X
X
X
X

WordPress Security Checklist: 10 Steps to Protect Your Site

HomepageArticlesWordPressWordPress Security Checklist: 10 St...

In short: WordPress security is not solved by a single plugin. It is the sum of small steps applied regularly. Up-to-date software, strong passwords with two-factor authentication, a limited number of administrator accounts, correct file permissions, SSL and a backup you have actually tested will stop most attacks. You can work through the 10-step checklist below in order.

  • Who it is for: Businesses, agencies and site owners who manage their own WordPress site.
  • How long it takes: The initial setup takes an hour or two on most sites; after that it is a matter of short, regular checks.
  • What you need: A WordPress administrator account and access to your hosting control panel.

Why Are WordPress Sites Targeted?

Because WordPress is so widely used, attacks are usually aimed not at one particular site but at every site carrying a known vulnerability. Automated scanners look for outdated plugin versions, weak passwords and exposed files. Even a small site is within the scope of these scans.

The entry points attackers use most often are:

  • Outdated plugins and themes: Components with a published vulnerability whose patch has not been installed.
  • Weak or reused passwords: Passwords exposed in another breach are tried on the login page.
  • Software from unknown sources: Paid themes and plugins distributed without a licence often contain malicious code.
  • Excessive privileges: Giving everyone the administrator role, or leaving files writable.

WordPress Security Checklist: 10 Steps

WordPress security layers: secure connection, plugin and database security, file permissions, backups and firewall

1. Keep core, themes and plugins up to date

Security patches arrive through updates. WordPress installs minor releases automatically by default; for plugins and themes you can enable auto-updates one by one on the Plugins screen in the dashboard. Take a backup before major version upgrades.

2. Delete themes and plugins you do not use

The files of a deactivated plugin remain on the server and can still be exploited if they contain a vulnerability. Do not just deactivate unused plugins, delete them. Remove all themes except your active theme and one default theme.

3. Use strong passwords and two-factor authentication

Set a unique, long password for every account and store passwords in a password manager. Turn on two-factor authentication (2FA) for administrator and editor accounts; in WordPress this is added with a plugin. Even if a password is stolen, the second step blocks the login.

4. Limit administrator accounts

Give the administrator role only to people who really need it. The Editor or Author role is enough for people who enter content. Do not use "admin" as a username, and close the accounts of former employees and previous agencies.

5. Limit login attempts and disable XML-RPC

By default WordPress does not limit failed login attempts. A plugin that restricts the number of attempts slows down password-guessing attacks. The same attacks can be carried out through XML-RPC, so disable that interface if you do not use it. The steps are covered in our guide on what XML-RPC is in WordPress.

6. Enforce SSL

Login details sent over an unencrypted connection can be read on the network. Serve your whole site over HTTPS and redirect HTTP requests to HTTPS. For the basics, see what an SSL certificate is; for the migration steps, see our HTTP to HTTPS migration guide.

7. Protect file permissions and wp-config.php

As a general rule, directories run with 755 and files with 644 permissions. Use a stricter permission (for example 600) for wp-config.php, which contains your database password. Never set any directory to 777; if a plugin asks for it, the problem is file ownership, not permissions.

8. Disable file editing in the dashboard

The theme and plugin editor in the dashboard lets anyone who takes over an account write code directly. You can disable the editor by adding this line to wp-config.php:

define( 'DISALLOW_FILE_EDIT', true );

In addition, blocking PHP execution in the wp-content/uploads directory prevents an uploaded malicious file from running. On servers using Apache, add a .htaccess file with the following content to that directory:

<FilesMatch "\.php$">
  Require all denied
</FilesMatch>

9. Take regular backups and test the restore

A backup is the only thing that brings your site back when every other measure has failed. Back up files and the database together, keep a copy off the server, and try a restore a few times a year. For details, see our article on website backup strategy.

10. Use a supported PHP version

PHP versions that have reached end of life no longer receive security patches. Run your site on a current PHP version that your theme and plugins are compatible with. You can change the version from your hosting control panel; this step also improves speed, as explained in our WordPress speed optimization article.

How Often Should Each Check Be Done?

  • Weekly: Install pending updates and confirm that the backup has run.
  • Monthly: Review the user list, delete unused plugins, and check for administrator accounts you do not recognise.
  • Quarterly: Run a test restore from backup, and check the PHP version and file permissions.
  • When staff or agencies change: Close the related accounts and change shared passwords.

First Steps If Your Site Has Been Compromised

  1. Put the site into maintenance mode so visitors are not exposed to malicious content.
  2. Change all passwords: WordPress accounts, hosting panel, FTP and database.
  3. Restore a clean backup. Choose one taken before the problem started.
  4. Update every component and delete unused plugins; otherwise the same vulnerability will be used again.
  5. Check the user list and remove accounts you do not recognise.
  6. Inform your hosting provider. Server logs help identify the point of entry.

Common WordPress Security Mistakes

  • Installing several security plugins: Plugins that do the same job conflict and slow the site down. Choose one.
  • Relying on a plugin alone: A security plugin does not close the vulnerability in an outdated plugin.
  • Keeping the backup on the same server: Anyone who gains access to the server can delete the backup too.
  • Using unlicensed themes and plugins: The licence fee saved is small compared with the cost of a clean-up.
  • Treating a hidden login URL as enough: Changing the login address reduces scans, but it does not replace password and update discipline.

If you are looking for a comprehensive reference, the official WordPress hardening guide covers the technical details of these steps.

WordPress Security with ÇAP Hosting

ÇAP Hosting hosting plans come with a free SSL certificate, PHP 8.x support and the CWP control panel, so you can manage the PHP version, file permissions and SSL from the panel. If you are setting up a new site, start with our WordPress installation guide, and if you get stuck on any step in this list, get in touch with us.

Frequently Asked Questions

Is WordPress a secure system?

WordPress core receives regular security updates. Most problems do not come from core but from outdated plugins and themes, weak passwords and software from unknown sources. A WordPress site that is kept up to date and configured correctly can be used safely.

Do I need a plugin for WordPress security?

It is not mandatory, but it makes the job easier. Features such as login attempt limiting and two-factor authentication are not built into WordPress, so they are added with a plugin. A plugin complements update, password and backup discipline; it does not replace it.

How do I know if my WordPress site has been hacked?

Common signs are administrator accounts you do not recognise, content or links you did not add, visitors being redirected to other sites, titles in a foreign language in search results and an unexplained rise in resource usage. If you see these, change your passwords and restore a clean backup.

Is it safe to auto-update plugins?

For most sites the benefit of auto-updates outweighs the risk, because vulnerabilities start being scanned for shortly after they are published. If you take regular backups, a faulty update can be rolled back. On critical e-commerce sites it is safer to try updates in a test environment first.

Does an SSL certificate protect my site from attacks?

SSL encrypts the data between the visitor and the server and prevents login details from being read on the network. It does not stop plugin vulnerabilities or weak passwords. SSL is therefore necessary, but not sufficient on its own.


Powered by WISECP
Top