Skip to content
Nexoora Club
Cybersecurity

The 12-Point WordPress Security Checklist for 2026

Most hacked WordPress sites fall to the same handful of mistakes. Work through this checklist in an hour and close the doors attackers use most.

nexooraclub3 min read3

WordPress powers a huge share of the web, which makes it a favourite target. The good news: the core software is well maintained, and most successful attacks exploit outdated plugins, weak passwords or sloppy configuration — all things you control.

Work through this checklist and you’ll be ahead of the vast majority of sites.

Accounts and logins

1. Use strong, unique passwords — and a password manager

Every admin account needs a long, random password that isn’t used anywhere else. A password manager (Bitwarden, 1Password, KeePassXC) makes this painless.

2. Turn on two-factor authentication (2FA)

Even if a password leaks, 2FA stops the attacker. Use an authenticator app or, better yet, a passkey or hardware key. Require it for every account that can publish or manage the site.

3. Don’t use “admin” as a username

It’s the first name bots try. Create a new administrator with a unique username, log in as them, then delete the old “admin” account (attributing its content to the new user).

4. Give people the least access they need

Writers should be Authors or Editors, not Administrators. Review your Users screen every few months and remove people who no longer need access.

Updates and plugins

5. Keep everything updated

Outdated plugins are the number-one cause of hacked WordPress sites. Enable automatic updates for minor core releases and for trusted plugins, and check the Updates screen weekly.

Test big updates on a staging copy first if your site makes money. Many hosts offer one-click staging.

6. Remove plugins and themes you don’t use

A deactivated plugin can still contain vulnerable files on the server. If you’re not using it, delete it. The same goes for old default themes — keep just one as a fallback.

7. Only install from trusted sources

Stick to the official WordPress.org directory or reputable commercial vendors. Never install “nulled” (pirated) premium plugins — they very often contain hidden backdoors.

Configuration hardening

8. Disable the built-in file editor

If an attacker gets into the dashboard, the theme/plugin editor lets them inject code instantly. Add this to wp-config.php:

define( 'DISALLOW_FILE_EDIT', true );

9. Force HTTPS everywhere

Get a free SSL certificate (most hosts offer Let’s Encrypt) and make sure both the WordPress Address and Site Address in Settings → General start with https://.

10. Protect sensitive files

On Apache servers you can block direct access to wp-config.php and stop PHP running in the uploads folder. In your root .htaccess:

<Files wp-config.php>
  Require all denied
</Files>

And in wp-content/uploads/.htaccess:

<Files *.php>
  Require all denied
</Files>

Always back up .htaccess before editing it. A typo can take your whole site offline with a 500 error.

Monitoring and recovery

11. Limit login attempts and add a firewall

A security plugin or a service like Cloudflare can block brute-force attacks and known malicious traffic before it reaches WordPress.

12. Have automatic, off-site backups — and test them

Backups are your undo button. Keep daily backups of files and database, stored somewhere other than your server (cloud storage, your host’s backup system). Once every few months, actually restore one to a test site to make sure it works.

Your one-hour action plan

  1. Update everything and delete unused plugins/themes (15 min)
  2. Enable 2FA for all admins and editors (10 min)
  3. Add DISALLOW_FILE_EDIT and check HTTPS (10 min)
  4. Install a reputable security/firewall solution (10 min)
  5. Set up and test automatic off-site backups (15 min)

Security isn’t a one-time task, but with these habits in place you’ve closed the doors that the overwhelming majority of attacks walk through.

Written by

nexooraclub

Writer and builder covering software, AI and the tools that make developers faster. Add your bio under Users → Profile.

3 comments

Join the discussion

Your email address will not be published. Required fields are marked *