Skip to content
WordPress Website Security: 20 Practical Ways to Protect Your Site
Maintenance & Security

WordPress Website Security: 20 Practical Ways to Protect Your Site

WordPress powers a very large share of the web, from personal blogs to busy online stores. That popularity is exactly why it attracts attackers. Bots scan the internet around the clock looking for outdated plugins, weak passwords and misconfigured servers, and they do not care whether your site belongs to a multinational or a family-run shop in Kochi.

The good news is that WordPress core itself is actively maintained and reasonably secure. Most compromises we are asked to clean up trace back to a handful of avoidable causes: unpatched plugins or themes, reused passwords, nulled (pirated) premium plugins, cheap shared hosting with poor isolation, and no backups to fall back on. Fix those, and you remove the vast majority of risk.

This guide brings together 20 practical WordPress security measures, grouped into logical layers, with a clear indication of what each one protects against. You do not need to be a developer to apply most of them, and you certainly do not need to do all 20 in one afternoon. Start with the first five and work down.

Key takeaways

  • Most WordPress hacks exploit outdated plugins and themes or weak, reused passwords, not WordPress core.
  • Two-factor authentication, strong unique passwords and limited admin accounts block most login-based attacks.
  • Off-site backups with tested restores are your safety net when everything else fails.
  • A web application firewall, good hosting and HTTPS form the outer defence layer.
  • Never install nulled plugins or themes; they are a common source of hidden malware.
  • Security is ongoing: schedule updates, reviews and monitoring rather than treating it as a one-time setup.

How WordPress sites actually get hacked

Understanding the common attack routes makes it much easier to prioritise. Broadly, attackers look for:

  • Vulnerable plugins and themes. When a flaw is publicly disclosed, automated tools start probing for unpatched sites within days, sometimes hours.
  • Credential attacks. Brute-force attempts and “credential stuffing” use passwords leaked from other websites to try to log in to yours.
  • Compromised hosting. On poorly isolated shared servers, one infected site can affect its neighbours.
  • Malicious code from untrusted sources. Nulled premium plugins frequently include backdoors.
  • Human error. Phishing emails, shared logins and former staff who still have admin access.

The outcomes range from spam links injected into your pages and redirects to scam sites, to stolen customer data, blacklisting by browsers and email providers, and your server being used to send spam. For a wider view of common web application risks, the OWASP Foundation publishes widely respected guidance, including its Top 10 list.

Layer 1: Keep the software clean and current

1. Update WordPress core, plugins and themes regularly

This is the single most important habit. Enable automatic minor and security releases for WordPress core, and review plugin and theme updates at least weekly. For major updates, take a backup and test on a staging site first. Our website maintenance checklist sets out a safe update routine.

2. Remove plugins and themes you do not use

Deactivated plugins still sit on the server, and their files can still be exploited. Delete anything you are not actively using, and keep only one default theme as a fallback besides your active theme.

3. Install only well-maintained, reputable extensions

Before installing a plugin, check when it was last updated, how many active installations it has, whether it is tested with your WordPress version and how quickly the author responds to support questions. The official WordPress.org plugin directory shows all of this. An abandoned plugin is a future vulnerability.

4. Never use nulled plugins or themes

“Free” copies of premium plugins from unofficial sites are one of the most common sources of malware we encounter. They often contain hidden code that creates admin users or injects spam links. Buy licences from the original developer; the cost is tiny compared with a clean-up.

5. Keep PHP and server software up to date

WordPress runs on PHP, and older PHP versions eventually stop receiving security fixes. Ask your host which version you are on and upgrade to a currently supported one, testing on staging first because older themes sometimes break on newer PHP.

Layer 2: Lock down logins and user accounts

6. Use strong, unique passwords for every account

Every admin, editor, hosting, database and SFTP account needs a long, unique password generated by a password manager. Reused passwords are the reason credential stuffing works so well.

7. Turn on two-factor authentication (2FA)

2FA requires a second step, usually a code from an authenticator app, before login. Even if a password leaks, the attacker cannot get in. Make it mandatory for administrators and shop managers at a minimum.

8. Limit login attempts and add bot protection

Restrict repeated failed logins from the same IP address and add a CAPTCHA or similar challenge to login, registration and checkout forms. This sharply reduces brute-force noise and server load.

9. Apply the principle of least privilege

Give each person the lowest role they need. Content writers should be Authors or Editors, not Administrators. WooCommerce staff typically need the Shop Manager role. Review users every month and remove former staff, freelancers and agencies promptly.

10. Avoid the “admin” username and obvious display names

Do not use “admin” or your domain name as a username, and set a public display name that differs from the login name. It is a small step, but it removes one piece of information attackers rely on.

Quick win: Open Users in your WordPress dashboard right now and filter by Administrator. If you see anyone who has left the business, or accounts you do not recognise, remove or downgrade them today. Unknown admin accounts can also be a sign of an existing compromise.

Layer 3: Harden WordPress configuration

11. Disable file editing in the dashboard

By default, administrators can edit theme and plugin code from inside WordPress. If an attacker gains admin access, this lets them plant malicious code instantly. Adding define('DISALLOW_FILE_EDIT', true); to wp-config.php removes the editor.

12. Set correct file permissions and protect wp-config.php

Typical recommendations are 755 for folders and 644 for files, with wp-config.php tightened further where your host allows. This file contains database credentials and security keys, so it should never be publicly readable.

13. Change the default database table prefix on new installs

Using a custom prefix instead of wp_ makes some automated SQL injection attempts less effective. It is easiest to set during installation; changing it on a live site needs care and a backup.

14. Disable XML-RPC if you do not need it

XML-RPC is an older remote access interface that is often abused for brute-force attacks. If you do not use the WordPress mobile app, Jetpack or a service that depends on it, block it at server or plugin level.

15. Refresh security keys and salts after an incident

The keys in wp-config.php encrypt login cookies. Generating new ones logs every user out, which is exactly what you want after a suspected breach or when someone with access leaves.

Layer 4: Protect the server and connection

16. Choose quality hosting with proper isolation

Good hosting provides account isolation, server-level firewalls, malware scanning, current PHP versions, automatic backups and responsive support. The cheapest shared plans rarely offer all of these. Our guide to choosing a domain name and web hosting explains what to look for.

17. Enforce HTTPS everywhere

An SSL/TLS certificate encrypts data between visitors and your site, protecting login details and customer information. Redirect all HTTP traffic to HTTPS, fix mixed-content warnings and make sure the certificate auto-renews. Browsers flag non-HTTPS pages as “Not secure”, which also hurts trust.

18. Add a web application firewall (WAF)

A WAF filters malicious requests before they reach WordPress. It can be cloud-based (sitting in front of your site, often bundled with a CDN) or plugin-based (running on your server). Cloud-based options also help absorb traffic floods.

Layer 5: Detect, recover and respond

19. Keep automated, off-site backups and test restores

Back up files and database daily (more often for busy shops), store copies away from your web server and keep several weeks of history. Every quarter, restore a backup to staging to prove it works. A backup you have never restored is a hope, not a plan.

20. Monitor activity, file changes and uptime

Use an activity log to record logins, user changes and plugin installs, enable file integrity monitoring to flag unexpected changes, and set up uptime alerts. Add your site to Google Search Console so you are notified if Google detects malware or hacked content.

WordPress security measures at a glance

Priority Measure Protects against Effort
Critical Regular updates, remove unused plugins Known plugin/theme vulnerabilities Low, ongoing
Critical Strong passwords and 2FA Brute force, credential stuffing Low
Critical Off-site backups with tested restores Total data loss, ransomware, failed updates Low to medium
High WAF, login limiting, quality hosting Automated attacks, bad bots, server compromise Medium
High Least-privilege user roles Insider mistakes, stolen staff accounts Low
Medium Disable file editing and XML-RPC, file permissions Escalation after a breach, brute force Low (technical)
Medium Activity logs and file monitoring Undetected intrusions Medium

Extra precautions for WooCommerce stores

Online stores hold customer names, addresses and phone numbers, and process payments, so the stakes are higher.

  • Use hosted or tokenised payment flows so card details are handled by the payment gateway, not stored on your server. Our comparison of payment gateway integration in India covers how the leading gateways handle this.
  • Protect checkout from card-testing bots with rate limiting and CAPTCHA on checkout and account creation.
  • Restrict access to order data. Only staff who fulfil orders need to see customer details.
  • Back up more frequently during sale periods so you never lose a day of orders.
  • Review data retention. Collect only what you need, and update your privacy policy to reflect how customer data is used, in line with India’s Digital Personal Data Protection Act.

Signs your WordPress site may already be hacked

Watch for these warning signs:

  • Visitors (especially from Google or on mobile) are redirected to unrelated or scam websites.
  • Google search results show your site with spammy titles, foreign-language text or pharmaceutical keywords.
  • Your browser or Search Console displays a “This site may be hacked” or “Deceptive site ahead” warning.
  • Unknown administrator accounts appear in the Users list.
  • Your host suspends the account for sending spam or using excessive resources.
  • Unfamiliar files appear in the uploads folder, or core files have recent modification dates you cannot explain.

What to do if your site is compromised

  1. Stay calm and contain. Put the site in maintenance mode if it is redirecting visitors or serving malware.
  2. Change every password: hosting, WordPress admins, SFTP, database and email accounts linked to the site.
  3. Take a copy of the infected site for investigation before cleaning, so evidence is not lost.
  4. Identify the entry point. Check access logs, recently changed files and outdated plugins. Without finding the cause, reinfection is likely.
  5. Clean or restore. Restore a known-clean backup from before the infection, or replace core, plugin and theme files with fresh copies and remove injected code from the database.
  6. Patch the hole: update or remove the vulnerable component, and refresh security keys and salts.
  7. Request a review in Google Search Console once the site is clean, if Google flagged it.
  8. Inform affected parties where customer data may have been exposed, and take advice on any reporting obligations.

Important: Simply restoring an old backup without fixing the vulnerability usually leads to the site being reinfected within days. Always close the entry point.

A practical security routine

Security works best as a schedule rather than a one-off project:

  • Weekly: apply updates, check security alerts, confirm backups are completing.
  • Monthly: review user accounts, scan for malware, delete unused plugins.
  • Quarterly: test a backup restore, rotate key passwords, review plugin health.
  • Yearly: full security audit, PHP upgrade, review hosting and firewall setup.

How Ciphercup can help

Since 2014, our team in Bangalore and Kochi has built and looked after WordPress and WooCommerce sites for businesses across India. If you want these 20 measures handled properly without spending your own evenings on them, our website maintenance service covers updates, daily backups, uptime monitoring and security hardening as standard, and our web development team can rebuild sites that have outgrown patching.

Worried your site might already be at risk? Contact us for a no-pressure review, or see the Website Care Plan on our pricing page.

Frequently asked questions

Yes. WordPress core is actively maintained by a large community and receives regular security releases. Most compromises come from outdated or poorly coded plugins and themes, weak or reused passwords, nulled software and low-quality hosting rather than from core itself. With sensible practices such as updates, two-factor authentication, backups and a firewall, WordPress is a solid platform for business sites and online stores.

A reputable security plugin is helpful for most sites because it can add login protection, two-factor authentication, malware scanning, activity logging and file change alerts in one place. It is not a substitute for updates, good hosting and backups, though. Some hosts and cloud firewalls already provide several of these features, so avoid stacking multiple overlapping security plugins that can slow the site or conflict.

Common signs include visitors being redirected to unrelated or scam websites, spammy titles or foreign-language text appearing in Google results, browser warnings such as deceptive site ahead, unknown administrator accounts, unexplained new files and your host suspending the account for spam or heavy resource use. Google Search Console also sends alerts if it detects malware or hacked content on your site.

Nulled plugins and themes are pirated copies of premium products distributed through unofficial websites. They frequently contain hidden code that creates secret admin accounts, injects spam links or opens a backdoor for attackers. They also do not receive legitimate updates, so security fixes never reach you. Buying a genuine licence from the original developer costs far less than cleaning up a compromised website.

Most business websites should be backed up at least daily, covering both files and the database, with copies stored away from the web server and kept for several weeks. Busy online stores may need more frequent database backups so recent orders are never lost. Equally important is testing a restore every few months, because a backup you have never restored may not work when you need it.

Written by the Ciphercup Team

Web designers, developers and marketers at Ciphercup Technologies, Bangalore & Kochi — building websites, online stores and digital campaigns since 2014. About us

Get A Free Quote?

We are committed to provide solutions to your business problems. Get the help from our experts by posting your business / service requests. Please provide the information about your business needs to help us serve you better.
Enquire Now Chat on WhatsApp