WordPress powers a huge share of the web, which makes it a favourite target. The good news: the core software is well maintained, and most successful attacks exploit outdated plugins, weak passwords or sloppy configuration — all things you control.
Work through this checklist and you’ll be ahead of the vast majority of sites.
Accounts and logins
1. Use strong, unique passwords — and a password manager
Every admin account needs a long, random password that isn’t used anywhere else. A password manager (Bitwarden, 1Password, KeePassXC) makes this painless.
2. Turn on two-factor authentication (2FA)
Even if a password leaks, 2FA stops the attacker. Use an authenticator app or, better yet, a passkey or hardware key. Require it for every account that can publish or manage the site.
3. Don’t use “admin” as a username
It’s the first name bots try. Create a new administrator with a unique username, log in as them, then delete the old “admin” account (attributing its content to the new user).
4. Give people the least access they need
Writers should be Authors or Editors, not Administrators. Review your Users screen every few months and remove people who no longer need access.
Updates and plugins
5. Keep everything updated
Outdated plugins are the number-one cause of hacked WordPress sites. Enable automatic updates for minor core releases and for trusted plugins, and check the Updates screen weekly.
Test big updates on a staging copy first if your site makes money. Many hosts offer one-click staging.
6. Remove plugins and themes you don’t use
A deactivated plugin can still contain vulnerable files on the server. If you’re not using it, delete it. The same goes for old default themes — keep just one as a fallback.
7. Only install from trusted sources
Stick to the official WordPress.org directory or reputable commercial vendors. Never install “nulled” (pirated) premium plugins — they very often contain hidden backdoors.
Configuration hardening
8. Disable the built-in file editor
If an attacker gets into the dashboard, the theme/plugin editor lets them inject code instantly. Add this to wp-config.php:
define( 'DISALLOW_FILE_EDIT', true );
9. Force HTTPS everywhere
Get a free SSL certificate (most hosts offer Let’s Encrypt) and make sure both the WordPress Address and Site Address in Settings → General start with https://.
10. Protect sensitive files
On Apache servers you can block direct access to wp-config.php and stop PHP running in the uploads folder. In your root .htaccess:
<Files wp-config.php>
Require all denied
</Files>
And in wp-content/uploads/.htaccess:
<Files *.php>
Require all denied
</Files>
Always back up .htaccess before editing it. A typo can take your whole site offline with a 500 error.
Monitoring and recovery
11. Limit login attempts and add a firewall
A security plugin or a service like Cloudflare can block brute-force attacks and known malicious traffic before it reaches WordPress.
12. Have automatic, off-site backups — and test them
Backups are your undo button. Keep daily backups of files and database, stored somewhere other than your server (cloud storage, your host’s backup system). Once every few months, actually restore one to a test site to make sure it works.
Your one-hour action plan
- Update everything and delete unused plugins/themes (15 min)
- Enable 2FA for all admins and editors (10 min)
- Add
DISALLOW_FILE_EDITand check HTTPS (10 min) - Install a reputable security/firewall solution (10 min)
- Set up and test automatic off-site backups (15 min)
Security isn’t a one-time task, but with these habits in place you’ve closed the doors that the overwhelming majority of attacks walk through.
Point 8 (disable file editing) saved me. A client site got compromised last year exactly that way.
Bookmarked. Going through this for all 14 sites I manage.
Is two-factor really necessary for subscriber accounts too?