{"id":308,"date":"2020-01-01T07:07:54","date_gmt":"2020-01-01T15:07:54","guid":{"rendered":"https:\/\/www.inetxsys.com\/articles\/index.php\/2019\/04\/26\/bs-how-can-i-get-my-business-to-show-up-on-local-search\/"},"modified":"2020-01-14T00:15:01","modified_gmt":"2020-01-14T08:15:01","slug":"web-hosting-security-best-practices-2020","status":"publish","type":"post","link":"https:\/\/www.inetxsys.com\/articles\/web-hosting-security-best-practices-2020\/","title":{"rendered":"Web Hosting Security Best Practices (2020)"},"content":{"rendered":"<p>When we think about website security, the\u00a0highly publicized breaches of major companies\u00a0come to mind. Multimillion-dollar security leaks involving exposed credit card information, login credentials, and other valuable data are covered extensively by the media, leaving one to believe only large-scale businesses are susceptible to online security risks<\/p>\n<p>Don\u2019t be fooled. Security standards are vital to the well-being of any website, large or small. That\u2019s why site owners are often bombarded by warnings of security risks in tandem with the sales pitches of many hosting providers. How do you separate the sales hype from the real risks?<\/p>\n<p>Education is the first step to protecting your online brand. Here, I\u2019ll cover some best practices to follow in your website management operations, as well as some key security features to look for in a prospective web hosting company.<\/p>\n<h3 id=\"backups\">1. Backups and Restore Points<\/h3>\n<p>People often overlook\u00a0backups as an element of security. Backups both provide and require security. Backups must be kept in a secure location away from the main server, following the other security steps we will outline. A secure backup provides a trusted repository for the latest copies of the system and data that can be deployed to restore a known, clean system to operation.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-367 size-full\" src=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/Website-Backups.jpg\" alt=\"\" width=\"694\" height=\"298\" srcset=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/Website-Backups.jpg 694w, https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/Website-Backups-300x129.jpg 300w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/p>\n\t<blockquote class=\"bs-quote bs-quote-19 bsq-t1 bsq-s17 bsq-left\">\n\t\t<span class=\"bsq-edge\"><\/span>\n\t\t<div class=\"quote-content\">\n\t\t\t<p>I wouldn\u2019t worry about going ahead and disavowing links even if you don\u2019t have a message in your Webmaster console.<\/p>\n\t\t<\/div>\n\t\t\t\t\t<div class=\"quote-author clearfix\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" class=\"quote-author-avatar\" src=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/seo-news-quote-avatar.png\"\/>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<span class=\"quote-author-name\">\t\t\t\t\t\t\t\t\t\t\tMatt Cutts\t\t\t\t\t\t\t\t\t\t<\/span>\t\t\t\t\n\t\t\t\t\t\t\t\t\t<span class=\"quote-author-job\">American Software Engineer<\/span>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/blockquote>\n\n<p>It is important to ask about a hosting company\u2019s backup schedule and restore policies. For example,\u00a0<a href=\"http:\/\/www.wpwebsitecoach.com\/how-often-do-you-backup-your-website\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">how frequently are backups conducted<\/a>\u00a0\u2014 weekly, monthly, or daily? Will the support reps help you restore your site from backup files, or are the backups intended for their use only? Will the team find and restore lost or corrupted files or will they only do a complete replacement from a recent backup? Will the hosting service only use the most recent backup or can you request restores from further back in time, and if that\u2019s the case, how far back in time can you go?<\/p>\n<h3 id=\"monitoring\"><\/h3>\n<h3 id=\"monitoring\">2. Network Monitoring<\/h3>\n<p>Does the hosting provider <a href=\"https:\/\/www.alertra.com\/articles\/web-host-strategies-for-server-monitoring\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">monitor the internal network for intrusions and unusual activity<\/a>? Diligent monitoring can stop the server-to-server spread of malware before it gets to the server hosting your site. Ask for some details on how the support team monitors the network, whether the staff is dedicated to this function, and what the engineers look for. SolarWinds\u2019s <a title=\"\" href=\"https:\/\/www.hostingadvice.com\/external\/?site=3d038eab489508bfdaf394a23583abde5f5327ab653b4ba7605b713deb45a7d73b5755bf415ec202d9bf88bdf540fe66aa8a174c92862b171f4847995f9cce4a\" target=\"_blank\" rel=\"noopener noreferrer\">guide to network monitoring best practices<\/a>\u00a0details several procedures and policies that any good network management team should follow.<\/p>\n<h3 id=\"ssl-firewalls-ddos\">3. SSL, Firewalls, and DDoS Prevention<\/h3>\n<p><a href=\"http:\/\/www.digitalattackmap.com\/understanding-ddos\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Distributed-Denial-of-Service (DDoS) attacks happen<\/a>\u00a0when an overwhelming amount of traffic is sent to your site, rendering it useless to visitors. Prevention starts at the edge of the network with a good firewall. However, there are\u00a0<a href=\"https:\/\/blog.radware.com\/security\/2013\/05\/can-firewall-and-ips-block-ddos-attacks\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">limits to how well a firewall stops DDoS attacks<\/a>.<\/p>\n<p>Can your provider give you some sense of what intrusions the company\u2019s firewalls are likely to stop and what other measures the security team employs? If you have a plan in which you manage your own server, you will need to know how to augment what the hosting service provides. At what stage will the network monitoring folks inform plan owners of potential problems that might affect their site?<\/p>\n<p>Does the provider make SSL certificates available? It will be your responsibility to implement SSL, but you can\u2019t if it is not available.<\/p>\n<h3 id=\"malware\">4. Antivirus and Malware Scanning and\/or Removal<\/h3>\n<p>You should understand which protective actions your hosting provider will perform and what you must do on your own to protect your website. Does the support team run scans on the files in your account, and can you see the reports? If your account becomes infected, does the support plan include help in identifying and removing the malware? The server security steps we describe starting with step 6 will take you a long way toward keeping malware off your website.<\/p>\n<h3 id=\"disaster-recovery\">5. High Availability and Disaster Recovery<\/h3>\n<p>Look for a hosting company that will\u00a0keep your site running with 99.9% uptime or better. This goes beyond file-level backups. Is a bare-metal image available for your server? This is a complete copy of a clean, functioning server operating system for a speedy recovery from system failures.<\/p>\n<p>The host\u2019s network should have redundant hardware to guard against downtime caused by hardware failures. Firewalls can be configured to run in pairs, with each one ready to take over the full load in case the other one fails. The same concept extends to servers.\u00a0<a href=\"http:\/\/www.internet-computer-security.com\/Firewall\/Failover.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Hardware failover<\/a>\u00a0is an important component of high-availability networks.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-370 size-full\" src=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/rack-servers1.jpg\" alt=\"\" width=\"700\" height=\"245\" srcset=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/rack-servers1.jpg 700w, https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/rack-servers1-300x105.jpg 300w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/p>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Load_balancing_(computing)\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Load balancing is another high-availability feature<\/a>. In this case, multiple servers are ready to handle server traffic. They all work with the same copy of your website data stored on a network shared drive and hand off traffic to each other so that no one server becomes overburdened.<\/p>\n<div class=\"h2-header\">\n<h2 id=\"servers\">Server Security Best Practices<\/h2>\n<div class=\"ret-sprite watermark\"><\/div>\n<\/div>\n<p>If you have a plan that provides a server without management support, you may have to do some or all of this on your own. If your plan does include some degree of hardware and\/or software management support, the following will give you an idea of which questions to ask or what the support people are talking about.<\/p>\n<h3 id=\"server-access\">6. Access and User Permissions<\/h3>\n<p>At the host level, access means physical access to the machines, as well as the ability to log into the server. Physical access should be limited to trained technicians with security clearance.<\/p>\n<p>You and your host company should use Secure Socket Shell (SSH), or equivalent, to log into the server to maintain the operating system (OS) or the website. For extra security, use RSA keys protected by a passphrase.\u00a0<a title=\"\" href=\"https:\/\/www.hostingadvice.com\/external\/?site=882f788a96a4f71d91fd96952c03b43930d2280bf44e07fbbe302966f6be0d36a226f2e7711fee42675078523d1e55f1cfe223595e0c1fa5bdd330d5d3808e4e483c9ec82a1e624ad03dbde225eb1e22\" target=\"_blank\" rel=\"noopener noreferrer\">Digital Ocean<\/a>\u00a0and\u00a0<a href=\"https:\/\/support.rackspace.com\/how-to\/logging-in-with-an-ssh-private-key-on-windows\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Rackspace<\/a>\u00a0both have tutorials on how to do this.<\/p>\n<p>Another good security step is to whitelist IPs that are allowed to access the server for maintenance. This can be done and modified through the hosting company\u2019s control panel provided for your account. You should also disable logins from the user root. Malicious players will commonly attempt to exploit this access point because the root user has full administrative privileges. You can always give equivalent permission to authorized admin logins.<\/p>\n<p>Files are protected by file permissions. Incorrect permissions cause time-consuming errors, and it is tempting to fix these errors by granting full permissions to all files. Don\u2019t do this. It gives any criminal hacker full control of your system if they get in.\u00a0<a title=\"\" href=\"https:\/\/www.hostingadvice.com\/external\/?site=882f788a96a4f71da7be96990277b99fe9cb89d1c8b4c2c8898ec1abbcb3b61e99fe056b5a4436f8caf1c06284b16f5972c4d87a1e7c2a33399a36b6455471c7b4c2924959126d1bbd92dd08f0fdb1c4\" target=\"_blank\" rel=\"noopener noreferrer\">Sucuri\u2019s guide to website security<\/a>\u00a0includes a primer on correct file permissions.<\/p>\n<h3 id=\"file-management\">7. File Management<\/h3>\n<p>All access to your server is remote. No one will go to the server to add, remove, or move website content files. You should use secure FTP (SFTP) with a secure and robust password for all file transfer and maintenance while also following other\u00a0<a href=\"https:\/\/www.helpsystems.com\/blog\/10-essential-tips-securing-ftp-and-sftp-servers\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">FTP and SFTP best practices<\/a>.<\/p>\n<h3 id=\"applications\">8. Applications and Logins<\/h3>\n<p>The hosting company should have a strict password policy for employees with mandatory password changes at regular intervals as well as when equipment or personnel changes. You should have similar policies for your server access passwords. Establish and enforce policies for strong passwords. Those who want to can exploit weak passwords within hours.<\/p>\n<p>Remove any unused, unmaintained apps on the server so no one can exploit unpatched vulnerabilities. Install \u2014 and maintain \u2014 utilities that monitor the server CPU, disk use, memory use, and application uptime.<\/p>\n<p>The databases on your server are potentially vulnerable targets for online criminals. UC Berkeley provides a\u00a0<a href=\"https:\/\/security.berkeley.edu\/resources\/best-practices-how-articles\/database-hardening-best-practices\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">guide to hardening databases<\/a>\u00a0against attacks.<\/p>\n<div class=\"h2-header\">\n<h2 id=\"websites\">Coding and Website Security Best Practices<\/h2>\n<div class=\"ret-sprite watermark\"><\/div>\n<\/div>\n<p>The security of your website software and data files is your responsibility, even with a managed hosting plan. As a webmaster, you are responsible for managing your content and your site\u2019s functionality. The hosting company does not know what you want on the site or how you want it to function for your site visitors.<\/p>\n<h3 id=\"site-passwords\">9. Passwords and User Access<\/h3>\n<p>At the website level, you will have passwords for people who administer the site, guest authors, and potentially website visitors, depending on the nature of the site. Establish and enforce\u00a0<a href=\"https:\/\/support.google.com\/a\/answer\/139399?hl=en\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">password strength policies<\/a>\u00a0for everyone who has backend access.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-374 size-full\" src=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/Password-security.jpg\" alt=\"\" width=\"694\" height=\"359\" srcset=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/Password-security.jpg 694w, https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/Password-security-300x155.jpg 300w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/p>\n<p>Admin staff and guest authors will need a stronger password because their accounts have a potentially greater impact on your site. Enforce changes after any suspected hacking attempt or when updating the content management system (CMS) or other software. The info@yourdomain.com address\/username is commonly attacked and should not be used. Use <a href=\"https:\/\/lifehacker.com\/5529133\/five-best-password-managers\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">secure password managers<\/a>\u00a0to generate unique complex passwords.<\/p>\n<p>Each account holder should have the fewest privileges needed to do their job. For example, never give admin privileges to a guest author. Your CMS should have a level of privileges that allows them to upload and edit their post and nothing more. Each person should have his or her own login so they are held responsible for all changes made by that account. High-level admins can monitor the activity of all accounts.<\/p>\n<p>Never allow unrestricted file uploads. Limit uploads to the types of files your users will really need to upload and exclude scripts or other executable code. An uploaded executable file coupled with poor file access settings will give an intruder instant control of your website.<\/p>\n<p>Your server config files include settings that restrict access to your files, such as browsing directories and protect folders containing sensitive information.<\/p>\n<h3 id=\"software\">10. Plugins, Software Updates, and Backups<\/h3>\n<p>Always\u00a0<a href=\"https:\/\/www.ameexusa.com\/6-reasons-to-keep-your-cms-updated\/?blogid=114\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">keep your CMS and software updated<\/a>. Latest versions are patched to fix all known security holes. Change any default settings, such as the admin login name, that individuals can find and use to break in.<\/p>\n<p><a href=\"https:\/\/www.smashingmagazine.com\/2012\/10\/four-malware-infections-wordpress\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">When installing plugins and other software, consider the code\u2019s age or the date of its last update<\/a>, as well as the number of installs. These metrics give you an idea of the safety and reliability of the product. If it is inactive, it probably has not been vetted for security holes. Be wary of the source of the download for this software. Third-party sites may have added malware to the package.<\/p>\n<p>Your website content is not secure until you have automatic, frequent, and redundant backups conducted. The\u00a0<a href=\"https:\/\/www.howtogeek.com\/219197\/youre-not-backing-up-properly-unless-you-have-offsite-backups\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">backups should be stored apart from your main server<\/a>. The idea is to protect your content against said server\u2019s potential failure. A backup that is on the server will often fail along with the server, depending on the nature of the disaster. The backups should happen frequently enough to capture changing and new content, and they should happen without needing someone to remember to start them each time. Test the backups to be sure that the system is working. Check these\u00a0<a title=\"\" href=\"https:\/\/www.hostingadvice.com\/external\/?site=882f788a96a4f71dbaf17cd0f360ec88c11b719af031abf7708996e1317fa9d4430f9c030de1478a836f5da30dcaaa2100ba2b07a1088cb2a6570b75c503014cd6a8756e9a69abb46f5d45cbd4de8488aa8a174c92862b1722d42c68a205e078\" target=\"_blank\" rel=\"noopener noreferrer\">critical website best practices<\/a>\u00a0for more ways to develop a sound backup strategy.<\/p>\n<p>If you have custom themes, plugins, or similar software, it is a good idea to keep fresh copies of the install files. If they have malfunctioned or been compromised, that problem will be saved on the backup. The install files ensure you can get back to a pristine working copy.<\/p>\n<p>Keep in mind that a backup gets your site back in a hurry, but it does not fix the underlying problem that crashed it. For example, if someone used an exploit to penetrate your site, that vulnerability still exists in the backup copy and needs to be fixed right away.<\/p>\n<h3 id=\"code-qa\">11. Code Reviews<\/h3>\n<p>A code review is\u00a0<a href=\"http:\/\/searchsoftwarequality.techtarget.com\/definition\/code-review\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">an in-depth check of an application after development is complete<\/a> and it is ready to be released. This is best done with a mix of automated tools and human inspection. The review is conducted in the full context of using the app \u2014 from login and authentication to data processing, encryption, and storage.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-376 size-full\" src=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/pexels-photo-546819.jpg\" alt=\"\" width=\"694\" height=\"461\" srcset=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/pexels-photo-546819.jpg 694w, https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/pexels-photo-546819-300x199.jpg 300w, https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/pexels-photo-546819-450x300.jpg 450w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/p>\n<p>Be wary of\u00a0<a href=\"https:\/\/www.acunetix.com\/websitesecurity\/sql-injection\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">SQL (Structured Query Language) deviously inserted into your website files<\/a>\u00a0by a third party. SQL injection is a method in which an attacker responds to an input request, such as username, with a valid SQL command. These commands can access data or delete it. Microsoft\u2019s\u00a0<a title=\"\" href=\"https:\/\/www.hostingadvice.com\/external\/?site=882f788a96a4f71dbd0dd50959c71a26fea019bef0a062237a5da2d9519396e62cce9581cfac2973681b395b7405a62f1961b369ed9a1d78bba19eadae4b8850\" target=\"_blank\" rel=\"noopener noreferrer\">guide to SQL injection describes the attacks in detail<\/a>\u00a0and suggests ways to mitigate the risk such as with the use of session variables.<\/p>\n<h3 id=\"site-encryption\">12. Encryption, Firewalls, and DDoS Protection<\/h3>\n<p>A\u00a0<a href=\"https:\/\/www.owasp.org\/index.php\/Web_Application_Firewall\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">web application firewall<\/a>\u00a0(WAF) monitors HTTP traffic to and from specific web applications. This provides more specific security than a network firewall, which does monitor HTTP, but does not understand the specific requirements of a web application. A WAF can be configured to prevent SQL injections as well as other techniques such as cross-site scripting and probing for vulnerabilities.<\/p>\n<p>Although DDoS prevention should be enacted at the network level, attackers may use one or a combination of several methods to flood your servers, and site owners must respond and protect themselves accordingly. Several noteworthy security leaders, including Cloudflare and Incapsula, offer\u00a0<a href=\"https:\/\/getvoip.com\/blog\/2016\/04\/25\/guide-to-ddos-attacks\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">advanced mitigation and prevention tools and services<\/a>\u00a0that can be employed to help keep sites safe.<\/p>\n<p>Finally, SSL (secure sockets layer) technology is required when sensitive data is transferred to and from the server. An SSL certificate does not secure your server from attacks or malware, but rather encrypts and secures communication between your server and the person using your site. By using SSL, you are securing your customer\u2019s information and\u00a0<a href=\"https:\/\/www.rapidsslonline.com\/blog\/raise-green-sign-of-trust-with-ev-ssl\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">keeping their trust in your site<\/a>.<\/p>\n<div class=\"h2-header\">\n<h2 id=\"operating-systems\">Operating System Security Best Practices<\/h2>\n<div class=\"ret-sprite watermark\"><\/div>\n<\/div>\n<p>Some of the measures that you take will depend on the operating system of your server. Web servers run either on Linux\/Unix or on Windows. You usually choose this when you choose the hosting plan.<\/p>\n<p class=\"subnav-links\"><a href=\"https:\/\/www.hostingadvice.com\/how-to\/web-hosting-security-best-practices\/#linux\">Linux Machines<\/a>\u00a0|\u00a0<a href=\"https:\/\/www.hostingadvice.com\/how-to\/web-hosting-security-best-practices\/#windows\">Windows Machines<\/a><\/p>\n<h3 id=\"linux\">13. Linux and Unix-Based OS<\/h3>\n<p>The server config file on Linux servers is called .htaccess. You can set rules in this file that prevent directory browsing and other activities that could expose sensitive information or open the server to other vulnerabilities.<\/p>\n<p>Although the PHP (hypertext preprocessor) language is more available and convenient, there are risks to using it on these servers. These OSes have a permission called executable, which means the file can execute code. It is important to limit executable commands when using PHP. This is where a code review is beneficial.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-377 size-full\" src=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/Linux-Server-vs.-Windows-Server.jpg\" alt=\"\" width=\"696\" height=\"202\" srcset=\"https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/Linux-Server-vs.-Windows-Server.jpg 696w, https:\/\/www.inetxsys.com\/articles\/wp-content\/uploads\/2019\/04\/Linux-Server-vs.-Windows-Server-300x87.jpg 300w\" sizes=\"auto, (max-width: 696px) 100vw, 696px\" \/><\/p>\n<h3 id=\"windows\">14. Windows OS<\/h3>\n<p>Windows servers have user privileges, such as executable, limited by default, and admins must enter passwords to gain high-level permissions. Security measures are guided by the Security Compliance Manager function on these servers. The config file where access restrictions are set is web.config. Microsoft provides\u00a0<a title=\"\" href=\"https:\/\/www.hostingadvice.com\/external\/?site=882f788a96a4f71db5e018ae7664fb4482401a0395dccb79ad3bab9420f3bcad738422cb52ce1d1d742d5e236e2ed56a5270ce18e3187094678db3062ed644164a93b3d6d5ac90ede0b56c798c3ddebaa8fa8cc69b3da188aa8a174c92862b1750afd61a7a84a3c65eb8c3502baf340282fa231794be38d0307e449355b68b0e4e3d6f4f82d85ce4b5b556c9d4ce65fe\" target=\"_blank\" rel=\"noopener noreferrer\">a guide to security best practices<\/a>. Although there are more known security holes with the Windows OS, trained Microsoft programmers patch flaws and release updates and are available to respond to incidents.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When his site was unexpectedly hit by a recent core Google algorithm update, one SEO was determined to find out why. Follow along with all the steps taken to see just what went wrong and how to determine the right fix.<\/p>\n","protected":false},"author":1,"featured_media":371,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,1],"tags":[],"class_list":["post-308","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bs-seo-basics","category-speed-security"],"_links":{"self":[{"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/posts\/308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/comments?post=308"}],"version-history":[{"count":0,"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/posts\/308\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/media\/371"}],"wp:attachment":[{"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/media?parent=308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/categories?post=308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inetxsys.com\/articles\/wp-json\/wp\/v2\/tags?post=308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}