Skip to main content

Security Checklist

A 12-Step Checklist for How to Secure a WordPress Site

WordPress powers a huge share of the web, which is exactly why automated bots scan it around the clock. This checklist covers the changes that close the most common doors attackers use.

24/7

Human support for security questions

Daily

Automatic backups on every plan

Free

Auto-renewing SSL included

30-Day

Money-back guarantee

In short

Securing a WordPress site starts with keeping core, themes, and plugins updated, using strong unique passwords with two-factor authentication, and installing a firewall or security plugin to block malicious requests before they reach the site. Add correct file permissions, disable the built-in file editor, limit login attempts, and keep daily backups running so any successful attack can be undone quickly rather than becoming a rebuild.

WordPress runs a significant share of websites, which makes it a standing target for automated bots that scan for outdated plugins, weak passwords, and known vulnerabilities around the clock rather than picking on any one site specifically. Most successful attacks aren't sophisticated; they exploit a plugin that was never updated or a password that was reused somewhere else.

The good news is that a short list of concrete changes closes off the overwhelming majority of these attempts. None of the steps below require custom development, and most take a few minutes each, but skipping even one, like leaving the file editor enabled or running plugins months out of date, leaves an easy opening.

Lock Down Access: Passwords, 2FA, and User Roles

Weak or reused passwords remain one of the most common ways into a WordPress site, especially for accounts created years ago under looser rules. Require long, unique passwords for every user, remove accounts that are no longer needed, and give each person only the role their job actually requires rather than defaulting everyone to Administrator.

Two-factor authentication adds a second check beyond the password, usually a time-based code from an app, so a leaked or guessed password alone isn't enough to log in. It takes only a few minutes to set up through a plugin and stops a large share of automated login attempts cold, since bots have the password but never the second factor.

Keep Core, Themes, and Plugins Current

Outdated plugins and themes are the single most common entry point, because once a vulnerability is publicly disclosed, bots start scanning for it within hours. Turn on automatic updates where possible, and check the dashboard for available updates on any plugin or theme at least weekly.

Remove plugins and themes that aren't actively in use rather than just deactivating them, since inactive code sitting in the file system can still be exploited if it contains a known flaw. Fewer active components also means fewer things to keep patched going forward.

Add a Firewall and a Security Plugin

A web application firewall inspects incoming requests and blocks known attack patterns, such as SQL injection attempts or requests probing for common plugin vulnerabilities, before they ever reach WordPress itself. A security plugin adds this layer along with malware scanning and login monitoring in one place.

Configure the plugin to email an alert on suspicious activity, such as repeated failed logins or a file change outside of a normal update, so a problem gets noticed in hours rather than being discovered weeks later when the site is already flagged by a browser or search engine.

Harden Files, Permissions, and the Server Layer

Set file permissions so that WordPress core files aren't writable by the web server unless an update is actively running, and disable the built-in theme and plugin file editor in the dashboard, since that editor becomes a direct code-execution tool if an attacker gets into an account.

Beyond the application layer, the server it runs on matters too: a host with daily backups, active malware monitoring, and a cPanel-style panel that supports one-click installers keeps the underlying environment patched and makes it possible to restore a clean copy within minutes if something does get through.

How to Secure a WordPress Site: 12-Step Checklist

Hosting That Backs Up Every Layer of Security

A security checklist covers the WordPress application, but the hosting environment underneath it matters just as much. Daily backups mean a successful attack is a restore, not a rebuild, and free auto-renewing SSL closes off one more class of interception attempts.

24/7 human support means a suspicious file change or unexpected login can get a second opinion immediately, rather than waiting until business hours while an attacker has more time to move around.

  • Daily backups so any breach is reversible in minutes
  • Free auto-renewing SSL on every hosting plan
  • cPanel-style panel with one-click installers for WordPress
  • 24/7 human support for anything that looks off

Why Hosting Cheap

What you get

Daily Backups

A recent, restorable backup turns a successful hack into a quick recovery instead of a rebuild from scratch.

Free Auto-Renewing SSL

Encrypts traffic between visitors and the site without any manual certificate renewal to forget.

24/7 Human Support

Real people are available to help investigate anything that looks like a compromise, day or night.

cPanel-Style Panel

One-click installers and clear file management make it easy to check permissions and remove unused plugins.

Pure NVMe SSD + LiteSpeed

Security plugins and firewalls add overhead; fast storage keeps the site responsive even with extra scanning running.

30-Day Money-Back Guarantee

Move to a more secure hosting setup and test it risk-free for the first month.

How It Works

Get set up in a few steps

1

Update everything and enable 2FA

Patch core, themes, and plugins, then add two-factor authentication to every admin account.

2

Install a firewall and security plugin

Block known attack patterns before they reach WordPress and turn on alerts for suspicious activity.

3

Harden files and keep daily backups

Lock down file permissions, disable the file editor, and confirm backups are running automatically.

Included

Everything you need, on every plan

  • Use long, unique passwords for every account
  • Enable two-factor authentication for admin logins
  • Update WordPress core, themes, and plugins regularly
  • Remove unused plugins and themes entirely
  • Install a firewall or security plugin with alerts
  • Disable the built-in theme and plugin file editor
  • Set correct file permissions on core files
  • Confirm daily backups are running and restorable

FAQ

Frequently asked questions

What is the single most important step in how to secure a WordPress site?

Keeping core, themes, and plugins updated stops the largest share of attacks, since most successful hacks exploit a known, already-patched vulnerability rather than something new. Pair that with strong passwords and two-factor authentication for the biggest impact.

Do I really need a security plugin if I already have a firewall from my host?

A host-level firewall blocks a lot of malicious traffic before it reaches the server, but a WordPress-level security plugin adds malware scanning, login monitoring, and file-change alerts specific to the application, so the two work well together rather than replacing each other.

How often should I check for plugin updates?

Checking at least weekly is a reasonable minimum, and enabling automatic updates for minor releases reduces the window between a vulnerability being disclosed and the site being patched.

Is two-factor authentication difficult to set up?

No. Most 2FA plugins take a few minutes to configure and use an authenticator app to generate a time-based code, which is scanned in once and then used at every login alongside the password.

Why disable the theme and plugin file editor?

That built-in editor lets anyone logged in as an administrator edit PHP files directly from the dashboard, which means an attacker who gets into an admin account can insert malicious code in seconds. Disabling it removes that shortcut without affecting normal site editing.

What should I do if I've followed this checklist but still suspect a hack?

Scan the site with a security plugin, check for unfamiliar admin accounts or files, and restore from a recent clean backup if anything looks altered, then reset all passwords before bringing the site back online.

Host Your Secured Site Somewhere That Backs It Up Daily

Get free SSL, daily backups, and 24/7 human support as the foundation under your WordPress hardening checklist.

Get Started