{"id":105,"date":"2026-09-14T16:20:00","date_gmt":"2026-09-14T11:20:00","guid":{"rendered":"https:\/\/example.com\/?p=105"},"modified":"2026-09-14T16:20:00","modified_gmt":"2026-09-14T11:20:00","slug":"wordpress-security-checklist","status":"publish","type":"post","link":"https:\/\/www.nexooraclub.com\/?p=105","title":{"rendered":"The 12-Point WordPress Security Checklist for 2026"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">WordPress powers a huge share of the web, which makes it a favourite target. The good news: the core software is well maintained, and most successful attacks exploit <strong>outdated plugins, weak passwords or sloppy configuration<\/strong> \u2014 all things you control.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Work through this checklist and you&#8217;ll be ahead of the vast majority of sites.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Accounts and logins<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1. Use strong, unique passwords \u2014 and a password manager<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Every admin account needs a long, random password that isn&#8217;t used anywhere else. A password manager (Bitwarden, 1Password, KeePassXC) makes this painless.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Turn on two-factor authentication (2FA)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Even if a password leaks, 2FA stops the attacker. Use an authenticator app or, better yet, a passkey or hardware key. Require it for <strong>every account that can publish or manage the site<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Don&#8217;t use &#8220;admin&#8221; as a username<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s the first name bots try. Create a new administrator with a unique username, log in as them, then delete the old &#8220;admin&#8221; account (attributing its content to the new user).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Give people the least access they need<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Writers should be <strong>Authors<\/strong> or <strong>Editors<\/strong>, not Administrators. Review your Users screen every few months and remove people who no longer need access.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Updates and plugins<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">5. Keep everything updated<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Outdated plugins are the number-one cause of hacked WordPress sites. Enable automatic updates for minor core releases and for trusted plugins, and check the Updates screen weekly.<\/p>\n\n\n\n<p class=\"tp-callout wp-block-paragraph\">Test big updates on a staging copy first if your site makes money. Many hosts offer one-click staging.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6. Remove plugins and themes you don&#8217;t use<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A deactivated plugin can still contain vulnerable files on the server. If you&#8217;re not using it, <strong>delete it<\/strong>. The same goes for old default themes \u2014 keep just one as a fallback.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7. Only install from trusted sources<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Stick to the official WordPress.org directory or reputable commercial vendors. <strong>Never<\/strong> install &#8220;nulled&#8221; (pirated) premium plugins \u2014 they very often contain hidden backdoors.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Configuration hardening<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">8. Disable the built-in file editor<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If an attacker gets into the dashboard, the theme\/plugin editor lets them inject code instantly. Add this to <code>wp-config.php<\/code>:<\/p>\n\n\n\n<pre class=\"wp-block-code language-php\"><code>define( 'DISALLOW_FILE_EDIT', true );<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">9. Force HTTPS everywhere<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Get a free SSL certificate (most hosts offer Let&#8217;s Encrypt) and make sure both the <strong>WordPress Address<\/strong> and <strong>Site Address<\/strong> in Settings \u2192 General start with <code>https:\/\/<\/code>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">10. Protect sensitive files<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On Apache servers you can block direct access to <code>wp-config.php<\/code> and stop PHP running in the uploads folder. In your root <code>.htaccess<\/code>:<\/p>\n\n\n\n<pre class=\"wp-block-code language-apache\"><code>&lt;Files wp-config.php&gt;\n  Require all denied\n&lt;\/Files&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">And in <code>wp-content\/uploads\/.htaccess<\/code>:<\/p>\n\n\n\n<pre class=\"wp-block-code language-apache\"><code>&lt;Files *.php&gt;\n  Require all denied\n&lt;\/Files&gt;<\/code><\/pre>\n\n\n\n<p class=\"tp-callout tp-callout--warn wp-block-paragraph\">Always back up <code>.htaccess<\/code> before editing it. A typo can take your whole site offline with a 500 error.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Monitoring and recovery<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">11. Limit login attempts and add a firewall<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A security plugin or a service like Cloudflare can block brute-force attacks and known malicious traffic before it reaches WordPress.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">12. Have automatic, off-site backups \u2014 and test them<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Backups are your undo button. Keep <strong>daily backups<\/strong> of files and database, stored <strong>somewhere other than your server<\/strong> (cloud storage, your host&#8217;s backup system). Once every few months, actually restore one to a test site to make sure it works.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Your one-hour action plan<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Update everything and delete unused plugins\/themes (15 min)<\/li>\n\n\n<li>Enable 2FA for all admins and editors (10 min)<\/li>\n\n\n<li>Add <code>DISALLOW_FILE_EDIT<\/code> and check HTTPS (10 min)<\/li>\n\n\n<li>Install a reputable security\/firewall solution (10 min)<\/li>\n\n\n<li>Set up and test automatic off-site backups (15 min)<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Security isn&#8217;t a one-time task, but with these habits in place you&#8217;ve closed the doors that the overwhelming majority of attacks walk through.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most hacked WordPress sites fall to the same handful of mistakes. Work through this checklist in an hour and close the doors attackers use most.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[16,33,36],"class_list":["post-105","post","type-post","status-publish","format-standard","hentry","category-cybersecurity","tag-checklist","tag-security","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/www.nexooraclub.com\/index.php?rest_route=\/wp\/v2\/posts\/105","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nexooraclub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nexooraclub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nexooraclub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nexooraclub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=105"}],"version-history":[{"count":0,"href":"https:\/\/www.nexooraclub.com\/index.php?rest_route=\/wp\/v2\/posts\/105\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.nexooraclub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nexooraclub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nexooraclub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}