A Web Host’s ModSecurity WAF Probably Isn’t a Reliable Source of Protection for Your WordPress Website
When it comes to security solutions for WordPress websites, the results of testing we do to see if security plugins provide protection against real vulnerabilities in WordPress plugins are a strong indication that people are not using security solutions based on how much protection they offer, considering how few provide protection. In our latest test, only a quarter of the plugins tested provided protection against a widely exploited vulnerability. Almost all the most popular plugins tested didn’t provide protection. If people are not considering the protection plugins offer, they almost certainly are not considering the unnecessary problems they can cause. What we have seen over the years is that is a missed opportunity, as the problems they cause are often a good way to assess whether they are a good option.
Yesterday, we touched on an example of that where the response from the developer of the Wordfence security plugin to incorrectly blocking contact form submissions was to suggest disabling a core protection that their firewall offers. So there is a problem with their firewall’s protection, but they don’t have any interest in getting it fixed. It’s not a great look. [Read more]