Monday, March 15, 2010

Posts Tagged ‘System’

4 security tips protects your blog from hacker

Recently online forums have been flooded with tales of WordPress blogs being hacked and then banned by Google for spreading badware. To avoid these nightmares, follow the simple WordPress security tips in this article to keep your blog safe.

Update to get the current version that’s secure

No software is free from bugs and security holes. Make sure that you are running the latest secure version. For WordPress – as of this writing – that means versions 2.6.

Since WordPress gives plugins and themes full access to your blog, you also need to keep your plugins up-to-date. With the latest 2.3 series of WordPress you are notified in the admin screen when the plugins that you have installed are released in new versions.

Disable and remove themes and plugins that you are not using

If you are like the majority of bloggers, you have tried several different themes for your blog. More than likely, you now have a few different unused plugins that are installed.

Every single piece of unwanted software may provide a new vulnerability. Since no one is using them, why waste the energy to take these packages to the latest version? Get rid of the software, eliminate all associated files and be done with the trouble.

The last step of actually removing the files from the server is very important. Almost all themes and plugins are installed in well known directory locations. An attacker can use that well known URL to exploit a vulnerability even if you’re not using that theme/plugin.

Only download and install trusted code

Just like you shouldn’t click on email attachments coming from people you don’t trust, you shouldn’t install software on your blog from untrusted sources. Only download code from the authors’ web site.

Since WordPress and most themes and plugins are released as open source, anyone can modify the code with malicious intent and put up the badware for download to unsuspecting web surfers.

There is a penalty for being an early adopter! Allow other people to work through the holes and security issues before you attempt to use the package.

Watch out for JavaScript includes

Web analysis services and ad networks require the addition of JavaScript to blog pages. JavaScript code is allowed to do almost anything with your web page without your permission. In Essence, you are trusting the security of your website to this unknown, third-party service

I would be unwilling to have JavaScript put on my web site by an entity I was not familiar with. I would be more receptive to legitimate, well-known ad network and web analytic providers such as Google AdSense and Google Analytics.

Ad networks also pose another problem if you don’t have control over who is allowed to advertise on your network. Google applies the guilt by association principle: If you are advertising for a site that has badware on it, your site may be blacklisted too.

How to make Wordpress become CMS

As many people know Wordpress is a blogging software, but now it is also can be a content management. So i would like to share some plugins, themes and tips that should be useful to you if you plan to done a content management.

Install Wordpress

Get the latest release of WordPress and install it on your clients server, some prefer to use Fantastico but i would suggest against it considering that Fantastico rarely install the latest version of WordPress.

Install the “One Click” Installer

(**if you ever used the Mambo/Joomla CMS before than this feature will be familiar to you)

Trust me this little plugin is going to be a lifesaver, the plugin allows uploading of a plugin or theme without the need of manually uploading by FTP, allowing the upload from the Admin panel. All you have to do is browse for the zip file and click “upload” and the plugin does the rest.

Permalinks/SEO

Nothing is worst than to have a person who doesn’t bother to do some SEO work for their client, WordPress has made it a tad easier to have a good SEO optimized site, just changed your Permalinks and you already on your way, next you should install the All in One SEO Pack.
If you need SEO help, i suggest you get the Seobook.

Customizing WordPress

Most probably you would not want your client to know that your using WordPress to build their site and even if you wanted them to know it’s always good to customize and tweak a little so that it doesn’t look “out-of-the-box’ and to achieve that you will need:

Custom Admin Branding – Customize the login screen, header and footer of the Wordpress Admin.

Clutter Free – Clutter Free is a plugin that lets you hide portions of the WordPress posting interface that you rarely (or never) use. Instead of being minimized (and still taking up room), they’ll be completely invisible.


WordPress Admin Themes
– A list i compiled a while back about Admin Themes.


Custom Admin Menu
– This plugin gives you full control of your Wordpress administration section, without requiring any changes to any files! All customizations are done using a very intuitive graphical interface.

Admin Drop Down Menu – This plugin makes life a little easier (Live Demo)

Wordpress Organizer – This plugin helps you or your client to manage the files uploaded to the site.

Custom Write Panel – In WordPress, a user could be assigned a role and, accordingly, that user will or will not have the capability to write a new Post.

With this plugin, a custom write panel could be accessible to certain roles only. For example, a custom write panel “Music Review” is created and a role “Music Review Writer” is invented. This custom write panel could be set to be visible to this new role only.

Dashboard Editor – This plugin allows you to add whatever you want to the Dashboard through PHP and HTML and allows you to even add Sidebar Widgets. You may also wipe the entire dashboard or individually remove some of the more irritating sections like the Dev news, Planet Wordpress and the getting started section.

Other Plugins to consider

Here’s a list of plugins that i found to be extremely useful when i’m working on my projects:

Contact Form & Forms

I’ve come across people who wanted not just a contact form but a form with many entry fields and i would highly recomend using the Dagon Design Form Mailer or cforms to accomplish this.

Gallery

There might be a need to run a gallery on the site and luckily for you there are already tons of “Gallery” plugins out there, you can find them all here.

Search Everything

One thing that bugs me about WordPress is the incapability to search anything that it outside of a “post”, if your projects requires you to have a good chunks of content on pages instead of posts than your going to appreciate the Search Everything plugin.

Page Navigation,Polls,Post Ratings,Print Page

All 4 of these plugins were created by Lester Chan, and it really does come in handy, you can find the plugins here.

QuickTags
Quicktags are those useful ‘one-click’ buttons that insert code for you,your client might not be as tech savy as you and so you could help them out by adding some quicktags, here’s a tutorial on how to add a quicktag.

‘Category Visibility’ Plugin

This plugin is ‘da bomb” UNFORTUNATELY it does not work with WordPress 2.3 and as far as i can tell it only works with version 2.2 and below which is really a sad thing considering what this plugin is able to do, with this plugin you can prevent a post from appearing on the frontpage and you can set it so that it enevr appears unless you link to that particular post…really really cool, i wish the author would update this plugin!.

Comment or No Comment?

Well if it’s going to be a site that a comment form on every single post is not needed so don’t forget to remove that from your theme, most of the time you can find and edit the code in the single.php file.

(if for some reason your using comments that don’t forget to activate Akismet)

Themes

This is a rather huge topic, there are tons of WordPress Themes out there and now there’s also quite a few Premium theme, i’m afraid i can’t say muuch about this topic because it’s really up to you to find the perfect theme and tweak or you could just design and code your own theme or buy a Premium Theme.

if you need help in finding themes you should read this.

That’s basically the steps to make the Wordpress as content management system, hopefully this post will be useful to you BUT remember this is just the tip of the iceberg, there are tons on tutorials, plugins and themes out there to ensure that you wil be able to bring out the best from WordPress.

All The Best!

Top 10 Alternative Wordpress Themes Download Sites

here is a list of other sites where you will be able to find great wordpress themes:

www.wpthemesfree.com

www.themeporter.com

www.wpthemespot.com

www.justskins.com

www.wpskins.org

www.templatesbrowser.com/wordpress-themes

www.themesbase.com

www.BloggingPro.com

www.wordpress-theme.org

www.bloggingthemes.com

After completing the list above there were some people who pointed out to me other good WordPress themes outlet, so here there are:

Additional Sites:

www.fresheezy.com

WordPress Wow

WPsnap

RockinThemes

Congratz Wordpress and Happy Birthday to Wordpress

May 27 2008, Happy 5 year Birthday to Wordpress. Wordpress is available completely free of charge under the GPL license. This blogging software that runs much of this site and thousands of other sites around the world is founded and developed by Matt.

To all California Readers, here is a good news. Wordpress will celebrate their birthday party at 111 Minna club starting at 9pm. The address is below:

111 Minna Gallery
111 Minna Street
San Francisco, California 94105.

Remember no present necessary, just bring yourself and all your wordpress friends to celebrate. It is a bar so 21 and above. Besides that, to get a free drinks, you will need a password, so just ask a fellow WordPresser.

Here is the announcement of first wordpress 0.7 release on May 27, 2003:
Wordpress Now Available
Also available at Facebook.

To see the others Wordpress Version at Release Archives.

Happy Birthday again to Wordpress. Wordpress.com | Wordpress.org | bbPress.org | automattic.com