New: “AI + WordPress” lessons just dropped — build smarter sites in half the time.

Security Basics: Updates, 2FA and Least Privilege

Lock down your site with timely updates, strong logins, two-factor authentication and the right user roles for every person.

WordPress core is actively maintained by a dedicated security team, but most site compromises come from the things around it: outdated plugins, weak passwords and too many admins. Three habits block the vast majority of trouble. Let’s build them.

Habit 1: Update promptly

  • Keep WordPress core, themes and plugins updated. Minor core releases, which often include security fixes, update automatically by default.
  • Delete unused themes and plugins rather than leaving them deactivated. Keeping one default theme as a fallback is fine.
  • Ask your host to keep PHP on a currently supported version.

Habit 2: Strong logins and 2FA

  • Use a password manager and a long, unique password for every account, including hosting, domain registrar and email.
  • Turn on two-factor authentication (2FA) for every admin. A 2FA or security plugin adds a code from an authenticator app at login. Some newer options support passkeys too.
  • Limit login attempts or use your host’s or security plugin’s login protection to slow down bots.
  • Protect the email account tied to your admin user. Whoever controls that inbox can reset your password.

Habit 3: Least privilege

Give every person the lowest role that lets them do their job. WordPress’s built-in roles are:

  • Administrator: full control. Keep this to as few people as possible.
  • Editor: manages and publishes all posts and pages, including other people’s.
  • Author: writes, publishes and manages their own posts.
  • Contributor: writes and edits their own posts but can’t publish them.
  • Subscriber: can manage their own profile and little else.

A guest writer? Contributor. Your content manager? Editor. Remove accounts the moment someone no longer needs them.

Professor’s warning: Never share one admin login among several people. Give everyone their own account so you can adjust or revoke access individually and see who did what.

Extra layers

A web application firewall (from your host, a CDN or a security plugin) filters malicious traffic, and malware scanning alerts you to problems early. Keep HTTPS on everywhere. See our plugins page for security tool options.

Your assignment

  1. Enable 2FA on your WordPress admin account and your hosting account.
  2. Review Users and downgrade or remove anyone with more access than they need.
  3. Apply all pending updates (after a backup, which is next lesson).