WordPress Security: 12 Ways to Protect Your Website from Hackers
Keep your WordPress site safe: updates, strong logins and 2FA, backups, a firewall, safe plugins and hosting — 12 practical steps that stop most attacks.

WordPress powers a huge share of the web, which also makes it the most targeted CMS. The good news: most hacked WordPress sites aren’t victims of sophisticated attacks. They fall to outdated plugins, weak passwords and missing backups — problems you can fix in an afternoon.
Here are the twelve measures I put in place when securing WordPress sites for clients, ordered by impact.
1. Keep WordPress, plugins and themes updated
Outdated plugins are the most common way into a WordPress site. Enable automatic updates for minor WordPress releases and trusted plugins, and check for remaining updates at least weekly. Updates matter most when they mention security fixes.
2. Delete what you don’t use
Every inactive plugin and theme is extra code that can contain vulnerabilities — even when deactivated. Keep one default theme as a fallback, and remove everything else you don’t actively use.
3. Only install plugins and themes from trusted sources
Use the official WordPress.org directory or reputable developers. Never install “nulled” (pirated) premium plugins or themes; they are a classic way to hide malware and backdoors.
4. Use strong, unique passwords and two-factor authentication
Every administrator account should have a long, unique password stored in a password manager, plus two-factor authentication (2FA). Avoid usernames such as “admin” that attackers try first.
5. Limit login attempts
Bots try thousands of password combinations against wp-login.php. Limiting failed attempts, or putting the login page behind a firewall rule, stops brute-force attacks before they get anywhere.
6. Give users only the access they need
Not everyone needs to be an Administrator. Use the Editor, Author or Contributor roles where possible, and remove accounts of former staff and agencies promptly.
7. Take automatic, off-site backups
Backups are your safety net when everything else fails. Schedule daily backups of files and database, store them away from your hosting account (for example in cloud storage), and test restoring one occasionally. A backup you’ve never restored is only a hope.
8. Use HTTPS everywhere
An SSL certificate encrypts logins and form submissions. Most hosts offer free certificates; redirect all HTTP traffic to HTTPS.
9. Put a web application firewall in front of your site
A firewall such as Cloudflare or a reputable security plugin blocks known attack patterns, malicious bots and suspicious traffic before it reaches WordPress.
10. Harden the configuration
- Set correct file permissions (typically 755 for folders and 644 for files) and protect
wp-config.php. - Consider disabling the built-in file editor with
define( 'DISALLOW_FILE_EDIT', true );if nobody on your team edits code from the dashboard. - Disable XML-RPC if you don’t use apps or services that need it.
- Keep PHP on a version that still receives security updates.
11. Choose good hosting
Quality hosting isolates accounts, keeps server software patched, scans for malware and offers server-level backups. Cheap overcrowded servers are a security risk as well as a speed problem.
12. Monitor your site
Use uptime monitoring, a malware scanner and Google Search Console, which alerts you if Google detects hacked content or security issues. The sooner you notice a problem, the smaller the damage.
Signs your site may already be hacked
- Unknown administrator accounts or plugins.
- Redirects to spam, pharmacy or gambling sites — sometimes only for mobile visitors or visitors from Google.
- Warnings in browsers or in Search Console.
- Strange pages appearing in Google results for your domain.
- Your host suspending the account or reporting outgoing spam.
What to do if you’ve been hacked
- Put the site in maintenance mode and change all passwords (WordPress, hosting, database, FTP).
- Restore a clean backup from before the infection — or clean files and database carefully.
- Update everything and remove the vulnerability that let attackers in.
- Scan again, then request a review in Search Console if Google flagged the site.
Frequently asked questions
Is WordPress secure?
WordPress core is maintained by a large security team and is generally secure when kept up to date. Most problems come from outdated plugins, weak passwords and poor hosting.
Do I need a security plugin?
It helps, especially for login protection, firewall rules and malware scanning. It doesn’t replace updates, backups and good passwords.
How often should I back up my website?
Daily for most business websites, and before every major update. Online stores and busy sites may need more frequent backups.
Want your WordPress site secured and maintained?
Security hardening, backups, updates and malware clean-ups are part of my IT support and web development services. If your emails are also landing in spam, read how to fix SPF, DKIM and DMARC. Get in touch for a security check.
