Yahoo now has a 25% stake in Taboola

Yahoo has just finalized a 30-year exclusive advertising partnership in Taboola, which would secure a 25% stake in the company. This deal will allow Yahoo to use Taboola’s tech to manage its native ads.

Taboola’s native edge. Taboola specializes in native ads which can be found on popular sites like CNN and MSN. The ads typically look like part of the website and can be informative or entertaining.

However, shares of Taboola have fallen nearly 80% since last year. In January, it merged with a special purpose acquisition company and was valued at $2.6 billion.

The deal with Yahoo gives Taboola the exclusive license to sell native ads across Yahoo’s sites, and the companies will share revenue from those ad sales. The companies did not disclose the terms of the revenue split. The deal will make Yahoo Taboola’s largest shareholder.


Get the daily newsletter search marketers rely on.

<input type="hidden" name="utmMedium" value="” />
<input type="hidden" name="utmCampaign" value="” />
<input type="hidden" name="utmSource" value="” />
<input type="hidden" name="utmContent" value="” />
<input type="hidden" name="pageLink" value="” />
<input type="hidden" name="ipAddress" value="” />

Processing…Please wait.

function getCookie(cname) {
let name = cname + “=”;
let decodedCookie = decodeURIComponent(document.cookie);
let ca = decodedCookie.split(‘;’);
for(let i = 0; i <ca.length; i++) {
let c = ca[i];
while (c.charAt(0) == ' ') {
c = c.substring(1);
}
if (c.indexOf(name) == 0) {
return c.substring(name.length, c.length);
}
}
return "";
}
document.getElementById('munchkinCookieInline').value = getCookie('_mkto_trk');


Meta and TikTok weigh in. Executives at companies like Meta and TikTok have warned that advertisers skittish about the economy have pulled back on their spending. But Jim Lanzone, the chief executive of Yahoo, said in an interview that the deal with Taboola puts both companies in a good position for when the ad market revives, the NY Times said.

“I’m thinking, you know, five, 10, 30 years,” Lanzone said. “Digital advertising has huge wind at its back over the long term.” He added that while the company will continue to try to bring in money in other ways, such as expanding its subscription business or investing in e-commerce, “we have hundreds of millions of people consuming news and sports and finance on market-leading properties that are heavily monetized through advertising — and will continue to be.”

Dig deeper. You can read the full article from the NY Times here.

Why we care. Advertisers who run native ads may now have another option to expand their reach. Yahoo also commented that they were attempting to “build up each of its products within its mini-media empire and capitalize on its audience.” If this happens it will give advertisers and brands a more competitive edge in choosing which platforms to spend their marketing dollars.

The post Yahoo now has a 25% stake in Taboola appeared first on Search Engine Land.

Original source: https://searchengineland.com/yahoo-now-has-a-25-stake-in-taboola-389809

Twitter has launched 3 new ad targeting options

Twitter has just launched new ad targeting options, including a new ‘Conversions’ objective they originally announced back in August.

The new ‘Conversions’ objective. Advertisers are now able to focus their ad campaigns on those users who are most likely to take specific actions.

Previously, Twitter advertisers were able to optimize campaigns to focus on clicks, site visits, and conversions. But now you can further optimize for page views, content views, add-to-cart, and purchases.

Business Finance

As I mentioned, the updates were announced in August but released just before Thanksgiving.

What Twitter says. “Website Conversions Optimization (WCO) is a major rebuild of our conversion goal that will improve the way advertisers reach customers who are most likely to convert on a lower-funnel website action (e.g. add-to-cart, purchase).”

So instead of just aiming to reach people who are likely to tap on your ad, you can expand that focus to reach users that are more likely to take next-step actions beyond that, like:

  • Add-to-cart
  • Purchase
  • Register contact info
  • Subscribe

“Our user-level algorithms will then target with greater relevance, reaching people most likely to meet your specific goal – at 25% lower cost-per-conversion on average, per initial testing.”

Dynamic Product Ads. Dynamic Product Ads were initially launched in 2016 (a version at least). But this new update integrates a more privacy-focused approach, in order to optimize ad performance with potentially fewer signals.

Collection Ads. The Collection Ads format enables advertisers to share a primary hero image, along with smaller thumbnail images below it.

Twitter says, “The primary image remains static while people can browse through the thumbnails via horizontal scroll. When tapped, each image can drive consumers to a different landing page.”

Dig deeper. Read the full article on the Twitter blog.

Why we care. Yes, Twitter is still releasing new ad updates, despite cutting most of its staff. But it’s likely that these updates were almost completely finished anyway when Musk took over since they had been in development for months.

Advertisers who are still on Twitter should test the new ad features and options to gauge whether they’re valuable additions.

The post Twitter has launched 3 new ad targeting options appeared first on Search Engine Land.

Original source: https://searchengineland.com/twitter-has-launched-3-new-ad-targeting-options-389815

PCI Compliance for Businesses: Everything You Have to Know

Home Business Magazine Online

In recent years, credit cards have become more and more popular. There are a number of reasons for this. First of all, they are a convenient way to pay for things. Today you can use them to pay for items online or in stores — in general, mostly everywhere. Another reason why credit cards are getting more popular is that they offer rewards programs. With many cards, you can earn points for every purchase you make. You can redeem these points to get cash back or other perks. Also, if your card is stolen, you can just call the company and cancel it. And finally, using a credit card can help you build up your credit history, which can be useful later on if you want to apply for a loan or a mortgage.

In general, credit card PCI compliance offers protection against fraud and assures the customers of your reliability and the fact that their personal data will be processed safely. In any case, a customer won’t be liable for any unauthorized charges. That’s why we’ll devote this article to the PCI Compliance topic. We will speak on the general meaning, some common PCI requirements for small business, the levels of compliance, tokenization solutions, and many more.

So, let’s start from the beginning. If you take credit cards, you must be PCI compliant. PCI compliance is required by all organizations that process, store, or transmit credit card information. This includes businesses of all sizes, from small mom-and-pop shops to large corporations.

PCI compliance is not optional — it’s mandatory. And there are serious consequences for businesses that don’t comply. If you’re found to be non-compliant, you could be fined by your credit card processor or even lose the ability to accept credit cards altogether. We will speak about it later in more detail.

Simply put, it’s a set of security standards that all businesses must meet in order to process credit cards safely and securely. The term “PCI” comes from the name of the committee responsible for developing these standards, the Payment Card Industry Security Standards Council (PCI SSC). This group describes them as a set of data security requirements and practices that can be applied to any organization involved in storing, transmitting, or processing credit cards. These security requirements are broken down into 12 main areas. It’s important to understand that PCI compliance doesn’t just address credit card data; it also covers storing other types of sensitive data such as social security numbers and employee personal information.

So, if your organization processes, stores, or transmits credit card data, you need to be aware of PCI compliance. Originally, the PCI security standards were designed to reduce credit card fraud and help you meet this requirement. If you need assistance, contact your provider or a qualified security organization.

As we have already said, the PCI Data Security Standard addresses 12 main areas of concern:

  1. Protect cardholder data.
  2. Maintain a vulnerability management program.
  3. Implement strong access control measures.
  4. Encrypt transmission of cardholder data.
  5. Use and regularly update anti-virus software.
  6. Develop and maintain secure systems and applications.
  7. Restrict access to cardholder data by business need-to-know.
  8. Assign a unique ID to each person with computer access.
  9. Restrict physical access to cardholder data.
  10. Track and monitor all access to network resources and cardholder data.
  11. Regularly test security systems and processes.
  12. Maintain a policy that addresses information security for all personnel. This policy should include procedures for detecting security breaches and reporting security violations to the appropriate individuals.

Small businesses are not exempt from PCI DSS requirements and must take steps to secure cardholder data. For small businesses with no more than 10 employees, PCI DSS includes the following requirements: Install and maintain a firewall configuration to protect cardholder data. Protect stored cardholder data. Protect transmitted cardholder data. Maintain an information security policy. Regularly test security systems and processes. Maintain a vulnerability management program. Protect all systems against malware and regularly install security updates. Maintain an information security program. Maintain a policy that addresses information security for employees. Implement strong access control measures. Use and regularly update anti-virus software or programs. Develop and maintain secure systems and applications. Restrict access to cardholder data by business need-to-know. Implement strong access control measures. Restrict physical access to cardholder data. Track and monitor all access to network resources and cardholder data. Regularly test security systems and processes. Maintain a vulnerability management program.

And a fine for non-compliance is a serious thing. Nasdaq has paid a $10 million civil monetary penalty and implemented a comprehensive information security program to settle charges brought by the Securities and Exchange Commission (SEC) relating to two separate data breaches that occurred in 2013 and 2014. The SEC’s Order finds that Nasdaq failed to safeguard its systems and failed to implement policies and procedures reasonably designed to protect the security, confidentiality, and integrity of nonpublic information. Nasdaq also failed to promptly disclose the data breaches once they were discovered.

There are four levels of compliance, depending on the volume of transactions a company processes per year: Levels 1, 2, 3, and 4. Levels 1 and 2 are required for merchants accepting credit cards, while Levels 3 and 4 are designed for organizations that process, store or transmit cardholder data on behalf of another organization.

PCI
Depositphotos

To be fully compliant, an organization must successfully complete and document a vulnerability scan, penetration test, and annual self-assessment of the PCI DSS compliance program. Although PCI DSS compliance is a requirement for all merchants, it’s not uncommon to find organizations that haven’t completed a self-assessment in years. For example, in recent years, e-commerce has become increasingly popular as more and more people shop online for items. However, many e-commerce companies ignore PCI DSS compliance, which could put customers at risk. Still, if a breach occurs, the e-commerce company will be liable. A good example of an e-commerce company that ignored PCI DSS compliance is Target. In 2013, Target lost the credit card information of 110 million customers to hackers who accessed their system through a third-party vendor. So, it’s better not to repeat their mistake.

While the cost of PCI compliance can be high, there are several strategies that businesses can use to minimize the cost.

One way to reduce the cost of PCI compliance is to use a self-assessment questionnaire. This questionnaire can be used to determine which parts of the PCI DSS apply to your business. By only implementing the required controls, you can save on both the upfront costs and the ongoing costs of PCI compliance. The questionnaire covers twelve key areas of PCI compliance, and businesses can use it to identify areas where they need to make improvements.

Another way to reduce the cost of PCI compliance is to outsource your payment processing. This can be done through a service provider or a payment gateway. By outsourcing your payment processing, you remove the burden of PCI compliance from your own internal IT staff.

And the last important thing we would like to discuss is tokenization. In the context of PCI compliance, tokenization can be used to store credit card numbers in a secure way. It replaces the sensitive data with a random string of characters, called a token, which has no value outside of the system. This makes it much more difficult for malicious actors to access credit card numbers. It’s common for third-party payment services to use tokenization to store credit card numbers in a database. Whenever a credit card is needed for any transaction, the tokenized value is used. The tokenized value can be stored in the database, or it can be stored in a file on the server. The implementation of tokenization varies depending on the third-party payment service provider and the type of database that is being used.

So, to conclude, PCI compliance can be costly and time-consuming, but it is an important part of protecting your customers’ credit card data. Organizations that fail to comply with the PCI security standards can be fined and may even lose their ability to process credit card payments. You definitely don’t need such problems. So be attentive, protect the data, and comply — then everything will be alright. Good luck!

The post PCI Compliance for Businesses: Everything You Have to Know appeared first on Home Business Magazine.

Original source: https://homebusinessmag.com/management/operations/pci-compliance-businesses-everything-know/

How Much Do Electric Cars Actually Cost?

Home Business Magazine Online

Technology has seen so many improvements in the past few years. Various enhancements have been made to existing technology to develop better and improved tech. One of the most significant technological advancements is the electric car. The introduction of the electric car to the world marks a milestone in technological advancement.

Electric vehicles are built differently from regular cars and run on electricity rather than the usual petrol or diesel. This leads to differences in the price of the two types of cars. When electric vehicles initially hit the market, they were more expensive than regular cars. However, that is rapidly changing.

Over the years, more companies have been involved in the electric car business, and electric car prices are becoming closer to gas-powered vehicles. Electric cars like the Hyundai Kona SUV have a price range around the same as some gas-powered cars. However, what are the hidden costs involved with electric vehicles?

Costs That Come with Electric Cars

People often think the price tag attached by car companies is the exact amount they must spend. This is very incorrect and can lead to unexpected expenses later on. Traditional electric cars usually have a higher company price tag than gas-powered cars.

However, there are many things to consider other than just the price tag attached by the car company. Someone who owns a gas-powered car will have to pay for maintenance, oil changes, and fuel. Likewise, an electric car owner will also have to incur additional costs apart from the price attached by the company.

An electric vehicle also requires a power source to function. The cost of charging and maintenance must also be considered when buying electric cars. The general costs that are involved with electric vehicles include:

  • The price tag that the company attaches;
  • Government incentives;
  • Electricity costs when charging;
  • Maintenance and repair costs; and
  • Cost of installing a home charging station.

Company Purchase Cost

Different companies attach different price tags to their electric vehicles. The prices linked to electric cars differ according to their function and the car brand. Some electric cars have their prices on par with well-known luxury vehicles, while some are less expensive, such as the Nissan Leaf.

Electric car companies like Tesla have electric cars costing more than fifty thousand dollars. Some other car companies have electric vehicles that don’t cost more than twenty-eight thousand dollars. The price attached by the company usually depends on the type of materials and parts used to construct the car.

In some countries, the government incentivizes individuals who buy electric cars. You can become eligible for a tax credit of about $7,500 if you buy an electric vehicle in the United States. However, this is only available for the company’s first two hundred thousand cars. Some of the more popular car companies have already met this limit.

The Cost of Charging

Charging cost is something significant to an electric car owner. It is one of the significant costs involved with purchasing an electric car. An electric vehicle can be charged at a public charging station or at a home station. It is hard to track the amount spent on charging the electric car.

The price of electricity in your location determines a lot when it comes to the charging cost of an electric car. Electric car charging stations have different levels, which also have varying prices. The cost of charging at a level 3 DC fast-charging station will be much higher than at a level 2 charging station.

Setting up your own charging station at home usually ranges between $200 and $1000. There will also be additional charges for installation, which further jack up the price. However, a home charging station is more cost-effective over time than a public one.

Energy Expenditure

Different electric cars have varying energy consumption. Some electric vehicles can move 100 miles relying on 21 kWh of electricity, while some require 33 kWh to cover the same distance. Once the energy in the car is depleted, it has to be recharged before it can be used again.

Electric cars are rapidly becoming a regular part of society. Many individuals prefer electric cars to standard gas vehicles. They are friendlier to the environment and easier to maintain than gas cars.

Most electric cars cost as much as luxury cars, while some can be bought at lower prices. Different factors also add and subtract from the total cost of electric vehicles, such as government incentives, charging costs, and maintenance fees.

The post How Much Do Electric Cars Actually Cost? appeared first on Home Business Magazine.

Original source: https://homebusinessmag.com/businesses/go-green/how-much-electric-cars-cost/

Tips for Handling Restraining Order Hearings

Home Business Magazine Online

If you have filed a case for getting a restraining order, you may be worried about the procedure and the things which take place in the court. However, some level of nervousness and worry is normal. Therefore, you should consider hiring a lawyer for your case. They help in preparing all the technical aspects of the case and guide to handling hearings as well. Furthermore, a lawyer will guide you on each step so you do not commit any mistakes.

Here are some tips for court hearings that can help you.

Avoid panicking

It is human behavior to fret or get nervous in cold settings. However, panicking will lead you nowhere. You may end up doing things that can harm your case and ruin your representation in court. A lot of court proceedings take place on a virtual basis as well. Always make sure to consult with the jurisdiction of your area about the details of your hearing and whether it is virtual or in person.

Seek guidance from advocates and legal experts

The state coalitions have a team of attorneys and professionals answerable to victims considering getting a restraining order. If you are stuck and confused about an issue, it is suggested to consult them and research the particular issue before you go for the court hearing. You can also see the guidance of domestic violence shelters present in your locality and their legal team for guiding you in the process. They generally have all the necessary information and details for preparing legal representation in a court hearing. You can seek their help to collect necessary information about the case and what to expect from the hearing.

Get all your documents ready

The legal procedures have an extensive amount of paperwork. However, it is necessary to take them seriously and file them with the help of a legal expert. Make sure to complete all the forms and paperwork in advance so that you do not have to worry about the end moment.

Collect proof and witness testimonies

A case becomes stronger if it is backed up by substantial proof and statements from witnesses who can confirm the abusive conduct which took place with the victim. The witnesses can be family members, kids, law-enforcement officers, medical providers, or coworkers. Other proof of the abuse includes photographs, videos of injuries and broken things, medical records, police reports, call recordings, text messages, etc. These sources of evidence help establish the abuse that took place and the victim’s innocence.

The post Tips for Handling Restraining Order Hearings appeared first on Home Business Magazine.

Original source: https://homebusinessmag.com/management/legalese/tips-handling-restraining-order-hearings/

Popular On-Demand Home Services Startups You Should Know About

Home Business Magazine Online

On-demand services give customers the ability to get almost any service they want, when they want it — no more waiting weeks or months to get that repairman or plumber to come out to your home. Take note of these five popular on-demand home services startups, as this industry looks set to skyrocket over the next few years.

Handy

Started in 2012, Handy is one of the most popular on-demand home services startups. The company connects customers with vetted and insured professional house cleaners, handymen, and more. With a simple to use mobile app, users can find local professionals to book appointments.

The best part? If you ever had an unsatisfactory experience with a pro on Handy’s platform, you can write a review that reflects their performance. There are no limitations as to how many reviews they may have on the site. If you’re looking for a reliable plumber, Handy also partners with HomeAdvisor which has been ranked among Inc.’s 500 Fastest Growing Companies in America for two years running. For those who want less hassle when booking all types of household services, this service makes it easy for people to schedule different types of projects without having to make multiple calls or emails.

Eco Tech

We’re all trying to make life easier, and the on-demand services industry has certainly helped. There are tons of apps out there that let you order anything from a ride to dinner to even someone to clean your house. So what’s new? Well, a few new on-demand home services startups have cropped up in recent years, each with its own twist on the model. One such example is Eco Tech Maids.

Founded in 2011 by Lynsie Campbell, EcoTech Windows & Doors is one company that has built an exceptional reputation.

Move Clean

The company was founded in 2011, and provides housekeepers to the public with a variety of different packages. MoveClean is available in over 200 cities, and has a rating of 4.7 stars on Yelp. The company’s motto is We’re Your Cleaning Concierge.

Fixer

The idea for Fixer came from CEO and founder, Johnathan, after he had to clean up his dad’s new house before they moved in. With the help of some friends who are designers, they created the website and launched it in September 2013. They also offer a professional design service that you can pay extra for if you’re not confident with your own designs or just want someone else to do all the work.

Hometalk

The company was founded by CEO Alexi Wellman after she successfully managed every step of her own remodel from start to finish. She believes that with the right tools and resources, homeowners can take control of their projects, with confidence and without stress. Hometalk is on a mission to make DIY accessible to everyone with smart home products, in-depth tutorials and expert advice.

The post Popular On-Demand Home Services Startups You Should Know About appeared first on Home Business Magazine.

Original source: https://homebusinessmag.com/businesses/business-spotlights/popular-on-demand-home-services-startups-know/

Join the webinar: ‘Lotame Accelerate: The (R)evolution of Customer Data in 2023’ by Lotame

Alexandra Theriault

Having first-party data is only half the battle for marketers. As you consider the 2023 roadmap, it’s critical to understand what’s possible with the customer data you do have, which partners add measurable value and how to implement successful data strategies. Register today for Lotame Accelerate: The (R)evolution of Customer Data in 2023 to learn from experts about how to connect your own customer data dots and build a winning product roadmap.

In this inaugural Lotame Accelerate webinar series, you’ll: 

  • Hear from an interactive panel of industry experts, covering topics ranging from customer data strategies to identity, clean rooms to modeling and data enrichment.
  • Get a sneak peek into some exciting developments around Lotame’s emerging customer data capabilities, including a teaser of a BIG REVEAL coming in January 2023.

Speakers include: 

  • Andy Monfried, CEO and co-founder, Lotame
  • Eliza Nevers, chief product officer, Lotame
  • John Spencer, director of digital strategy, Zion & Zion
  • Alexandra Theriault, GM, Spherical, Lotame
  • Bob Walczak, CEO, MadTech Advisors

Join Lotame on Wednesday, November 30, at 11:30 a.m. EST for the live webinar or access the recording following the event. If your timezone is not compatible, register anyway to automatically receive the recording!

The post Join the webinar: ‘Lotame Accelerate: The (R)evolution of Customer Data in 2023’ appeared first on Search Engine Land.

Original source: https://searchengineland.com/join-the-webinar-lotame-accelerate-the-revolution-of-customer-data-in-2023-389651

Shopify is testing a new universal search feature

Google may have a new shopping competitor on its hands. Shopify is testing a new feature in its app that allows customers to search across all merchants on the platform.

How it works. The new “Search for anything” search box enables you to search for items previously purchased, merchants matching the search term, and products sold by any Shopify merchants.

Thanks to Glen Gabe for pointing this out to us on Twitter.

The new Shopify marketplace. It seems that Shopify has changed its viewpoint on whether or not to become a marketplace. In 2021, Shopify’s president Harley Finkelstein said it did not have plans to be a marketplace. But with their new search test, they are, in fact, becoming a marketplace.

The test is rolling out to a limited number of users. We have no word on who will have access to the search feature, how long it will run, or if it will ever be released globally. “Current and former Shopify employees said it was unclear whether the company would ever roll it out to a wider audience, as internal debate continues about whether the feature would hurt merchants,” says Madeline Stone at Business Insider.

Why we care. The new universal search feature could mean that Shopify merchants will need to start paying to appear first in search results or start planning their SEO strategy. Furthermore, app users and shoppers will only see results from stores on the app, which could limit the options shown for certain products. This may not be an issue, though, since there are over 4 million stores built on the platform. It may also entice sellers to move their stores from other ecommerce platforms.

The post Shopify is testing a new universal search feature appeared first on Search Engine Land.

Original source: https://searchengineland.com/shopify-is-testing-a-new-universal-search-feature-389739

5 Ways to Make Cash on the Side

Home Business Magazine Online

In this financial climate, it can be really difficult to make cash that will cover monthly expenses. Many people end up getting a second, or even third job just to pay the bills.

Making cash on the side is a more passive way to earn income, and therefore, can be done in conjunction with full-time jobs. Here are five ways to earn extra income.

1. Invest

If you’re playing a more secure, long-term game, it can be important to make some smart moves, so that you can grow your wealth passively. A small investment could make a big difference to your ability to earn extra money.

Many types of investments can include bank investments, insurance investments, stocks, and more. Another great option lies with less conventional methods. Check out this list of alternative investments to see what might be right for you.

2. Monetize Your Hobby

Turning your hobby into a bit of extra profit may not be ideal if you wish to keep it separate from your work life. However, if you have a special skill like painting, music, crafting, etc, it can be a great way to add a little extra cash to your weekly budget.

You may try selling your art on a handmade website like Etsy. This way you just post your product and leave it be until somebody buys it.

Also, teaching is another great way to add income. Do you have some skills that you could teach?

3. Downsize

Downsizing is never ideal, but sometimes it can be an opportunity to sell some unwanted belongings and conserve money at the same time. With nearly 46% of Americans having financial issues, it’s no surprise that 35% of them sell belongings to deal with financial disruption.

You may consider selling items you don’t need or don’t use frequently. This doubles as a refreshing cleanout of your home. Then, consider ways to simplify your lifestyle.

For example, this could mean moving to a smaller living space, or cutting out small daily purchases. While downsizing isn’t ideal, it does offer an immediate sigh of relief during financial hardship.

4. Sitter Jobs

This one is more common and, conversely, more flexible. Pet sitters, babysitters, and house sitters can build a reputation by being efficient and reliable. If you’re great with animals, consider being a pet sitter or dog walker. If your specialty is children, seek out babysitting jobs.

Consider distinguishing yourself from other sitters by getting certified in CPR for children, by learning about the medical needs of pets, and offering cleaning or other additional services for houses. Having this experience under your belt will help you stand out among the competition.

5. Rent Out an Extra Room

If you have extra space in your house or apartment, consider renting out a room. You could offer it as an AirBnB, or offer it to more long-term renters.

In the case of long-term renters, you should be prepared to have a roommate if you are still living in the house. However, you may have to act as a landlord if you own a house but are not living in it.

In the case of offering a room as an AirBnB, be sure to make your AirBnB competitive with others like it by making sure it’s clean and well-maintained, and that you are readily available for assistance.

Try These Methods Today!

One final piece of advice: the best thing you can do is start now! You may not think it will be fruitful right away, but slow and minuscule progress financially is better than none at all. Therefore, make today the day that you take control of your finances.

The post 5 Ways to Make Cash on the Side appeared first on Home Business Magazine.

Original source: https://homebusinessmag.com/businesses/business-opportunities/5-ways-make-cash-side/

15 ways to secure your WordPress site

As a marketer, SEO or web developer, you know how important it is to keep your WordPress site secure. 

From using strong passwords and updating plugins to installing a security plugin and monitoring traffic, these tips will help you keep your site safe from hackers. 

Why security matters for SEO

Website security is often overlooked. However, site security is essential for SEO and digital marketing.

WordPress is the most popular content management system (CMS), powering millions of websites. 

However, WordPress sites are also susceptible to attacks which can lead to: 

  • Site hijacking.
  • Malware injection.
  • Phishing scams.
  • And more.

All of these can damage your reputation, hurt your SEO, and cost you money. That’s why it’s important to take proactive steps to secure your WordPress site.

There are a number of reasons why WordPress is a target for hackers. 

  • Because the CMS is so popular, there are more potential targets. 
  • As it is open source, the code is available for anyone to view and study. This makes it easier for hackers to find vulnerabilities. 
  • Due to its ease of use, many people don’t take the time to properly secure their WordPress site. 

As a result, hacked WordPress sites are a major source of malware and spam.

Why security matters for WordPress

WordPress’s large user base makes it a prime target for hackers.

Malware, backdoor and SEO spam issues account for the leading types of attacks across WordPress, according to Sucuri. 

What’s most relevant to SEO is how attackers are using WordPress websites to steal traffic for their own nefarious means. Typically, the methodology is to redirect traffic away to a malicious website or inject spam links on your website.

This not only benefits the attacker but can also damage your website’s reputation and potentially harm your user base. 

How to secure your WordPress site

Let’s dive right into the fun bits of how you can get right into securing your WordPress site.

The majority of these tactics are completely free and require minimal technical expertise.


Get the daily newsletter search marketers rely on.

<input type="hidden" name="utmMedium" value="” />
<input type="hidden" name="utmCampaign" value="” />
<input type="hidden" name="utmSource" value="” />
<input type="hidden" name="utmContent" value="” />
<input type="hidden" name="pageLink" value="” />
<input type="hidden" name="ipAddress" value="” />

Processing…Please wait.

function getCookie(cname) {
let name = cname + “=”;
let decodedCookie = decodeURIComponent(document.cookie);
let ca = decodedCookie.split(‘;’);
for(let i = 0; i <ca.length; i++) {
let c = ca[i];
while (c.charAt(0) == ' ') {
c = c.substring(1);
}
if (c.indexOf(name) == 0) {
return c.substring(name.length, c.length);
}
}
return "";
}
document.getElementById('munchkinCookieInline').value = getCookie('_mkto_trk');


1. Add a CDN-level firewall

Any website is susceptible to attack from bots and other malicious actors. A distributed denial of service (DDoS) attack can overload a server with requests, causing it to crash and making the site inaccessible. 

A CDN-level firewall adds an additional layer of security by identifying and filtering out suspicious traffic before it reaches the server. This can help to protect your site from DDoS and other bot attacks. 

In addition, a CDN-level firewall can also improve the performance of your website by caching static content and delivering it more quickly to visitors. As a result, adding a CDN-level firewall is an effective way to secure your website and improve its performance.

2. Change your login page URL regularly

Regularly changing your login URL may seem like a small security measure, but it can actually deter hackers from finding easy access to your website. 

By constantly changing your login URL, you make it more difficult for hackers to guess or brute force their way into your site. 

There are ways to change the URL manually, but most hosting providers recommend using plugins to manage this.

3. Add a JavaScript challenge to your login page

Adding a JavaScript (JS) challenge to your login page will help ensure that only authorized users, not bots, are able to access your site. 

When enabled on the page, it serves as a security check to validate that the request is coming from a browser capable of executing JavaScript. 

The challenge requires no interaction from the user but adds a short delay (less than five seconds) until the browser finishes processing the JavaScript.

4. Limit login attempts

It is crucial to limit the number of allowable login attempts to deter hackers from using brute force methods and gaining access to accounts. Doing so makes it more difficult for hackers to guess your password and prevent them from accessing your account even if they have your username. 

In addition, limiting login attempts helps to protect your account from being locked out if someone else tries to guess your password. 

5. Secure all passwords and enable two-factor authentication

Another way to make your WordPress site more secure is to improve the difficulty of your passwords and enable two-factor authentication.

Passwords are often the first line of defense against hackers, so it’s important to choose ones that are hard to guess. A good password should be at least eight characters long and include a mix of letters (uppercase and lowercase), numbers, and symbols. Avoid using easily guessed words like “password” or your birthdate. 

Two-factor authentication (2FA) adds an extra layer of security by requiring a second form of identification, such as a code sent to your mobile phone, email address or authenticator app before you can log in. This makes it much harder for hackers to gain access to your site even if they know your password.

6. Remove XML-RPC.php

A simple measure to secure your WordPress site is to remove the XML-RPC.php file. This file allows anyone to remotely access your WordPress site, which can give hackers the ability to inject malicious code or take over your site entirely. 

Additionally, attackers can conduct brute-force login attempts through this file, so even if you secure your login page, attackers can gain access through it.

Fortunately, removing the XML-RPC file is a relatively straightforward process. Simply connect to your site via FTP and delete the file from your server. Once you have done this, be sure to update your .htaccess file to prevent any further access to the file.

7. Remove WP and plugin versions

Hackers are always finding new ways to exploit vulnerabilities and break into websites. That includes looking at the WordPress and plugin versions you are using.

If you are running an outdated version, it may have known security issues that can easily be exploited. That’s why you must keep your WordPress installation and all plugins up to date. 

That said, zero-day exploits exist and knowing which version of a plugin or WordPress core you’re using can clue in hackers how to gain access to your website.

8. Disable comments

The comment section is among the most vulnerable parts of any website. As this section is often left unmoderated, it can be easy for hackers to insert malicious code into otherwise innocent-looking comments. 

As a result, website owners need to be vigilant in moderating the comment section and ensuring that only safe content is allowed. 

9. Reduce plugins

Having too many plugins – or worse, unused and duplicate plugins – can actually jeopardize the security of a WordPress site. That’s because each plugin represents a potential point of entry for hackers. 

By reducing the number of plugins on a WordPress site, owners can help to reduce security risks. It can also help to improve site performance by reducing the number of requests that the server has to process. 

10. Set up auto-update on plugins

Using WordPress’s native auto-update feature is a straightforward way to ensure that all installed plugins and themes are up to date. 

This is especially important for plugins and themes that handle sensitive data, such as credit card information or personal records. In addition to security benefits, auto-updates also ensure that all installed software is compatible with the latest version of WordPress – improving your site’s stability. 

11. Check open ports on the server

While open ports on a web server may offer some advantages, they also create security vulnerabilities that can be exploited by hackers. 

To determine if there are any vulnerable ports on your server, run an Nmap scan. If you discover any open ports, work with your web hosting provider to close or filter them. 

A safer option would be to work with a notable WP-managed hosting provider who locks down their ports. 

12. Ensure SSL is set up properly

SSL certificates are an important part of website security. They encrypt communication between a website and its visitors, making it difficult for hackers to intercept data. 

However, SSL certificates can be vulnerabilities in themselves if not properly configured. Outdated or unpatched SSL certificates can be exploited by hackers, allowing them to gain access to sensitive information. Renewing SSL certificates regularly ensures that they are up to date and less likely to be exploited. 

In addition, setting up SSL certificates properly in the first place can prevent potential vulnerabilities. For example, ensuring that only strong cipher suites are used can make it more difficult for hackers to crack the encryption. 

13. Add security headers

Security headers prevent malicious code injection and mitigate the risk of cross-site scripting attacks. Adding them also helps block payload-based attacks and reduce the chances of your site being compromised by malware. 

Some types of security headers I recommend adding to your website include:

  • Referrer policies.
  • HTTP Strict-Transport-Security (HSTS).
  • A content security policy.
  • X-Frame options.
  • X-Content-Type-Options.
  • Cross-site scripting (XSS) protection.

14. Set up daily backups

Any website owner knows that there is always a risk of data loss due to hacking, power outages, or other unexpected events. That’s where daily backups come in handy. If your site does get compromised, you will have a fallback option that you can use to restore your site. 

There are many different ways to create backups, but a popular method is to use a WordPress plugin. However, I recommend working with a web host that takes automatic daily backups for you as part of their core services.

15. Run final security tests

Before you can relax and enjoy your newly secured WordPress website, there’s one last step you need to take: run a final security scan to check for any vulnerabilities that might have been missed. 

There are many different security scans available, both free and paid. Which one you choose is up to you, but it’s crucial to make sure the scan you choose is comprehensive. 

Once the scan is complete, take a close look at the results. If any vulnerabilities were found, take steps to fix them right away.

Secure your WordPress site for better search performance 

By following these 15 steps, you can help to secure your WordPress website and protect your data. While no system is 100% secure, these steps will make it much harder for hackers to gain access to your site. 

In addition, be sure to keep all software up-to-date, as security patches are released regularly. 

Finally, run regular security tests on your site to ensure that new vulnerabilities have not been introduced. By taking these precautions, you can help keep your website safe from attack.

The post 15 ways to secure your WordPress site appeared first on Search Engine Land.

Original source: https://searchengineland.com/wordpress-site-security-389655