WordPress

WordPress Security Tips

The practical, high-impact security habits that prevent the vast majority of WordPress site compromises.

The most effective WordPress security tips are also the simplest: keep WordPress core, themes and plugins updated, use strong unique passwords with two-factor authentication, remove anything you do not use, put a firewall in front of the site and keep tested off-site backups. Most compromised WordPress sites are breached through known, already-patched vulnerabilities or weak logins, not sophisticated attacks. The checklist below covers the essentials and the next layer of hardening.

Why are WordPress sites targeted so often?

WordPress powers a very large share of the web, which makes it worthwhile for attackers to build automated tools that scan millions of sites for known weaknesses. Those tools do not care who you are. A small local business site is scanned just as often as a large brand.

The good news is that WordPress core itself has a strong security team and a regular release process. The weak points are usually around it: outdated plugins and themes, weak or reused passwords, poor hosting and missing backups. Each of those is within your control.

What are the security fundamentals every WordPress site needs?

If you do nothing else, do these.

Keep everything updated

WordPress core, plugins and themes all receive security patches. Once a vulnerability is published, automated attacks against it can start quickly, so delaying updates is the most common way sites get compromised. WordPress supports automatic updates for core, plugins and themes; enable them for trusted, well-maintained components, and review major updates on a staging site first.

Use strong, unique passwords and two-factor authentication

Every account with admin or editor access should use a long, unique password stored in a password manager. Add two-factor authentication (2FA) for all privileged users, using a plugin such as the official Two Factor plugin or the 2FA features built into security plugins like Wordfence or Solid Security. 2FA stops most credential-stuffing and brute-force attacks even if a password leaks.

Limit login attempts

Automated login attempts are constant background noise on the web. Limiting failed attempts, adding rate limiting at the firewall and using CAPTCHA or similar challenges on login forms significantly reduces this exposure.

Remove what you do not use

Deactivated plugins and unused themes still sit on the server, and a vulnerable file can still be reached. Delete them rather than just deactivating them. Keep one default WordPress theme installed as a fallback.

Use HTTPS everywhere

Serve the entire site over HTTPS with a valid SSL/TLS certificate, which most hosts provide free. It protects login details and form submissions in transit and is expected by browsers and search engines.

How do you harden WordPress beyond the basics?

Once the fundamentals are in place, these measures add meaningful protection.

  • Put a web application firewall (WAF) in front of the site. A cloud firewall such as Cloudflare or Sucuri filters malicious traffic before it reaches your server. An application-level firewall such as Wordfence inspects requests inside WordPress. Using one or both blocks a large volume of automated attacks.
  • Disable file editing in the dashboard. Adding define( 'DISALLOW_FILE_EDIT', true ); to wp-config.php removes the built-in theme and plugin editor, so an attacker who gains admin access cannot edit code through the browser.
  • Apply least privilege. Give each person the lowest role they need. Content writers rarely need administrator access. Remove accounts for former staff and contractors promptly.
  • Disable XML-RPC if you do not need it. It is a common target for brute-force attempts. Some apps and services rely on it, so check before turning it off.
  • Run a supported PHP version. Older PHP versions stop receiving security fixes. Your host should let you choose a current, supported version.
  • Keep security keys and salts unique. These values in wp-config.php protect login cookies; regenerate them after any suspected breach.
  • Set sensible file permissions. Files should not be writable by everyone, and wp-config.php should be tightly restricted.
  • Monitor for known vulnerabilities. Services such as Wordfence Intelligence, Patchstack and WPScan track vulnerabilities in plugins and themes and can alert you when something you use is affected.

Choose hosting with security in mind

Your host is part of your security. Good WordPress hosting isolates each site from others on the same server, keeps server software patched, offers free SSL certificates, runs malware scanning, provides SFTP rather than plain FTP, and includes automatic backups stored away from the server. Staging environments, which let you test updates before they reach the live site, are another sign of a host that takes WordPress seriously. Very cheap shared hosting often lacks some of these, and moving hosts is far easier before an incident than after one.

Watch your logs and alerts

Security settings only help if someone notices when they are triggered. Make sure alerts for failed logins, file changes, new administrator accounts and malware detections go to an inbox someone actually reads, and review activity logs after any unusual behaviour.

How do you choose safe plugins and themes?

Every plugin is extra code running on your site, and quality varies enormously. Before installing anything, check:

  1. When it was last updated. A plugin not updated for a long time may be abandoned.
  2. Compatibility. Whether it is tested with the current WordPress version.
  3. Active installs and reviews. Widely used plugins tend to have problems found and fixed faster.
  4. Support responsiveness. Whether the developer answers support questions and fixes reported issues.
  5. Security history. Whether past vulnerabilities were patched quickly.
  6. Source. Only install from WordPress.org or reputable commercial vendors. Never use “nulled” (pirated) premium plugins or themes, which are a common source of hidden malware.

Fewer, well-chosen plugins are safer and faster than many overlapping ones.

Why are backups part of security?

Backups do not prevent attacks, but they turn a serious incident into a recoverable one. A good backup setup has these features:

  • Automatic and frequent. Daily for most business sites, more often for busy online stores.
  • Complete. Database and files, including uploads.
  • Stored off-site. Not only on the same server as the website. The widely used 3-2-1 approach means three copies, on two types of storage, with one off-site.
  • Retained long enough. Infections are sometimes discovered weeks later, so keep several restore points.
  • Tested. A backup that has never been restored is only a theoretical backup. Test a restore on staging periodically.

Which security measures matter most?

MeasureEffortProtection gained
Regular updates of core, plugins and themesLow, ongoingVery high
Strong passwords and 2FA for all adminsLowVery high
Tested off-site backupsLow to mediumVery high for recovery
Web application firewallLow to mediumHigh
Removing unused plugins, themes and usersLowMedium to high
Least-privilege user rolesLowMedium
Disabling dashboard file editingVery lowMedium
Vulnerability monitoring and alertsLowHigh

What should you do if your WordPress site is hacked?

Act quickly and methodically.

  1. Put the site into maintenance mode or take it offline if it is serving malware or spam.
  2. Change all passwords: WordPress users, hosting, database, FTP/SFTP and email accounts linked to the site.
  3. Check for unknown administrator accounts and remove them.
  4. Restore from a clean backup taken before the compromise, or have the site professionally cleaned.
  5. Update everything and remove the vulnerable plugin or theme that allowed the breach.
  6. Regenerate security keys and salts.
  7. Scan the site again and check Google Search Console for security warnings, requesting a review if Google has flagged the site.
  8. Work out how the attacker got in, so it does not happen again.

Frequently asked questions

Do I need a security plugin?

Most sites benefit from one, for firewall rules, login protection, malware scanning and alerts. It is not a substitute for updates, strong passwords and backups, and running several overlapping security plugins can cause conflicts and slow the site.

Is WordPress less secure than other platforms?

WordPress core is well maintained and regularly patched. Most problems come from outdated extensions, weak passwords and poor hosting. A well-maintained WordPress site is a secure foundation.

How often should I update WordPress?

Security updates should be applied as soon as practical, ideally within days. Minor updates can run automatically. Test major version updates, and large plugin updates, on a staging site first.

Security is an ongoing discipline rather than a single setting. If you would rather have it handled for you, our website maintenance and support services cover updates, backups, monitoring and incident response, and our WordPress development services include security hardening. See also our guide to optimising a WordPress website, or contact us for a security review.

Ready to start your project?

Tell us about your goals and timeline. We'll follow up with next steps and a straightforward proposal — no pressure, no obligation.