Last Updated on August 25, 2020 by Christopher G Mendla
A standard installation of WordPress works, but it lacks many features that are needed for even a basic site including critical security features. For any feature that you wish to add, there are usually one or more plugins that will accomplish the task. Plugins are a matter of your needs and personal taste.
Plugins extend and enhance the functionality of WordPress. They are third party tools that ‘plug in’ to your WordPress installation. For the purposes of this discussion we are talking about hosted WordPress installations and not WordPress.com
Currently there are over 50,000 plugins available. If you tried to install even a small fraction of that amount, your site would slow to a crawl.
Many of the plugins, including some of the most useful and popular, are either free or have free versions.
There are plugins that are critical for securing your site and others that provide better user experiences by providing services such as speeding up your site. This post provides a starting point for a basic WordPress Site.
WordPress 5.5 added many features that provide functionality that previously required plugins. You should review your site periodically to determine if WordPress has replaced the functions of a plugin
When you are choosing plugins, the best way to do so is from the “Add New” link in the Plugins area. When you do that, you will see an indications of:
Some other things to consider would be:
Below are some of the plugins we install for most sites. Every site will have a unique set of needs.
This is probably one of the most critical plugins and should be one of the first that you install. Due to the popularity and number of WordPress sites, new sites are targets for hackers. They will start attacking a site within hours of it being launched.
One tool to protect your site is Wordfence Security. You can use it ‘out of the box’ but it pays to go through and check the configuration. You can block users when their attempted logins fail after a certain number of tries.
An alternative security package is Jetpack. With Jetpack, you probably need to go to one of the paid plans for about $3.50 /month to get a good level of protection. Jetpack adds some other useful tools in addition to security. I have run sites with both Wordfence and Jetpack. You might have to tweak the configurations a bit to make sure that there are no conflicts.
This should be added as early as possible in the process.
I have learned over the years to not trust web hosting companies for backups. As your site grows, you should have backups of the database and all files. This includes media files. Depending on your work flow, you could have the media files backed up locally and not necessarily from the server.The free version of BackupWordPress will allow you to back up your database and/or files manually or on a scheduled basis. Jetpack also provides backup capability starting with the $3.50/month plan.
It is still a good idea to set up a backup scheme in cPanel in addition to any other backups. I currently do a manual backup at least weekly using Softaculous which is included with my cPanel.
The default behavior of images in your post leaves a lot to be desired. A plugin such as Responsive Lightbox and Gallery will enhance your user’s experience. When a user clicks on an image in a post, a lightbox will show the image full size.
The default installation of WordPress has no provision for forms. There are a number of fairly good tools that will provide this ability. One example is Ninja Tools. The free version will allow you to place useful forms on your site.
NOTE – as of April 2018, Ninja forms does not provide for auto completion of form fields. This is a show stopper for almost all applications
We replaced Ninja Forms with WP-Forms lite which provides similar functionality. They also have form plugins with more features.
If you need more complex forms in almost any of the plugins, you will need to upgrade to the paid version.
Users sharing your site via social media can help grow your site quickly. There are social media plugins that will manage displaying buttons for social sharing. Sassy Social Media is one tool. You will need to tweak the configuration a bit. Don’t forget to check how the sharing buttons render on tablets and mobile devices.
Pro tip – Keep the number of social media choices limited. Don’t be tempted to add them all or your page will look like a carnival.
The editor installed with WordPress is a basic version of the TinyMCE Editior. Your formatting choices are very limited. Installing the TinyMCE Advanced plugin will allow much more control over the formatting of your posts.
As soon as you launch a WordPress site, every cretin will start flooding your site with comment spam. This does some serious damage to your site.
Comment Link Remove will allow you to set options to that any links in the comments are turned into plain text. You can also remove the URL field from the comments which prevents spammers from adding links there. You still need to make sure that you are requiring moderation for submitted comments.
Another useful tool in conjunction with Comment Link Remove is Antispam Bee. This is available as a free version. Like the commercial Askimet, it checks incoming comments for indicators of spam and trashes them accordingly.
Running afoul of copyright trolls could cause horrendous losses for you. Copyright trolls purchase image libraries. They then scan for any ‘unauthorized’ use of these images. Once they find a use, no matter how small the site is, they use their army of bottom feeding lawyers to demand thousands of dollars.
A tool such as Download Free Images will allow you to insert images in your posts that are royalty free. This adds a button to your editor. When you click the button, you can search for images. If you find one you like, Pixabay Images will add it to your Media and post. It will also add the proper attribution for the image. There is still a possibility that you could have copyright issues but they are minimized.
Redirection is for more advanced users and is especially important if you moved to WordPress from another site. Redirection will log 404’s (not found) errors. This is often where someone tried to access your page using an old link. You can then ‘correct’ this by creating a redirect from the old link to the new link. This can be tedious for larger sites but it will prevent you from losing a lot of traffic after a migration to WordPress.
Relevanssi provides an enhanced search tool for your site. The basic version will meet most needs but there is an enhanced paid version as well.
Depending on your site, it might be helpful to list similar posts at the end of a post. Similar Posts does this very well. It looks at the content of your post and tries to find other posts from your site that are similar. The idea is to keep your visitors engaged on your site.
However, Similar Posts requires a lot of server resources. In many cases this can really slow down your site. Jetpack offers a cloud based tool to show similar costs for a fee.
Search engine optimization is critical to getting decent rankings for your content. The free version of Yoast will work for most beginners and intermediate users. Yoast will give you advice regarding the readability and search engine friendliness of your posts and other content.
Another part of SEO is controlling how the ‘link juice’ of your site flows to other sites. When you link to a site, you are endorsing that site. Some of the ‘goodness’ of your site will flow to other sites. If the site you are linking to is a legitimate strong site, that can be OK. However, there are other cases where you might not want the ‘link juice’ to follow.
There is a learning curve with Yoast. You need a fundamental understanding of basic SEO principles. Fortunately there is a LOT of documentation and videos available.
When used properly, Yoast will act as a coach to help you create articles that are Search Engine Friendly.
Our sites are set up on Cloudflare. I have certificates for HTTPS for all the sites except one. There is a plugin, Flexible SSL for Cloudflare that allows you to easily integrate HTTPS with Cloudflare
I’ve been using Peter’s Post It Notes to add notes to posts. This provides a simple input box when you are editing a post. You can write a note such as “Link to the article on how to beat the lottery when we write it”.
The plugins listed above will give you a basic site with backups, security and some critical usability enhancements. As you add plugins, keep a close eye out for decreases in site performance.
Unfortunately there is no easy way to see which of your plugins have not had an available update for a while. A plugin that is not updated COULD introduce vulnerabilities.
Your email address will not be published. Required fields are marked *
Save my name, email, and website in this browser for the next time I comment.