Class, today’s lesson is the one that lets you sleep at night. WordPress core is actively maintained by a dedicated security team, but a site is only as secure as its weakest login, plugin or password. The good news is that most attacks are automated and opportunistic, so a handful of sensible habits blocks a huge amount of trouble. Here are 25 steps, grouped so you can work through them one section at a time.
Professor’s note: You don’t need to do all 25 today. Start with logins, updates and backups; they deliver the biggest protection for the least effort.
Logins and Accounts
- Use strong, unique passwords for every account, generated and stored by a password manager.
- Enable two-factor authentication for all administrators, using a plugin such as Two Factor or Wordfence.
- Don’t use “admin” as a username. If you already do, create a new administrator, log in as them, and delete the old account (assigning its content to the new user).
- Give people the lowest role they need. WordPress roles are Administrator, Editor, Author, Contributor and Subscriber. A guest writer rarely needs more than Contributor or Author.
- Remove old accounts for people who no longer work on the site.
- Limit login attempts to slow down password-guessing bots. Many security plugins and hosts include this.
- Review application passwords in each user’s profile and revoke any you don’t recognise or use.
Updates and Software
- Keep WordPress core updated. Minor security releases install automatically by default.
- Update plugins and themes promptly, and enable auto-updates for trusted ones once backups are in place.
- Delete unused plugins and themes. Deactivated code can still be a risk if it has a vulnerability. Keep one default theme as a fallback.
- Only install from trusted sources: WordPress.org or reputable developers. Never use nulled software.
- Vet new plugins before installing; see our plugins hub for a five-minute checklist.
- Use a supported PHP version. Check Tools → Site Health, then update via your host.
Warning: Updates occasionally cause conflicts. That’s a reason to have backups and a staging site, not a reason to skip updates. Outdated plugins are a far bigger risk.
Backups and Recovery
- Schedule automatic backups of both files and database, with a tool like UpdraftPlus or your host’s system.
- Store backups off-site, not only on the same server as your website.
- Test a restore occasionally, ideally to a staging site, so you know the process works.
- Write a simple recovery plan: who to contact at your host, where backups live, and how to restore.
Hardening Your Configuration
- Use HTTPS everywhere. Confirm both addresses in Settings → General begin with https://.
- Disable the built-in file editor. Add this line to wp-config.php, above “That’s all, stop editing!”, so nobody who gains admin access can edit theme and plugin code from the dashboard:
define( 'DISALLOW_FILE_EDIT', true ); - Keep secret keys and salts unique. wp-config.php contains security keys; the official generator at api.wordpress.org/secret-key/1.1/salt/ creates fresh ones. Replacing them logs everyone out, which is useful after a suspected compromise.
- Use a firewall. This could be your host’s, a service such as Cloudflare, or a plugin-based firewall like Wordfence.
- Use secure file permissions. Common recommendations are 755 for folders and 644 for files, with wp-config.php stricter where your host allows. Ask your host if unsure.
Tip: Always back up wp-config.php before editing it, and use a plain text editor or your host’s file manager. A single missing quote or semicolon can take the site offline until it’s fixed.
A Note for Code Tinkerers
If you add custom code, follow WordPress security basics: sanitise input, escape output, and check permissions and nonces. For example, when outputting a value in a template, escape it:
<?php
$city = get_post_meta( get_the_ID(), 'city', true );
echo '<p>' . esc_html( $city ) . '</p>';
?>
Our web development hub covers these practices in more depth.
Monitoring and Habits
- Run regular malware scans via your host or a security plugin, and act on alerts.
- Watch for warning signs: unknown admin users, unexpected redirects, strange new files, or search results showing spammy text.
- Choose a reputable host that isolates accounts, patches servers, and offers support when things go wrong.
If the Worst Happens
Stay calm. Contact your host, change all passwords (hosting, WordPress, database, email), restore a clean backup, update everything, and replace your security keys. If the infection returns, a professional clean-up service may be worthwhile. Find more guides in our resources.
Homework
Print this checklist or copy it into a note, and tick off every item you’ve completed. Then do the top three you haven’t: two-factor authentication, off-site backups, and disabling the file editor. Want to stay current? Join our newsletter for security reminders.