{"id":2634,"date":"2016-04-21T11:52:45","date_gmt":"2016-04-21T17:52:45","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2634"},"modified":"2016-04-21T11:52:45","modified_gmt":"2016-04-21T17:52:45","slug":"ithemes-security-plugin-has-one-click-secure-button-that-does-nothing-except-claim-the-website-has-been-secured","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/04\/21\/ithemes-security-plugin-has-one-click-secure-button-that-does-nothing-except-claim-the-website-has-been-secured\/","title":{"rendered":"iThemes Security Plugin Has &#8220;One-Click Secure&#8221; Button That Does Nothing Except Claim The Website Has Been &#8220;Secured&#8221;"},"content":{"rendered":"<p>We are frequently asked what about various broad based WordPress security plugins and which ones should be used. Our answer to the second\u00a0part of that\u00a0is none of them. These plugins generally provide little protection against actual threats and have been found to have security vulnerabilities themselves fairly often. That second part might sound odd, you would think that someone developing a security related plugin would be very careful about the security of their plugin, but people that actually know about security would be unlikely to be involved in developing one of these due to the first part of that, that they don&#8217;t provide much protection against actual threats.<\/p>\n<p>So what you are left with is products generally developed by people that don&#8217;t have much concern for real security and in a lot of cases seem to be mainly interested in making money by taking advantage of the public that understandably lacks strong security knowledge. That results in lots of plugins and related services that end up scaring people based on bad or false information and that collect information from users under false pretense.<\/p>\n<p>If you are looking for some particular security feature you would be better off finding a plugin that doesn&#8217;t also include a kitchen sink of other features\u00a0with it, since that reduces amount of code that could be harboring security vulnerabilities. The important things you need to do to keep your website secure are listed <a href=\"http:\/\/www.whitefirdesign.com\/resources\/secure-your-website-from-hackers.html\">here<\/a>.<\/p>\n<h2>The iThemes Security Plugin And Trust<\/h2>\n<p>That all brings us to something we just ran across with one of those plugins,\u00a0<a href=\"https:\/\/wordpress.org\/plugins\/better-wp-security\/\">iThemes Security (formerly Better WP Security)<\/a>, which is listed as having 700,000+ active installs.<\/p>\n<p>One important element of any security product is trust,\u00a0since the average user can&#8217;t verify that a product does what it says, they are trusting the developers in a major way. Any abuse of that trust should be a major\u00a0red flag. That trust is\u00a0something the developers of the iThemes Security plugin don&#8217;t seem to care about.<\/p>\n<p>When you install and activate the iThemes Security plugin a notice is displayed at the top of the page with a button to &#8220;Secure Your Site Now&#8221;:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2637\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-1.png\" alt=\"ithemes-security-1\" width=\"500\" height=\"200\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-1.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-1-300x120.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p>Clicking on that brings up this page:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2638\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-2.png\" alt=\"ithemes-security-2\" width=\"1076\" height=\"577\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-2.png 1076w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-2-300x161.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-2-768x412.png 768w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-2-1024x549.png 1024w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>The most important part of that would seem to be the section Titled &#8220;Secure Your Site&#8221;:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2639\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-3.png\" alt=\"Use the button below to enable default settings. This feature will enable all settings that cannot conflict with other plugins or themes.\" width=\"884\" height=\"77\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-3.png 884w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-3-300x26.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-3-768x67.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>When you click on the One-Click Secure button, you get a message that it is &#8220;Working&#8230;&#8221; for a moment:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2640\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-4.png\" alt=\"ithemes-security-4\" width=\"882\" height=\"78\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-4.png 882w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-4-300x27.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-4-768x68.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>Then it will tell you that &#8220;Site Secured. Check the dashboard for further suggestions on securing your site.&#8221;:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2641\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-5.png\" alt=\"ithemes-security-5\" width=\"888\" height=\"79\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-5.png 888w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-5-300x27.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/04\/ithemes-security-5-768x68.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>Based on that you would think\u00a0that the website has been secured in some way after doing that. It turns out that nothing actually has happened, something we found about when ran across a <a href=\"https:\/\/wordpress.org\/support\/topic\/no-security-status-visible#post-8000303\">post<\/a> on a thread on the WordPress.org support forum for the plugin that stated<\/p>\n<blockquote><p>Please note that since the 5.2.0 release (5.2.1 included) clicking on the <strong>One-Click Secure<\/strong> button in the <strong>First Important Steps<\/strong> modal window will not do anything despite the fact that it still reports:<\/p>\n<blockquote><p>Site Secured. Check the dashboard for further suggestions on securing your site.<\/p><\/blockquote>\n<p>which is also kind of lame as there is no longer a Security Status section on the Dashboard page &#8230;<\/p>\n<p>Note this is not a bug, since iThemes knowingly removed the code that was normally executed behind this button &#8230;<\/p><\/blockquote>\n<p>If you want to see that for yourself you can see the changes made in version 5.2.o <a href=\"https:\/\/plugins.trac.wordpress.org\/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=1330783%40better-wp-security&amp;old=1283582%40better-wp-security&amp;sfp_email=&amp;sfph_mail=\">here<\/a>\u00a0(doing a search on the page for &#8220;Register one-click settings&#8221; will take you to parts of the page where that is shown).\u00a0What makes this even more incredible is how long ago this happened, version 5.2.0 was release on January 18 and the post pointing that out is now two months old, and yet it is still that way now.<\/p>\n<p>When they don&#8217;t care about misleading people with something that visible, then you have to wonder what else they might be misleading people about. We already spotted\u00a0one other thing, but you will have to wait for a future post to hear about that.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We are frequently asked what about various broad based WordPress security plugins and which ones should be used. Our answer to the second\u00a0part of that\u00a0is none of them. These plugins generally provide little protection against actual threats and have been found to have security vulnerabilities themselves fairly often. That second part might sound odd, you &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/04\/21\/ithemes-security-plugin-has-one-click-secure-button-that-does-nothing-except-claim-the-website-has-been-secured\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;iThemes Security Plugin Has &#8220;One-Click Secure&#8221; Button That Does Nothing Except Claim The Website Has Been &#8220;Secured&#8221;&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,32],"tags":[55],"class_list":["post-2634","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-wordpress-plugins","tag-ithemes-security"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2634","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2634"}],"version-history":[{"count":4,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2634\/revisions"}],"predecessor-version":[{"id":2643,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2634\/revisions\/2643"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2634"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}