WordPress core is actively maintained by a dedicated security team, but most site compromises come from the things around it: outdated plugins, weak passwords and too many admins. Three habits block the vast majority of trouble. Let’s build them.
Habit 1: Update promptly
- Keep WordPress core, themes and plugins updated. Minor core releases, which often include security fixes, update automatically by default.
- Delete unused themes and plugins rather than leaving them deactivated. Keeping one default theme as a fallback is fine.
- Ask your host to keep PHP on a currently supported version.
Habit 2: Strong logins and 2FA
- Use a password manager and a long, unique password for every account, including hosting, domain registrar and email.
- Turn on two-factor authentication (2FA) for every admin. A 2FA or security plugin adds a code from an authenticator app at login. Some newer options support passkeys too.
- Limit login attempts or use your host’s or security plugin’s login protection to slow down bots.
- Protect the email account tied to your admin user. Whoever controls that inbox can reset your password.
Habit 3: Least privilege
Give every person the lowest role that lets them do their job. WordPress’s built-in roles are:
- Administrator: full control. Keep this to as few people as possible.
- Editor: manages and publishes all posts and pages, including other people’s.
- Author: writes, publishes and manages their own posts.
- Contributor: writes and edits their own posts but can’t publish them.
- Subscriber: can manage their own profile and little else.
A guest writer? Contributor. Your content manager? Editor. Remove accounts the moment someone no longer needs them.
Professor’s warning: Never share one admin login among several people. Give everyone their own account so you can adjust or revoke access individually and see who did what.
Extra layers
A web application firewall (from your host, a CDN or a security plugin) filters malicious traffic, and malware scanning alerts you to problems early. Keep HTTPS on everywhere. See our plugins page for security tool options.
Your assignment
- Enable 2FA on your WordPress admin account and your hosting account.
- Review Users and downgrade or remove anyone with more access than they need.
- Apply all pending updates (after a backup, which is next lesson).