{"id":156860,"date":"2016-06-24T14:00:12","date_gmt":"2016-06-24T14:00:12","guid":{"rendered":"https:\/\/premium.wpmudev.org\/blog\/?p=156860"},"modified":"2016-06-23T06:13:57","modified_gmt":"2016-06-23T06:13:57","slug":"privacy-tips","status":"publish","type":"post","link":"https:\/\/wpmu-dev.pro\/blog\/privacy-tips\/","title":{"rendered":"Privacy Checklist: 10 Tips for Protecting Visitors to Your WordPress Site"},"content":{"rendered":"<p>Businesses of all sizes\u2014bloggers, SMBs, eCommerce companies, large enterprises, and more\u2014understand the importance of having a website. Without it, a business is relegated to the more time \u2013 and labor \u2013 intensive (and not to mention outdated) method of increasing brand recognition and converting leads through cold calling and word-of-mouth.<\/p>\n<p>Plus, if your brand doesn\u2019t have a website, you\u2019re relying on customer reviews on sites like Yelp, Glassdoor, social media, and others to dictate how consumers should feel about you.<\/p>\n<p>You don\u2019t want to do that.<\/p>\n<p>A website is an essential part of every business\u2019s identity. And like any part of your business that speaks directly to your audience, you want to make sure it offers a safe, reliable, and professional experience. Your site is an extension of who you are as a brand, a company, and a service provider, so it\u2019s important to have full control over your online identity.<\/p>\n<p>Website design, functionality, and mobile responsiveness are all important in helping brands establish credibility with their audience. However, without the proper security measures in place to begin with, all that effort you spend in setting up a great looking website may be for naught. If your site gets taken down, if a lapse in security leads to stolen customer information, or if your site becomes an attack vehicle for hackers, the effort you put into design and development won\u2019t matter anymore\u2014especially to visitors who had grown to trust you.<\/p>\n<h3>For the Web Is Dark and Full of Terrors&#8230;<\/h3>\n<p>The\u00a0<a href=\"https:\/\/wordpress.org\/about\/security\/\" rel=\"noopener\" target=\"_blank\">WordPress security team<\/a>\u00a0goes to great lengths to ensure they\u2019re providing a safe and secure CMS for customers to build and manage websites from. The team includes security experts who are quick to act when there are potential security risks in the WordPress core software\u00a0or third-party tools like plugins and themes. You also may have noticed they will occasionally release updates to patch up system fragilities. However, that doesn\u2019t mean the platform is 100% free of risk.<\/p>\n<p>Due to the popularity of third-party tools used in tandem with WordPress, the CMS is not always as secure as they\u2019d like it to be. That\u2019s no reason to start distrusting third-party plugins, themes, or software providers, however. It simply means you should be taking measures to ensure that if WordPress\u2019s team misses a potential security risk, that you\u2019ve got tools in place to monitor and protect your website and its visitors.<\/p>\n<h4>So Who Is at Risk?<\/h4>\n<p>Some of you may be thinking, \u201cWell, I\u2019m a [small business owner\/independent blogger\/freelancer\/etc.] with a relatively small audience. I\u2019m not going to get hacked.\u201d<\/p>\n<p>The truth is, hackers don\u2019t care who you are. If they spot a weakness in your website\u2019s setup, they will attack and put your business at risk. Even if your website doesn\u2019t collect (or store) payment, login, or other personal information, hackers will find a way to make your website work for their own purposes.<\/p>\n<p>So who really is at risk here? The answer: <em>Everyone.<\/em><\/p>\n<p>To clarify, \u201ceveryone\u201d not only refers to your brand or business; \u201ceveryone\u201d refers to any person who has visited your website. As you\u2019ll see soon enough, attacks on websites aren\u2019t always done for the purpose of destroying a business\u2019s reputation (though that is pretty much a guaranteed end result regardless). Hackers often take advantage of site vulnerabilities in order to gain access to customer data they wouldn\u2019t otherwise be able to retrieve on their own.<\/p>\n<p>It\u2019s important to remember the following:<\/p>\n<ul>\n<li>Don\u2019t think you\u2019re immune to an attack because of your business\u2019s size or level of visibility.<\/li>\n<li>Make sure you\u2019re aware of the potential risks.<\/li>\n<li>With the right monitoring and management tools and process in place, you can recover your website from a hacking attempt. Your customers\u2019 information may not be so lucky, so guard it well (i.e. not on your site).<\/li>\n<\/ul>\n<h4>WordPress Website Risks<\/h4>\n<p>In a recent <a href=\"https:\/\/www.wordfence.com\/blog\/2016\/04\/hackers-compromised-wordpress-sites\/\" rel=\"noopener\" target=\"_blank\">Wordfence survey<\/a>, WordPress users were polled to find out what sort of attacks they\u2019ve experienced on their website. Here is a summary of those results, ranked by the most common attack type:<\/p>\n<p><b>Site Defacement (~25%)<\/b><\/p>\n<p><em>What happens?<\/em> Attackers either replace your website with their own content or they take down your website completely. Hackers don\u2019t need a reason to do this other than to make a statement.<\/p>\n<p><b>Email Hacking (~20%)<\/b><\/p>\n<p><em>What happens?<\/em> Attackers take control of your email and use it to send out spam. There may be a number of reasons why a hacker would do this; among them: to use your email server for free, to destroy your business\u2019s reputation, or to send out malicious links and content on behalf of a source people trust (that being yours).<\/p>\n<p><b>SEO Improvement (~18%)<\/b><\/p>\n<p><em>What happens?<\/em> Hackers will plant their own links and content within your site in order to improve their own website\u2019s SEO. While search ranking criteria can change based on trends in how people use the web (eg. mobile device adoption, social media for search, etc.), one thing will stay the same: when a reputable source links to a website or content, that website will then be seen as a trusted source too.<\/p>\n<p><b>Redirects (~15%)<\/b><\/p>\n<p><em>What happens?<\/em> Hackers will use your trusted source as a way to automatically funnel new, unsuspecting traffic to their site. So when someone tries to visit your website, they are instead taken to the attackers\u2019 website containing malicious content.<\/p>\n<p><b>Page Impersonators (~5%)<\/b><\/p>\n<p><em>What happens?<\/em> Attackers create what are known as phishing pages that look like valid forms. They\u2019ll create these impersonator pages to lure site visitors into giving them personal information.<\/p>\n<p><b>Malware Distribution (~3%)<\/b><\/p>\n<p><em>What happens?<\/em> Attackers gain access to your website and then distribute malware to all of your visitors\u2019 computers in order to retrieve their personal information.<\/p>\n<p><b>Information Jacking (~20%)<\/b><\/p>\n<p><em>What happens?<\/em> If you store sensitive customer information on your website (payment information, logins, personal information, and more), attackers only need to gain access to your site in order to steal it.<\/p>\n<p><b>Attack Launchpad (~2%)<\/b><\/p>\n<p><em>What happens?<\/em> Again, by leveraging your website as a trusted source, attackers can use your server to gain access to and attack other websites.<\/p>\n<p><b>Ransomware (~2%)<\/b><\/p>\n<p><em>What happens?<\/em> Just as the name implies, ransomware is a form of software attackers will implant on your website so you can no longer gain access. Their hope is that you won\u2019t have a backup or another way to get back in, and will in turn be willing to pay a \u201cransom\u201d for it.<\/p>\n<p><b>Content Host (~1%)<\/b><\/p>\n<p><em>What happens?<\/em> Attackers gain access to your server in order to host their own malicious files there.<\/p>\n<p><b>Referral Spam (~1%)<\/b><\/p>\n<p><em>What happens?<\/em> If you\u2019ve ever reviewed your website\u2019s referring sources list from Google Analytics, you may have noticed some odd-looking websites on there. These are due to bots that were set up on your website. So when traffic is referred from your website to another source, instead of seeing your url in their analytics, they\u2019ll instead see the fake referral website.<\/p>\n<p>As you can see, attacks can come in all shapes and sizes. Some hackers want to use your website\u2019s good reputation for their own devious purposes while others just want a way to gain access to all of your visitors\u2019 personal information. Regardless of the type of attack, it\u2019s clear that hackers won\u2019t discriminate on what type of business they hit if they see a weakness they can take advantage of.<\/p>\n\n<h3>Ensuring Privacy for Your Site Visitors<\/h3>\n<p>Regardless of your business type or size, it\u2019s important to be aware of the risks your website visitors take when they go to your site. They trust that a visit to your site and the handing over of their private information will be handled securely. So if you want to maintain your customers\u2019 trust and keep their confidence in your brand intact, you need to take the appropriate steps in securing your website.<\/p>\n<h4>1. Invest in Good Hosting<\/h4>\n<p>By <a href=\"https:\/\/wpmu-dev.pro\/blog\/web-hosting-review-so-just-who-is-the-best\/\" target=\"_blank\" rel=\"noopener\">hosting<\/a> your WordPress website on a trusted provider\u2019s server, you\u2019re taking the first step in securing your website and protecting your visitors\u2019 privacy. Quality hosting services will provide you with a number of site security assurances, including 24-hour monitoring, regular website backups, and individual hosting space (since sharing with another account could bring any corruptions from that site over to yours).<\/p>\n<p>If you\u2019re unsure of whether your current host provider or others you\u2019re looking into provide a safe environment, check their reviews. If they have ongoing issues with security or have a track record of poorly managing issues customers have brought to them, you\u2019ll want to find someone else.<\/p>\n<h4>2. Use a CDN<\/h4>\n<p>At this point you might be wondering why we would suggest that you invest in additional \u201chosting\u201d services if you\u2019re already paying for a reputable hosting provider. Well, a\u00a0<a href=\"https:\/\/wpmu-dev.pro\/blog\/should-you-use-cdn\/\" target=\"_blank\" rel=\"noopener\">CDN<\/a>\u00a0(content delivery network) isn\u2019t really a hosting service. A CDN sits on\u00a0<em>top<\/em>\u00a0of your hosting and aids in the delivery of your website\u2019s non-static content to visitors, no matter where they\u2019re located around the world.<\/p>\n<p>CDNs are most commonly associated with faster site load speeds, but many of them\u2014like\u00a0<a href=\"https:\/\/www.cloudflare.com\/features-cdn\/\" rel=\"noopener\" target=\"_blank\">CloudFlare<\/a>\u2014provide additional security checks for your website.<\/p>\n<div  class=\"wpdui-pic-large   \" >\n<figure class=\"wp-caption aligncenter\" data-caption=\"true\"><img loading=\"lazy\" decoding=\"async\" class=\"attachment-1364x1364 size-1364x1364\" src=\"https:\/\/wpmu-dev.pro\/blog\/wp-content\/uploads\/2016\/05\/maxcdn-network.png\" alt=\"MaxCDN, a popular CDN, has 19 servers in 18 cities around the world.\" width=\"1364\" height=\"400\" \/><figcaption class=\"wp-caption-text\">MaxCDN, a popular CDN, has 19 servers in 18 cities around the world.<\/figcaption><\/figure>\n<\/div>\n<h4>3. Set Up SSL<\/h4>\n<p>For any website dealing in sensitive information,\u00a0<a href=\"https:\/\/wpmu-dev.pro\/blog\/ssl-https-wordpress\/\" target=\"_blank\" rel=\"noopener\">SSL<\/a>\u00a0(Secure Sockets Layer) is an absolute must. Once you\u2019ve lined up a hosting provider you trust, look to see if they offer SSL certificates as well (which many of them do). If they don\u2019t, there are others who can issue a valid certificate for free, like\u00a0<a href=\"https:\/\/letsencrypt.org\/\" rel=\"noopener\" target=\"_blank\">Let\u2019s Encrypt<\/a>.<\/p>\n<p>The main purpose of SSL is to create an extra layer of protection (via encryption) for your visitor&#8217;s information so third parties can\u2019t gain access to it. In addition, SSL encryption comes along with the added benefit of improved SEO. As Google and the other search engines seek to refer traffic to valid and trusted sources, your SSL certificate stands as proof of this.<\/p>\n<h4>4. Consider DDoS Protection<\/h4>\n<p>In the Attack Launchpad security threat mentioned above, we discussed how hackers might be invading your site for the purposes of attacking another one. That\u2019s essentially what DDoS (distributed denial of service) is. Hackers will use a number of methods to direct an overwhelming amount of traffic to a website in the hopes of forcing the site to crash and consequently denying site visitors any access.<\/p>\n<p>If your company is a larger enterprise and\/or you process a lot of transactions, making an investment in a DDoS mitigation service is not a bad idea. The cost of your site going down and all business coming to a halt can be disastrous for a company, so consider this extra layer of protection a necessity. A number of companies with CDN services\u2014like\u00a0<a href=\"https:\/\/www.incapsula.com\/ddos\/ddos-mitigation-services.html\" rel=\"noopener\" target=\"_blank\">Incapsula<\/a>\u2014offer DDoS protection as well, so take time to research and see whether it\u2019s possible to bundle your security services under one umbrella (and save some money).<\/p>\n<h4>5. Install a Firewall<\/h4>\n<p>Your host provider should have already installed a firewall for your server. While firewalls are a great way to keep out unwanted visitors, many hackers these days have found creative ways to get around them. To be on the safe side, add a firewall to your website for an extra level of protection.<\/p>\n<p><a href=\"https:\/\/firewalld.org\/\" rel=\"noopener\" target=\"_blank\">Firewalld<\/a>\u00a0offers a free one you can use. If you\u2019re unsure of how to install it yourself, check with your host provider and see if they can help. If you\u2019re on a shared server, they should be able to do this for you without a problem.<\/p>\n<h4>6. Keep Plugins in Check<\/h4>\n<p>Most WordPress website vulnerabilities come from plugins. WordPress\u2019s security team reviews all third-party tool submissions, but it\u2019s inevitable that some insecurity will make it through\u2014and plugins happen to be the most common place where it does.<\/p>\n<p>There are three things you can do to make sure your plugins are kept in check:<\/p>\n<ol>\n<li>Read through the information WordPress collects on all plugins. Check for WordPress version compatibility (which indicates they\u2019re keeping plugins up-to-date alongside WP security updates), last update (which indicates a developer who stays on top of the plugin\u2019s maintenance), active installs (which indicates how many other users trust the plugin), and ratings. Take it one step further and read through the negative ratings to see if anyone has reported security issues in the past.<\/li>\n<li>Review the plugin\u2019s scripts to verify there isn\u2019t any malicious coding in it. <em>Note: this will require that you know PHP. If you need assistance reviewing any scripts or coding, <a href=\"https:\/\/wpmu-dev.pro\/blog\/defender\/\" target=\"_blank\">Defender<\/a> can scan your site for vulnerabilities. Anything deemed unnecessary or potentially harmful should be stripped out.<\/em><\/li>\n<li>Use a security plugin to monitor and report on any potential issues with other plugins as well as to use brute force protection. While there are a number of well-rated security plugins available,\u00a0<a href=\"https:\/\/wordpress.org\/plugins\/wordfence\/\" rel=\"noopener\" target=\"_blank\">Wordfence<\/a> is a popular option with over a million downloads and a rating of 4.9 out of 5 stars.<\/li>\n<\/ol>\n<h4>7. Disable Error Reporting<\/h4>\n<p>Did you know that when your site throws an error that your server path will be displayed for all to see? Hackers know this and they will keep an eye out for that information if you haven\u2019t disabled front-end error reporting. Rather than give that valuable information away for free, disable those notifications.<\/p>\n<p>For more on error reporting, check out our post <a href=\"https:\/\/wpmu-dev.pro\/blog\/debugging-wordpress-how-to-use-wp_debug\/\" target=\"_blank\">Debugging WordPress: How to Use WP_DEBUG?<\/a><a>.<\/a><\/p>\n<h4>8. Clean Up Your Spam<\/h4>\n<p>The amount of spam hitting a website can be a problem. Spam isn\u2019t just an annoyance, but it also can pose some serious security risks. That\u2019s why plugins like Akismet were created\u2014so you can easily block comments from known spammer IP addresses.<\/p>\n<p>In collecting IP address information on your website though, you\u2019re putting visitors\u2019 privacy at risk. The only way to keep that information safe is by not storing the IP address information from commenters in the first place. So if you get rid of IP address information on your site, how do you prevent spam comments as well as trackbacks and pingbacks from coming through?<\/p>\n<ul>\n<li>For splogs (fake spammer accounts), you can use our\u00a0<a href=\"https:\/\/github.com\/wpmudev\/anti-splog\" rel=\"noopener\" target=\"_blank\">Anti-Splog plugin<\/a>.<\/li>\n<li>For trackbacks and pingbacks, you merely need to update your WordPress settings to not \u201callow link notifications from other blogs.\u201d You can read more about it in our post <a href=\"https:\/\/wpmu-dev.pro\/blog\/trackback-pingback-spam\/\" target=\"_blank\">How to Stop WordPress Trackback and Pingback Spam<\/a>.<\/li>\n<\/ul>\n<div  class=\"wpdui-pic-large   \" >\n<figure class=\"wp-caption aligncenter\" data-caption=\"true\"><img loading=\"lazy\" decoding=\"async\" class=\"attachment-1364x1364 size-1364x1364\" src=\"https:\/\/wpmu-dev.pro\/blog\/wp-content\/uploads\/2016\/06\/stop_spam_810.png\" alt=\"Stop spam on your Multisite network with our Anti-Splog plugin.\" width=\"1364\" height=\"682\" \/><figcaption class=\"wp-caption-text\">Stop spam on your Multisite network with our Anti-Splog plugin.<\/figcaption><\/figure>\n<\/div>\n<h4>9. Enforce Stronger Login Settings<\/h4>\n<p>There are two types of logins you need to be concerned with on your website: your own as well as those of your visitors. Any time someone is given access to your website (on either the front or the backend), there is an increased risk of someone else maliciously entering or gaining access to private information.<\/p>\n<p>With that being said, there are a number of ways you can ensure certain login guidelines are enforced (just make sure you\u2019re abiding by them as well):<\/p>\n<ul>\n<li>Encrypt users\u2019 passwords with\u00a0<a href=\"https:\/\/wpmu-dev.pro\/blog\/strong-passwords-bcrypt\/\" target=\"_blank\" rel=\"noopener\">bcrypt hashing<\/a><\/li>\n<li>Secure the wp-admin directory (which contains access info for everyone) by requiring an additional username and password in order to access the folder.<\/li>\n<li>Add the\u00a0<a href=\"https:\/\/wordpress.org\/plugins\/google-authenticator\/\" rel=\"noopener\" target=\"_blank\">Google Authenticator plugin<\/a> for two-factor authentication.<\/li>\n<li>Require users to choose a strong password containing letters, numbers, and symbols.<\/li>\n<li>Limit login attempts and lockout anyone who exceeds a certain number of those attempts.<\/li>\n<\/ul>\n<h4>10. Restrict Access<\/h4>\n<p>Restricting access to your website isn\u2019t just about keeping hackers out, it\u2019s also about making sure that any user given access for specific purposes sticks to those purposes. Here are some restrictions you should plan on setting:<\/p>\n<ul>\n<li>Your\u00a0<a href=\"https:\/\/wpmu-dev.pro\/blog\/wordpress-wp-config-file-guide\/\" target=\"_blank\" rel=\"noopener\">wp-config.php<\/a>\u00a0file contains a lot of valuable information. In order to secure that file, move it up one level above your WordPress installation. This will ensure that whoever tries to access it receives an error message instead.<\/li>\n<li>Update your security keys regularly. Our\u00a0<a href=\"https:\/\/wpmu-dev.pro\/project\/wp-defender\/\" target=\"_blank\" rel=\"noopener\">Defender plugin<\/a>\u00a0will handle this for you with one click.<\/li>\n<li>You\u2019ll also want to\u00a0<a href=\"http:\/\/codex.wordpress.org\/Hardening_WordPress#Disable_File_Editing\" rel=\"noopener\" target=\"_blank\">disable edit<\/a>\u00a0capabilities for admin users. This will force anyone trying to access your PHP files (like themes, plugins, etc.) to log in through FTP.<\/li>\n<li>Carefully manage your users\u2019 roles and access within WordPress so they only have access to the areas of your site they need to get into.<\/li>\n<li>On a related note, make sure to remove FTP access immediately after a user has completed the necessary work within it.<\/li>\n<li>Disable\u00a0<a href=\"https:\/\/codex.wordpress.org\/Changing_File_Permissions\" rel=\"noopener\" target=\"_blank\">directory browsing<\/a>\u00a0so hackers and unauthorized users can\u2019t see any of the files on your website.<\/li>\n<li>The\u00a0<a href=\"https:\/\/wpmu-dev.pro\/blog\/htaccess\/\" target=\"_blank\" rel=\"noopener\">.htaccess file<\/a>\u00a0is going to be your best friend when it comes to controlling site access. Set up rules to restrict access and site visits automatically.<\/li>\n<\/ul>\n<p>It should also be noted that all of these suggested tips for ensuring privacy are especially important for eCommerce websites that deal with the exchange of financial data. In order to achieve PCI compliance, you need to have certain systems in place to ensure you\u2019re securing customer info.<\/p>\n<p>Remember: your main goal in using more reliable security services and having stricter standards for your website is so you can protect visitors\u2019 information. If they start to feel in any way that your website is compromising their safety, they\u2019re going to abandon it in search of someone else\u2019s who can give them that sense of security.<\/p>\n<p>If you have any further questions on what you can do to secure your website, check out the <a href=\"https:\/\/wpmu-dev.pro\/blog\/keeping-wordpress-secure-the-ultimate-guide\/\" target=\"_blank\" rel=\"noopener\">Ultimate Guide to WordPress Security<\/a>.<\/p>\n<h3>In Case Your Site Does Get Hacked<\/h3>\n<p>There are a number of ways you can find out if your website has been the victim of hacking:<\/p>\n<ul>\n<li>Google search warnings<\/li>\n<li>Google Webmaster tools detect malware<\/li>\n<li>Hosting provider takes your website offline<\/li>\n<li>Google Analytics shows a severe and permanent drop-off in traffic<\/li>\n<li>A customer tells you (which you want to prevent at all costs)<\/li>\n<\/ul>\n<p>WordPress website security is not always a sure thing, but there are steps you can take to ensure the effects of an attack are not long-lasting or inflict irreparable damage to your brand.<\/p>\n<ol>\n<li>Review <a href=\"https:\/\/codex.wordpress.org\/FAQ_My_site_was_hacked\" rel=\"noopener\" target=\"_blank\">WordPress\u2019s guide<\/a> on how to deal with being hacked.<\/li>\n<li>Reset your WordPress, cPanel, FTP, and other database logins and secret keys immediately.<\/li>\n<li>Check the list of website users. Anyone you don\u2019t recognize should have their access privileges revoked.<\/li>\n<li>Check in with your hosting provider, especially if you use shared hosting and your site\u2019s attack has put others at risk.<\/li>\n<li>Run a Sucuri or Wordfence scan (or use whichever security plugin provider you have) on your website.<\/li>\n<li>Run a scan on your computer. Have all other website admins do the same.<\/li>\n<li>Review your<em> .htaccess<\/em> and <em>wp-config.php<\/em> files for any errant coding or scripts. Remove any corruptions.<\/li>\n<li>For any files, plugins, or themes found to contain potential security risks, remove and reinstall secure versions (if you still need them).<\/li>\n<li>If your website has gone down or the rework needed to remove the malicious content is excessive, replace your website with a backed-up version.<\/li>\n<li>Once the threat has been identified and removed, notify any parties potentially affected so they can take security precautions on their end.<\/li>\n<\/ol>\n<p>In case you missed it\u00a0last year, check out what happened to <a href=\"https:\/\/wpmu-dev.pro\/blog\/cleaning-up-after-wordpress-hack\/\" target=\"_blank\" rel=\"noopener\">Jenni McKinnon<\/a> when she skimped on securing her WordPress website and what she ultimately did to recover from it. There are some good lessons to be learned from her experiences.<\/p>\n<h3>Wrapping Up<\/h3>\n<p>A breach in your site\u2019s security can mean huge losses for your business\u00a0in revenue,\u00a0time,\u00a0SEO,\u00a0brand reputation, and\u00a0your audience\u2019s trust<\/p>\n<p>You can\u2019t afford to hold off on securing your website until something happens. Do your due diligence and ensure that you\u2019ve got the right security tools in place; that you\u2019re working with trusted third parties; and that you\u2019re not storing sensitive company, user, or visitor information on your website.<\/p>\n<p>Your website is the face of your company and the only true touchpoint on the web where visitors can learn more about you. Don\u2019t let their experience suffer or let them put their personal privacy at risk because you failed to take the appropriate preventative measures.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Businesses of all sizes\u2014bloggers, SMBs, eCommerce companies, large enterprises, and more\u2014understand the importance of having a website. Without it, a business is relegated to the more time \u2013 and labor \u2013 intensive (and not to mention outdated) method of increasing brand recognition and converting leads through cold calling and word-of-mouth. Plus, if your brand doesn\u2019t [&hellip;]<\/p>\n","protected":false},"author":344989,"featured_media":156880,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"blog_reading_time":"","wds_primary_category":0,"wds_primary_tutorials_categories":0,"footnotes":""},"categories":[263],"tags":[10810,146],"tutorials_categories":[],"class_list":["post-156860","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tutorials","tag-wordpress-security","tag-privacy"],"_links":{"self":[{"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/posts\/156860","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/users\/344989"}],"replies":[{"embeddable":true,"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/comments?post=156860"}],"version-history":[{"count":13,"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/posts\/156860\/revisions"}],"predecessor-version":[{"id":224093,"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/posts\/156860\/revisions\/224093"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/media\/156880"}],"wp:attachment":[{"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/media?parent=156860"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/categories?post=156860"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/tags?post=156860"},{"taxonomy":"tutorials_categories","embeddable":true,"href":"https:\/\/wpmu-dev.pro\/blog\/wp-json\/wp\/v2\/tutorials_categories?post=156860"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}