WordPress powers a large share of the web, which makes it a popular target. Most WordPress compromises trace back to the same few causes: outdated plugins, weak or reused passwords, abandoned admin accounts and poor-quality themes or plugins. Here is a practical hardening checklist.
Keep core, themes and plugins updated
Enable automatic minor core updates and check plugin updates at least weekly. Test major updates on a staging copy first if the site is business-critical.
Be selective about plugins
- Install only what you need, from reputable developers with recent updates.
- Delete (don’t just deactivate) plugins and themes you no longer use.
- Avoid “nulled” (pirated) premium plugins; they’re a common source of malware.
Lock down logins
- Don’t use “admin” as a username.
- Require strong passwords and two-factor authentication for administrators.
- Limit failed login attempts.
- Review user accounts regularly and remove ones that aren’t needed.
Harden the configuration
- Disable the built-in theme and plugin file editor.
- Disable XML-RPC if you don’t use it.
- Prevent username discovery through author archives and the users REST endpoint.
- Add security headers and enforce HTTPS.
- Use correct file permissions and keep
wp-config.phpprotected.
Back up and monitor
Automated daily backups stored off-site, plus monitoring for file changes, new administrator accounts and uptime. Test a restore periodically.
Choose good hosting
A good host keeps server software updated, isolates accounts, offers a firewall and provides backups. Cheap hosting can cost more after one incident.
Don’t forget the website’s own code
Custom themes and plugins should validate and sanitise input, escape output, check permissions and use nonces to protect forms from cross-site request forgery. These are the standards we build to.
Need your WordPress site reviewed or maintained? Tell us about it.