algorithm