Geek Archives - uPress https://www.upress.io/blog/post/category/geek/ Managed WordPress Hosting Wed, 12 Jan 2022 13:25:30 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://www.upress.io/wp-content/uploads/2021/01/favicon.png Geek Archives - uPress https://www.upress.io/blog/post/category/geek/ 32 32 A WordPress Sandbox: What it is, Why You Need it and How to Use it https://www.upress.io/a-wordpress-sandbox-what-it-is-why-you-need-it-and-how-to-use-it/ https://www.upress.io/a-wordpress-sandbox-what-it-is-why-you-need-it-and-how-to-use-it/#respond Mon, 10 Jan 2022 11:06:43 +0000 https://www.upress.io/?p=1857 Have you ever spent hours updating your WordPress site only to have it crash, losing all your work? Don't you wish there were a place you could test changes to your WordPress site before taking them live? A WordPress sandbox allows you to play around with your site while removing the risk.

The post A WordPress Sandbox: What it is, Why You Need it and How to Use it appeared first on uPress.

]]>
Most WordPress users find themselves constantly developing their site, from plugin updates to minor daily adjustments. It can be tempting to work on your site live, but even the smallest changes can put your site at risk. Even a single line of faulty code can compromise your site running smoothly.

Setting up a staging site (essentially a clone of your site) is a great way to test changes before taking them live. A WordPress sandbox is a staging environment in which you can modify your site freely without worrying about a mistake negatively affecting your site availability or your business.

Discover your personal WordPress sandbox today - click here

Let's take a look at everything you need to know about WordPress sandbox to get you on track to start innovating.

Dangers to look out for when you make changes on a live site

Even the smallest tweaks on a WordPress site can have a big impact. Until you test these changes, you can't be sure how they will affect your site. Whether you are updating plugins or trying out a new theme, one wrong move can lead an entire site to crash. A site crash may be the worst-case scenario, but there are a number of other risks involved in implementing changes before testing them.

Some other potential consequences of working on your WordPress site in a live environment are:

  • Broken website design
  • Drop in search engine ranking
  • Slow website load speed
  • Loss of visitors and potential business
  • Putting sensitive information at risk of exposure

WordPress website management is much more difficult when you do not know the potential issues that may arise with each adjustment you make to your site. The risks of working on your site in a live environment definitely outweigh the rewards, which is why you should have a staging site for all your WordPress development.

What is a staging site?

A staging site, or sandbox site, is an exact copy of your WordPress site in which you can experiment with modifications before taking them live. The staging site helps you catch errors in code or simply test different design elements without modifying your actual site. Whether you want to try out a new feature, update widgets or plugins, or make a major change, the staging site provides an environment in which you can do so safely.

While some users download WordPress locally on their devices to test changes before adding them to their live site, this may not always give accurate results. Certain changes made on the local server may not run the same way on the live server, leading to unforeseen errors.

Unlike the local WordPress server, the staging site runs on the same server configuration as your live site, so you will not run into any new issues when you are ready to take the changes from the staging environment to the live environment.

In short, the WordPress sandbox or staging site is a space for you to explore new things and figure out what works best on your site.

How to set up a staging site for WordPress

There are a number of options when it comes to setting up a WordPress staging site, some of which are more complicated than others. The best solution is dependent on your level of website management expertise. We have outlined the different ways to set up a WordPress Sandbox to help you get started.

Setting up a staging site through your WordPress host

If you are using a WordPress hosting service, a staging site may be offered as part of your package. If so, this is the easiest and most reliable way to set up your staging site. As managed WordPress hosting experts at uPress, for example, we provide a built-in sandbox, so you don't have to do any of the heavy lifting.

Another advantage to this option is that once you have decided which change you would like to take live, your managed WordPress host will also ensure that this process runs smoothly. Additionally, you'll usually be able to access your staging site in one click from within your dashboard or control panel.

This sandbox option offers the most convenience and the least headache, but it may be more costly than the other sandbox options below. On the other hand, if you anyway want other features included in managed WordPress hosting, the inclusion of the sandbox may just make the deal even sweeter.

Setting up a staging site with a WordPress plugin

If you do not use a WordPress hosting service, or your hosting service does not include a staging site, there are a number of WordPress plugins that can help you create a staging site. While this may be a cheaper option, there are some downsides.

For one, if you are using a WordPress hosting service in addition to a staging plugin, there might be compatibility conflicts as the plugin will not have full access to your hosting server.

Another potential issue with using a plugin is that the data from your staging site will be saved on the plugin's server. If your site contains sensitive data, such as customer information, this option may not provide the level of security you are looking for.

If you do want to go with a WordPress plugin for your staging site, you can download one from the WordPress plugin directory. The process of creating your staging site will differ depending on which plugin you decide to download.

Set up local installation

If you would like to set up an offline staging site, local installation is an option. Keep in mind that, unlike the other options for setting up a staging site, only those with access to your computer will be able to use a local staging site.

There are multiple free applications you can download to help you set up a local hosting environment on your computer, such as Local or Bitnami. Each application will differ slightly but will walk you through the setup process once you have downloaded.

While this option is cheap, the downside is that you will have to transfer your live site to your local staging site. This means that you will have to manually add any plugins or themes that you use on your live site, which takes more time than the previous options and also needs more technical know-how.

Setting up a staging site for WordPress manually

This option is more complicated than the others and is not recommended for WordPress beginners. To manually create a WordPress staging site, you will need to create a subdomain, an FTP account, import your database and hide your staging site. If any of the steps are not completed correctly, it could cause problems on your live site, which kind of defeats the purpose of a staging site to begin with.

If you do decide to manually set up your staging site, implementing the changes to your live site later is also a lengthier process with its own set of drawbacks.

Unless you are an experienced WordPress manager, this is probably not the option for you.

Tips for best using a sandbox

Once you have chosen the best option for setting up your staging site, the fun can begin. Think of the sandbox as exactly that: a place to play on your site with whatever different themes, plugins and design ideas you want. Feel free to explore the world of WordPress and expand your site’s horizons. The WordPress sandbox protects your site from any security breaches or crashes so you can keep your site up-to-date and in line with your newest business ideas, without risking any crashes or design disasters.

Once you are ready to deploy your changes to your live site, depending on which option you are using for your staging site, you should be able to do so quickly and easily. Most WordPress hosts and some plugins allow you to deploy changes with the click of a button.

All the world's a staging site... so go became a player.

As managed WordPress hosting experts, we know what we're talking about, whether you're asking what is a WordPress sandbox, why you need it and how to use it for website management. You can trust us with the entire gamut of WordPress questions, so the only one left is... why aren't we hosting your WordPress site yet? Click below and join us.

Discover your personal WordPress sandbox today - click here

The post A WordPress Sandbox: What it is, Why You Need it and How to Use it appeared first on uPress.

]]>
https://www.upress.io/a-wordpress-sandbox-what-it-is-why-you-need-it-and-how-to-use-it/feed/ 0
Top 10 WordPress Security Vulnerabilities - and How to Protect Your Site https://www.upress.io/top-10-wordpress-security-vulnerabilities-and-how-to-protect-your-site/ https://www.upress.io/top-10-wordpress-security-vulnerabilities-and-how-to-protect-your-site/#respond Thu, 01 Jul 2021 09:31:57 +0000 https://www.upress.io/?p=1118 WordPress sites can be highly secure, as long as you take steps to prevent, address, or otherwise mitigate security vulnerabilities. Here's the skinny on how to keep your WordPress site updated, patched, and protected against cyber threats.

The post Top 10 WordPress Security Vulnerabilities - and How to Protect Your Site appeared first on uPress.

]]>
It's practically gospel that WordPress sites are less secure than sites built on other platforms, but that's actually a myth. We are managed WordPress hosting experts, so we know! WordPress is far and away the most popular website host, which means that the chances are high that any given site that gets hacked will have been built on WordPress.

Of course, it's still vital for website managers to keep their WordPress sites updated, patched, and protected against cyber threats. Here are 10 of the main WordPress security vulnerabilities that hackers could target to break into your website, and suggestions for ways to strengthen them and close the wormholes.

Migrate to uPress within 24 hours


  1. Vulnerable plugins 

Plugins add so much functionality to WordPress sites, but if you're not careful, they could turn into a vulnerable backdoor. There are tens of thousands of plugins and themes made by third-party developers and companies worldwide, but not all of them are equally secure or trustworthy.

It's crucial to choose plugins which are actively managed, with owners who regularly release updates and provide support. Just like core WordPress updates, plugin and theme updates help fix known WordPress security vulnerabilities, close loopholes that hackers could exploit, and make sure that your site is as secure as possible. An old plugin that no longer receives active support can therefore be an open door for hackers.

It can often be tempting to use a premium plugin or WordPress theme that's not offered through the WordPress plugin repository, but it's often a mistake. Sometimes, these premium plugins and themes aren't updated regularly, and sometimes not at all. Even when they are updated, the process is usually complicated and has to be done manually, so unless you keep on top of the updates, there's a high risk that your plugin will go un-updated.

As managed WordPress hosting experts, we highly recommend using only plugins and themes from the official WordPress plugin repository that were developed by well-known companies and are kept updated for your managed WordPress hosting or self-hosted site. This will go a long way to preventing any security issues, since these plugins and themes are thoroughly checked to make sure they don't contain any malicious code and are in line with security regulations.

  1. Default passwords

Passwords are meant to protect the entrance to websites and web hosting platforms under your control, so they are often the first line of attack for hackers. One of the most common approaches is a Brute Force attack, when hackers just try out hundreds of passwords, hoping that they'll get lucky and hit on the one you used for your account. That's why it's so important to create a long and complicated password for your website. The harder it is to guess your password, the less likely it is that this kind of attack would succeed.

You'd be amazed at the number of web managers and developers who forget to change the default password on their website — and when we say website, we mean not just the WordPress site itself, but also the WordPress dashboard, FTP accounts, databases, WordPress managed hosting, the email you use to recover your site, and anything else tied to it. If you're using managed WordPress hosting, make sure that you generate a different unique password for every account. Reusing a password you've used before, or are using elsewhere, raises the risk that someone will guess it, or hack it from a different site.

Even more sites have passwords like "password", "12345678", or easy-to-guess options like birth dates, ID numbers, and phone numbers, which are always among the first that bots or hackers will try.

Many website owners don't like to use long and complicated passwords simply because they're hard to remember. A good solution is to use a complete sentence that makes sense only to you (and even misspell a word on purpose) so it's much easier to remember. These kinds of passwords are much stronger than a single-phrase password.

Another solution would be to use a password manager that generates and stores unique secure passwords. That way you only have to remember one secure password; the one for your password manager.

It's not just the password, either: you also need to pick a secure username for your managed WordPress hosting or self-hosted website. If you use "admin" as your username, you are basically doing half the job for hackers targeting your website.

  1. Weak user permissions

The more people can access your WordPress dashboard, the greater the risk that someone will introduce an unsafe plugin, use a weak password, or accidentally activate infected software. It's easy to lose track of permissions if you're managing a large team of web designers, editors, SEO managers, writers, and more, but crucial to restrict access to mission-critical areas.

WordPress has a number of different user roles, each of which permits a different level of access and activity:

  • Subscriber – A registered user who can only access their own personal profile.
  • Contributor – A user with permission to edit and manage their own posts, but who can't publish any content.
  • Author – A user with permission to edit, manage, and publish their own posts.
  • Editor – A user with permission to edit, manage, and publish their own and other users' posts and pages, but without permission to access "sensitive" areas of the dashboard.
  • Administrator – A user with permission to view and change all WordPress dashboard areas and every feature and option.
  • Super Administrator – (Only available on Multisite installs) User with permission to access and manage all the websites on a Multisite network.
  1. Unlimited login attempts

Hackers can only attempt the brute force attacks mentioned above if they have an unlimited number of opportunities to keep trying to guess your password. By default, WordPress allows unlimited login attempts from any IP address, which just makes it easier for malicious actors.

Close this WordPress security vulnerability by setting WordPress to automatically block the attacker's IP after a certain number of failed attempts. One of the easiest ways to set this up for self-hosted or managed WordPress hosting is using a plugin called Limit Login Attempts Reloaded. It's available for download from the official WordPress plugin repository.

uPress customers: The plugin WeSafe is installed by default on all the websites on our servers and performs this action.

  1. Single-factor authentication

"Regular," single-factor authentication just requires anyone logging in to enter their username and password, and then they can gain entry. It means that hackers effectively only have to pass through one "gate" to enter the website and is one of the more serious WordPress security vulnerabilities.

You can make it much harder for them by activating two-factor authentication (TFA). With two-factor authentication, everyone has to enter a unique one-time code sent via email or SMS to their pre-registered account or phone number, or one that's generated on another registered device, as well as getting the right password.

One of the easier ways to do this for your managed WordPress hosting site is by using the Google Authenticator plugin that's available for download from the official WordPress repository. It offers two-factor authentication via a mobile app (note that you need to install the Authenticator app on your phone for this to work). After installing everything, you log in to your WordPress site with your username and password. You'll be requested to enter a 6 digit code from the mobile app. The code changes every 30 seconds and can be generated only on the app that is paired with your user account.

  1. Sending unencrypted data

Whenever something is changed on the WordPress hosted site you manage, the data travels from one server to another, giving malicious actors an opportunity to intercept the information packets and steal the data. But if you encrypt it, using a TLS encryption certificate, they wouldn't be able to read the data even if they could capture it.

The TLS certificate is based on unique encryption keys installed on the website's server. Only your computer will be able to use those keys to decrypt the information. You can acquire a TLS certificate for free with most hosting providers, using Let's Encrypt.

Upress customers: You can install a TLS certificate from the security tab in our management panel.

  1. Ignoring backdoor vulnerabilities

Backdoors are a kind of malware that hackers send out, often disguised as authentic WordPress system files, in the hopes that someone will install it on their site. Once installed, it creates a kind of wormhole that lets hackers enter the server by the backdoor (hence the name) and creep across to other sites hosted on the same server.

As well as enabling two-factor authentication, checking site permissions, and preventing unlimited login attempts, you can help protect your site from backdoor WordPress security vulnerabilities by regularly scanning it with tools like SiteCheck that detect common backdoors.

  1. Malicious redirects

A malicious redirect attack is when the hacker changes some of the code in your website files, either by entering through a back door, using a rogue plugin or theme, or breaking into your server.

Disabling unlimited login attempts, ensuring your passwords are strong, and checking your permission levels can all help prevent malicious redirects. It's also a good idea to scan your site from time to time with a scanning plugin, and follow up on any alerts that you receive.

  1. Permitting XML-RPC protocols

Since WordPress version 3.5, every WordPress site has XML-RPC protocol enabled by default. Although this helps connect your WordPress managed site with other applications and websites, it can also compromise your security. XML-RPC protocols allow hackers to the system.multicall function to attempt logging in with thousands of different protocols for only a small number of requests.

Disabling can be done by using the Disable XML-RPC-API plugin; by restricting access to the xmlrpc.php path at the server firewall level, or by using the .htaccess or nginx.conf file at the server level.

  1. Welcoming bad bots

Many hackers use bots as "spies" to check on your website's defenses and performance before they decide to attack. As well as scoping out your site for WordPress security vulnerabilities, bad bots can drag down performance and steal bandwidth and content.

But you don't need to let them through the door. There's a list of "bad bots" on botreports.com, and you can block them from entering your site at all. Most security plugins and managed storage services already block the bots on this list, but you can be doubly safe by blocking them at the firewall; at server level with the.htaccess or nginx.conf file; or by installing the StopBadBots plugin.

UPress clients: There is an on / off button to block bad bots under the Security tab.

Stop WordPress security vulnerabilities from turning into security incidents

WordPress sites can be highly secure, as long as you take steps to prevent, address, or otherwise mitigate security vulnerabilities before hackers can take advantage of them. These 10 tips won't prevent any security incident, but they are a very good start to making your WordPress managed sites as secure as possible.

As managed WordPress hosting experts, we speak your language. We can geek out with you about security vulnerabilities, but we can also discuss HTTP2 protocol, IPv6 support, or DNS tools. You can trust us with the entire gamut of WordPress questions, so the only one left is... why aren't we hosting your WordPress site yet? Click below and join us.

Explore plans

The post Top 10 WordPress Security Vulnerabilities - and How to Protect Your Site appeared first on uPress.

]]>
https://www.upress.io/top-10-wordpress-security-vulnerabilities-and-how-to-protect-your-site/feed/ 0
How to Fix a Slow First Page Load on a WordPress Site https://www.upress.io/how-to-fix-a-slow-first-page-load-on-a-wordpress-site/ https://www.upress.io/how-to-fix-a-slow-first-page-load-on-a-wordpress-site/#respond Tue, 01 Jun 2021 06:14:06 +0000 https://www.upress.io/?p=1013 When WordPress is slow to load the first page, it can spell death to web traffic. But WordPress sites can be notoriously heavy and slow to load, thanks to all the plugins, themes, unnecessary CSS, etc. Nobody wants to wait, so how do you fix a sluggish first page load? Here are 7 fixes that you can implement today.

The post How to Fix a Slow First Page Load on a WordPress Site appeared first on uPress.

]]>
As managed WordPress hosting experts, we know all too well that when WordPress is slow to load the first page, it can spell death to web traffic. We’re all busy doing hundreds of things at a time, our patience is limited even at the best of times, and no one is willing to wait around for your page to load. Google’s latest core update requires every web page to load Largest Contentful Paint (LCP) in no more than 2.5 seconds to be considered just “acceptable,” and you need to keep it under 2 seconds to be "good."

But WordPress sites can be notoriously heavy and slow to load, thanks to all the plugins, themes, unnecessary CSS, etc. 

It’s easier to track down the fault when the entire website is slow, but it’s fairly common to see a really slow page load the first time you hit the website in the morning, or if the site’s been unused for a few hours and then you return to it. 

After it’s "woken up" the first time, it's generally smooth and fast loading for the rest of the day. Since it's pretty unlikely that your website is just not a morning person, there’s got to be another way to fix a WordPress site that's slow to load the first page.

To fulfill your need for speed - click here


How to deal with your WordPress site when it's slow to load first page

There's no single solution that works for every web page. Fixing website speed and page load requires a lot of time, attention, and tedious trial and error, although there are some common fixes to try out first before you reach out to your community forum. 

Use your local server's IP and turn to https://gtmetrix.com to run a site audit and work through the issues that it presents. Some of the factors that influence page speed and load, and which could be causing your issue, include:

  • Image optimization
  • Too many CSS files, and/or CSS files that are going unused
  • Too many JavaScript files
  • Not deferring JavaScript parsing
  • Failing to minimize JavaScript
  • Failing to minimize CSS
  • Too many MySql queries
  • Failing to minimize request size
  • Forgetting to leverage browser caching

Here are some of the ways that WordPress developers have dealt with their slow initial page load problem. 

  1. Check your server

If you're lucky, it's a server issue caused by your host's policies. Shared hosting is particularly prone to slowing down your page load and speed, but it can happen even with dedicated hosts.

Some hosts do throttle speeds for inactive pages, and there have been a lot of complaints around GoDaddy's host loading speeds. Try transferring your page to a local managed WordPress hosting service so you can identify if the problem persists.

  1. Examine your caching 

If you're loading RSS feeds front-end, the cache can expire, which causes a very long pause before there’s a response the next time you load up the site. Installing a caching plugin can help.

If you've already got a lot of caching in your cPanel, that could be interfering with response time. Deactivate and reactivate your caching plugins one at a time to see what helps, and try rejigging your caching plugin setup. Sometimes it helps to remove "Combine CSS Files" and "Combine JavaScript Files".

If you've identified the cache plugin, but you can't do without it, experiment with the plugin settings. ESI has been found to be a problem for LS Cache plugin users, it treats each image as a separate block and makes a separate PHP request, so that's a lot of requests and the images load very slowly

  1. Reinstall all plugins

Even though your plugin is active, updated, and seems to be working smoothly, sometimes you end up with a patchwork of updates and code that drags everything down. It can work to remove and then reinstall each of your plugins, one at a time. Reinstalling means you get the latest version all in one smooth package.

  1. Clean up heavy elements

Over time, large databases can bloat and get clogged up. If you’ve been running the same website for years, all your different plugins, restyling, and updates can leave their traces on database tables. Use query monitor to determine if this is a problem — log in as admin with query monitor active, leave the site for a day, then return to check which queries take the longest.

Sometimes 'Advanced Database Cleaner' can help, but if your databases are large, your only option will be to completely reset them and rebuild them from scratch.

  1. Rewrite your php

WordPress' PHP itself can be holding you back. Try rebuilding your site with your own PHP codes. It might take more effort than using WordPress PHP, but the results will be worth it.

  1. Cron job workaround

It's not a solution, but if you’ve been trying and trying and you still can’t find the root of the issue, setting up a cron task or scheduled task can serve as a workaround. Create a cron job to call your home page once every 5, 10, or 20 minutes, to keep it "awake" so that you won’t have the issue of WordPress being slow to load the first page.

  1. Think differently

One developer couldn't work out what was dragging down his site page load and speed. His team tried literally everything, and nothing worked. They came back to it after four years (!) and discovered that the sites had too many articles marked as sticky.

Because of the WordPress serialized array in wp_options to mark sticky posts, it caused the main loop of the dynamic home page to take an incredibly long time. Clearing the sticky_posts field in the table fixed the problem.

Deal with WordPress when it's slow to load first page

Fixing your WordPress website speed really isn't optional. It’s almost certainly going to take you a lot of time and effort, trying one thing and then another, but it'll be worth it when you solve the issue. These fixes mentioned above are a good place to start.

As managed WordPress hosting experts, we speak your language. We can geek out with you about site audits, but we can also discuss cron tasks, IPv6 support, or DNS tools. You can trust us with the entire gamut of WordPress questions, so the only one left is... why aren't we hosting your WordPress site yet? Click below and join us.

To fulfill your need for speed - click here

The post How to Fix a Slow First Page Load on a WordPress Site appeared first on uPress.

]]>
https://www.upress.io/how-to-fix-a-slow-first-page-load-on-a-wordpress-site/feed/ 0
How do I Backup My WordPress Site Without Plugins https://www.upress.io/how-do-i-backup-my-wordpress-site-without-plugins/ https://www.upress.io/how-do-i-backup-my-wordpress-site-without-plugins/#respond Sun, 09 May 2021 08:43:09 +0000 https://www.upress.io/?p=922 Because sites crash for many reasons including security breaches, serious system failures, or human error, WordPress backups are an essential part of site maintenance. A backup enables you to restore your compromised website to full functionality. Should you use a backup plugin? Find out here.

The post How do I Backup My WordPress Site Without Plugins appeared first on uPress.

]]>
All good developers know why site backups are important. They vividly recall that one moment of distraction when they clicked the wrong button or received the ominous notification that their site was hacked. Their hearts skipped a beat upon discovering that weeks' or years' worth of work was wiped out instantly, and they had no way to restore it.

Because sites crash for many reasons including a security breach, a serious system failure, or a human error, WordPress backups are an essential part of your site maintenance. A backup enables you to restore your compromised website to full functionality.

Website backups provide you with peace of mind — should anything go wrong, your site content will be safe.

Backup your WordPress site

How do I backup my WordPress site?

There are different tools and software available to backup your site, the most popular being a WordPress backup plugin.

If you run a standalone WP site like a small blog or a one-page "business card" website, you can easily install a website plugin to do the job.

But sometimes a plugin just won't suffice, especially if your website is larger and more complex like an online store.

Before responding to the question — how do I backup my WordPress site without plugins -- let's first understand why you might not want to use a plugin for backups.

Create a site backup with the click of a button - click here


Why not use a WordPress backup plugin?

With over 400,000 plugins in the WordPress Plugins directory, surely there must be one good plugin to conduct your website backups.

Yes, there are a few. But there are also a few good reasons to avoid adding additional plugins to your WordPress site.

  1. Website Security

Plugins provide third-party functionality to your site. The keyword here is third-party, meaning plugins are like strangers lurking on your site.  Some plugins are high quality and undergo regular updates and maintenance,  while others are not, and those poor quality ones might one day end up compromising your website security.

Popular online stores, for example, constantly receive new customer data including new user accounts and shopping carts in addition to their regularly added content and are much more vulnerable to attacks and crashes. Using a third-party plugin to do backups, in some cases, can be risky.

2. Website Speed

In the age of SEO, site speed is critical. The more plugins installed on your site, the heavier it becomes and the slower your site loads for your user.

As site speed decreases, the bounce rate increases which results in fewer conversions. Keeping your site lean (by limiting your plugins among other strategies) is important for attracting and keeping customers on your site.

3. Website Customization

With larger, more complex and custom sites, the basic file backup offered by many WordPress backup plugins just isn't enough. In addition, you have less control over what you can back up.

How Do I Backup My WordPress Site Without Plugins?

With larger, more complex and custom sites, the basic file backup offered by many WordPress backup plugins just isn't enough. In addition, you have less control over what you can back up.

1) Use your managed WordPress hosting solution's automatic backup plan

At uPress managed WordPress hosting, for example, we provide an automatic 30-day backup history, so you can restore all files, only selected files or just the database. Check with your current managed WordPress web hosting provider to see if a backup plan is available. This is the easiest route.

2) Use your web host's manual backup plan

Even if your web host conducts regular backups, it's important to backup your site manually in real time before or after making critical changes or installing updates.

Manual backups allow you to backup your site at any time and save it for future use.

You have more control during a manual update because you can choose which files you want to back up rather than backing up everything.

If you don't make frequent changes to your site — one manual backup a month is usually enough to keep your site safe.

WordPress sites must include backups for both the WP files and the WP database. If you only back up one, you’ll be missing half your site.

To manually update your entire site, simply login to your host's control panel, open the backup tool, click it, and voila! Your entire site will soon be backed up.

If you want to back up only certain files, below are more detailed instructions:

  1. Log into your hosting platform's administrative platform and find the Files Manager.
  2. Open Files manager and view all your WP directories and files.
  3. Select and compress the files that you need.
  4. Select a location to save the compressed files.
  5. Download this compressed file.

For WordPress Database Backup:

  1. Find your database in the  Files Manager and open wp-config.php. If you don’t know the name of your database, just do a search by typing in: define('DB_NAME',
  2. Next, locate phpMyAdmin, Database or MySql in your host’s control panel.
  3. Then, go to the database and click on export.
  4. On the export settings page, customize the following options:
    • Set the backup file type to GZIP (or ZIP)
    • Set the maximum length of a created query to 0 (so as to avoid truncation of queries)
  1. Hit Go and the database will start downloading

For security purposes, save your backup in separate places like on an external hard drive and in a Dropbox folder.

3) Use an FTP (file transfer protocol) server

While less commonly used and more technical, FTP servers provide significant security for file transfers. Here's how to back up your website using FileZilla FTP client.

  1. Download and install FileZilla, an FTP client.
  2. Open up FileZilla and enter your host information.
  3. Connect to your site. 
  4. Locate and copy your site's files. 
  5. Download them into a folder on your computer and save.
  6. Check your computer folder to be sure all the files have transferred.

Backup your website

There's no question that website backups are crucial to maintaining your site and avoiding tedious disaster recovery scenarios. How you back up your site is dependent on your needs as well as the complexity of your site.

The best place to begin is with your managed WordPress hosting service to see what backup plans they offer and if they match your needs.

As managed WordPress hosting experts, we speak your language. We can geek out with you about why we're hesitant to use plugins for backups, but we can also discuss cron tasks, IPv6 support, or DNS tools. You can trust us with the entire gamut of WordPress questions, so the only one left is... why aren't we hosting your WordPress site yet? Click below and join us.

Create a site backup with the click of a button - click here

The post How do I Backup My WordPress Site Without Plugins appeared first on uPress.

]]>
https://www.upress.io/how-do-i-backup-my-wordpress-site-without-plugins/feed/ 0
How Do I Update a WordPress Plugin Without Losing Customization? https://www.upress.io/how-do-i-update-a-wordpress-plugin-without-losing-customization/ Sun, 18 Apr 2021 09:01:17 +0000 https://www.upress.io/?p=815 86% of WordPress sites hacked are due to an outdated WordPress install, plugin, or theme. But users resist updating as updates can cut off plugins, extensions, and templates. So how do you maintain your precious customization while adhering to update standards? Find out here.

The post How Do I Update a WordPress Plugin Without Losing Customization? appeared first on uPress.

]]>
Updating your WordPress plugin promptly is crucial to its security and functionality. In fact, 86% of WordPress sites hacked are due to an outdated WordPress install, plugin, or theme. When things get hacked, we get frantic calls from customers (who we then help!) but we'd rather teach them how to prevent and avoid such incidents. As the managed WordPress hosting experts, please listen to our sage advice - do your backups - don't worry about customization. Read on to do it safely and keep everything you need.

Because WordPress CMS is open source, hackers can study WordPress source code to locate vulnerabilities in your site. For this reason, WordPress CMS and WordPress plugin developers issue frequent updates to eliminate new vulnerabilities and to maintain security on your site. But users often resist updating their sites as updates can cut off plugins, extensions, and templates that aren’t using the best practices and coding standards.

Customization is key, so are updated plugins - click here for both


Below is a list of four best practice suggestions to help you successfully update your WordPress plugin without losing the customization you’ve so carefully built.

1) Conduct regular WordPress backups and create a staging site
regular WordPress backups
Living dangerously is for Vegas. Not for WordPress maintenance.

By conducting frequent backups of your site's database and files, you can always roll back to the previous version without losing important data.

As an additional precaution, you should create a staging site and clone your site to it. Run all updates and testing on this staging site. This will give you insight into whether or not there are any compatibility issues. Once compatibility is confirmed, you can safely move any update changes to your plugin over to your live site.

2) Use hooks to extend your plugin functionality

WordPress provides hooks with actions and filters so you can customize your plugins and easily upgrade them. If your plugin contains hooks, you can extend its functionality without affecting its core. Plugin updates will not affect these hooks.

If your plugin does not contain code for hooks, you can create your own hooks or hire a developer to do so.

3) Avoid editing the plugin core

When customizing your plugin, avoid making changes to its core. You can add a functionality plugin to your website to make additional changes.

A functionality plugin allows you to place customized code into a separate plugin rather than directly into the plugin or theme itself. You can edit your functionality plugin and add snippets to it using the quick link in the admin menu. Because these customizations are separate from the actual plugin or theme, they’re not affected by plugin updates.

4) Use Code Snippets to add more functionality

Similar to a functionality plugin, the code snippets plugin enables you to add more functionality to your website without affecting its core theme. It runs like a "mini-plugin" using a GUI interface for adding snippets.

Snippets are stored in the WordPress database and are therefore not affected by WordPress updates.

If you have fewer snippets to add and prefer editing a file rather than using a graphic interface, then you can stick with the functionality plugin.

Update Your Plugins with Confidence

A healthy, secure, and high-functioning website depends on regular WordPress updates.

There isn't one clear way to update a plugin without losing customization. But there are preemptive ways to prevent your site from breaking. By implementing the best practices suggestions above, you will avoid unnecessary complications like data loss and compatibility issues when updating your plugins.

As managed WordPress hosting experts, we speak your language. We can geek out with you about updates and their effects on plugins, but we can also discuss cron tasks, code snippets, or DNS tools. You can trust us with the entire gamut of WordPress questions, so the only one left is… why aren’t we hosting your WordPress site yet? Click below and join us.

Customization is key, so are updated plugins - click here for both

The post How Do I Update a WordPress Plugin Without Losing Customization? appeared first on uPress.

]]>