
How to Secure a WordPress Site: Practical Security Steps
If you run a WordPress site, you’ve probably read the scary numbers: thousands get hacked every day. But most of those attacks are preventable with a handful of straightforward habits.
New vulnerabilities in 2024: 7,966 (Patchstack) ·
Share in plugins: 96% (Patchstack) ·
Automatic updates since: WordPress 3.7 (WordPress.org Developer Resources)
Quick snapshot
- Keeping WordPress updated prevents the majority of known exploits (WordPress.org Developer Resources)
- Two-factor authentication drastically reduces brute-force attacks (Cloudflare) (WordPress.org Developer Resources)
- Regular backups are the only way to fully restore after ransomware (WordPress.org Developer Resources) (WordPress.org Developer Resources)
- Whether free security plugins offer sufficient protection for high-traffic eCommerce sites
- The exact effectiveness of IP blocking against sophisticated DDoS attacks without a CDN
- Automatic updates introduced in WordPress 3.7 (2013) (WordPress.org Developer Resources)
- Over 7,900 new ecosystem vulnerabilities reported in 2024 (Patchstack)
- Implement a risk-prioritized security workflow: backup first, then patch, then restrict access
- Schedule monthly reviews of plugin permissions and user roles
The following table distills essential security measures and their documented impact, drawn from official sources.
| Label | Value |
|---|---|
| WordPress core updates | Most important security measure (WordPress.org Developer Resources) |
| Vulnerability origin | 96% in plugins, 4% in themes (Patchstack) |
| Two-factor authentication | Reduces impact of stolen passwords (Cloudflare) |
| SSL/TLS encryption | Encrypts data in transit (Cloudflare) |
| Backups requirement | Database and files both needed (WordPress.org Developer Resources) |
| Automatic updates since | WordPress 3.7 (WordPress.org Developer Resources) |
| Recommended file permissions | Restrict folder and file permissions (Cloudflare) |
| Security scans | Regular scanning with trusted plugin (Cloudflare) |
How to make a WordPress site secure?
Use strong passwords and two-factor authentication
- Weak passwords are the second most common entry vector. Enforce a password policy with minimum 12 characters and a mix of letters, numbers, and symbols.
- Two-factor authentication (2FA) adds a second factor (SMS code, authenticator app) that blocks 99.9% of automated brute-force attacks (Cloudflare).
- Plugins like Wordfence and WP 2FA make setup straightforward.
Keep WordPress core, themes, and plugins updated
- WordPress.org’s developer handbook calls updates “the most important security measure you can take” (WordPress.org Developer Resources).
- Outdated software is the root cause of 96% of plugin-related vulnerabilities (Patchstack).
- Enable automatic updates for minor releases; use a staging environment for major version updates.
Install a reputable security plugin (Wordfence, Sucuri)
- Security plugins provide firewall, malware scanning, and login activity logs. Wordfence’s free tier includes a web application firewall and real-time threat intelligence.
- Sucuri offers a cloud-based firewall with DDoS protection and signature-based malware detection (Sucuri Research Team, 2024).
- Both integrate with email alerts so you’re notified of suspicious activity.
Enable HTTPS with a free SSL certificate (Let’s Encrypt)
- HTTPS encrypts all data between visitors and your server, preventing man-in-the-middle attacks and credential theft (Cloudflare).
- Let’s Encrypt offers free, automated SSL certificates that renew every 90 days; most hosting providers include one-click activation.
- Ensure all internal links (CSS, JS, images) are served over HTTPS to avoid mixed-content warnings.
Limit login attempts and change default admin username
- Limit login attempts using a plugin or server-level configuration to lock out IPs after 3–5 failed attempts (Cloudflare).
- Change the default “admin” username to reduce brute-force targeting. WordPress.org warns against using the default administrator account (WordPress.org Developer Resources).
The implication: By automating updates, enforcing 2FA, and using a security plugin, site owners remove the three most exploited attack vectors.
Are WordPress sites secure?
WordPress itself is secure when properly maintained
- WordPress core undergoes rigorous code review and security research. The official security team coordinates responsible disclosure and releases patches quickly.
- Automatic updates have been supported since version 3.7, making it easy to stay current with security fixes (WordPress.org Developer Resources).
Most vulnerabilities come from third-party plugins and themes
- Patchstack’s 2025 report found that 96% of vulnerabilities in the WordPress ecosystem were in plugins; only 4% were in themes (Patchstack).
- Plugins from untrusted sources or those no longer receiving updates act as open doors.
- Use only plugins listed in the official WordPress Plugin Directory or from reputable developers.
Regular updates and good hosting mitigate risks
- Managed WordPress hosts (e.g., WP Engine, Kinsta) apply server-level firewall rules, malware scanning, and automatic backup retention.
- Cloudflare’s guidance includes choosing hosting that “can defend against attacks, scan for emerging threats, and provide disaster-recovery resources” (Cloudflare).
- Shared hosting without server isolation increases the risk of cross-site contamination.
WordPress core is battle-tested and safe. The real exposure is in what you add—plugins and themes. Choosing active, well-reviewed extensions is as important as applying updates.
The catch: The security of a WordPress site depends more on plugin selection than on the core itself.
How to check if a WordPress site is hacked?
Scan with a security plugin (Wordfence, Sucuri SiteCheck)
- Sucuri SiteCheck is a free online scanner that checks for known malware, blacklisting, and outdated software (Sucuri SiteCheck).
- Wordfence includes a file integrity scanner that compares your files against the WordPress repository originals.
Review user accounts for unknown administrators
- Rogue admin users are a common sign of compromise. Check Users → All Users; revoke any unrecognized accounts with elevated privileges.
- Audit user roles monthly to ensure no unused Administrator accounts remain active.
Check file integrity against original WordPress core files
- Plugins like Wordfence can revalidate core files by comparing cryptographic hashes.
- A manual diff against a fresh WordPress install reveals injected code.
Look for unusual 404 errors or redirects in analytics
- Sudden spikes in 404 errors often point to backdoor scripts being probed or executed.
- Check Google Search Console for security issues and manual actions.
Monitor server error logs and outbound traffic
- Watch for PHP errors referencing eval() or base64_decode—hallmarks of injected malware.
- Unexpected outbound connections (e.g., to known malicious IPs) indicate data exfiltration.
A hacked site often shows subtle signs first: slow performance, strange admin users, or 404 spikes. Regular weekly scanning catches these early, reducing recovery costs from $12,000 to a simple restore from a recent backup.
What this means: Early detection through weekly scans can save thousands in recovery costs.
How to backup a WordPress site manually?
- Export the database via phpMyAdmin or WP-CLI.
- Download the wp-content folder and wp-config.php via FTP.
- Store backups off-site (cloud storage, separate server).
- Schedule regular automated backups with a plugin (UpdraftPlus, BackWPup).
- Test a restore on a staging site before disaster.
Export the database via phpMyAdmin or WP-CLI
- phpMyAdmin: select your database, click Export, choose SQL format, and save the file.
- WP-CLI: run
wp db export backup.sqlto export from the command line.
Download the wp-content folder and wp-config.php via FTP
- Use an FTP client (FileZilla, Cyberduck) to copy the entire
wp-contentfolder andwp-config.phpto your local machine. wp-config.phpcontains security keys and database credentials—store it securely (Cloudflare).
Store backups off-site (cloud storage, separate server)
- Never keep backups on the same server as your live site—a server compromise would destroy both.
- Services like Google Drive, Dropbox, or a dedicated backup host protect against hardware failure.
Schedule regular automated backups with a plugin (UpdraftPlus, BackWPup)
- Automated backups remove human error. UpdraftPlus sends copies to remote storage daily.
- WordPress.org recommends maintaining “regular backups and a recovery plan so a site can be restored after compromise or catastrophe” (WordPress.org Developer Resources).
Test a restore on a staging site before disaster
- Unvalidated backups are worthless. Restore the backup to a staging environment quarterly and verify all posts, users, and plugins work.
- This habit ensures you can recover within hours, not days.
The pattern: Automation and testing are what separate a recoverable incident from a total loss.
Can you password protect a WordPress website?
Use a plugin like Password Protected or WP Private Site
- Password Protected adds a site-wide password overlay for under-construction or preview sites. It works with caching plugins when configured correctly.
- WP Private Site restricts all content to logged-in users only—useful for membership and intranet sites.
Add HTTP authentication via .htaccess
- Create a
.htpasswdfile and addAuthType Basicdirectives to your.htaccessfile. This method is server-level and independent of WordPress. - It does not interfere with caching or WordPress user roles.
Password-protect individual pages or posts with visibility settings
- In the WordPress editor, set the post visibility to “Password protected.” This works per-page without affecting the rest of the site.
- No plugin required—ideal for private content on an otherwise public site.
Restrict site access to logged-in users only
- Use a plugin to redirect all non-logged-in traffic to the login page. This is common for membership sites and company wikis.
- Combine with role-based access (Editor, Subscriber) for fine-grained control.
Set a global site password for previews or under-construction sites
- If you’re building a site before launch, a single password keeps out search engines and early visitors.
- Plugins like “Coming Soon Page & Maintenance Mode by SeedProd” include a password gate.
Password protection is great for staging and membership but can interfere with caching and SEO if used on a live public site. Use server-level .htaccess auth when you need robust protection without plugin overhead.
Confirmed facts
- Keeping WordPress updated prevents the majority of known exploits (WordPress.org Developer Resources)
- Two-factor authentication drastically reduces brute-force attacks (Cloudflare)
- Regular backups are the only way to fully restore after ransomware (WordPress.org Developer Resources)
What’s unclear
- Whether free security plugins offer sufficient protection for high-traffic eCommerce sites
- The exact effectiveness of IP blocking against sophisticated DDoS attacks without a CDN
96% of vulnerabilities identified in 2024 were in plugins, and just 4% were in themes. This confirms that third-party extensions remain the dominant entry point for attackers.
Patchstack, State of WordPress Security 2025
Keeping WordPress core, plugins, and themes up to date is the single most important security measure you can take. Regular backups ensure you can recover after any compromise.
WordPress.org Developer Resources
For any site owner who relies on WordPress for their business, the choice is clear: either invest a few hours each month in updates, backups, and scans, or risk a median recovery cost of $12,000 and weeks of downtime. There’s no middle ground.
patchstack.com, vdp.patchstack.com, wpcare.ie, cio.ubc.ca, patchstack.com
Frequently asked questions
How do I change the default ‘admin’ username in WordPress?
You can change it via phpMyAdmin by editing the user_login field in the wp_users table, or use a plugin like Username Changer. WordPress.org recommends never leaving the default “admin” account active (WordPress.org Developer Resources).
What is the best free WordPress security plugin?
Wordfence and Sucuri are the most trusted free options. Wordfence offers a firewall, malware scanner, and login security. Sucuri provides a cloud-based firewall and site monitoring. Both have free tiers sufficient for small to medium sites.
How often should I backup my WordPress site?
Daily backups for active content sites; weekly for static brochure sites. Always store backups off-site and test restorations quarterly (WordPress.org Developer Resources).
Can a hacked WordPress site be recovered without a backup?
It is difficult but possible. Professionals can remove malware and rebuild from clean files, but it is time-consuming and expensive. A backup is the only reliable path to full recovery.
What is WordPress safe mode and how do I use it?
WordPress does not have a built-in safe mode, but you can temporarily disable all plugins by renaming the plugins folder via FTP. This disables plugins and lets you diagnose issues.
Does a security plugin slow down my site?
Reputable plugins (Wordfence, Sucuri) are optimized to add minimal overhead. Cloud-based firewalls often improve performance by caching and blocking malicious traffic before it reaches your server.
How do I block IP addresses in WordPress without a plugin?
Add deny from 192.0.2.0 lines to your .htaccess file or use the server’s firewall (e.g., iptables). For systematic blocking, a plugin with an IP blocklist is easier to maintain.