Back to blog
    Header image for the article "WordPress Security Guide: 15 Essential Steps"
    Security22/04/20268 min

    WordPress Security Guide: 15 Essential Steps

    WordPress powers 43% of the web, making it a prime target for hackers. These 15 steps will protect your site from vulnerabilities.

    Author: Meiko Neuman

    Founder and web strategist, Kodulehe Haldus

    Why is WordPress a Target?

    43% of the world's websites = millions of similar vulnerabilities. One vulnerable plugin = millions of potential victims. Bots are scanning constantly.

    15 Steps to Protect WordPress

    1. Update Everything WordPress core, plugins, and themes. 60% of hacks result from outdated software.

    2. Remove Unused Plugins and Themes Even inactive plugins serve as attack vectors.

    3. Strong Admin Password + 2FA WP 2FA plugin (free). Google Authenticator.

    4. Change the Admin Username "admin" is the first one a bot tries. Create a new admin user and delete the old one.

    5. Change the Login URL WPS Hide Login plugin. /wp-admin → /secure-login

    6. Limit Login Attempts Use the "Limit Login Attempts Reloaded" plugin. 3 failed attempts = IP blocked.

    7. Disable XML-RPC `xmlrpc.php` is a frequent attack vector. If you don't use it, block it.

    8. Disable File Editing in the Admin Panel Add to `wp-config.php`: `define('DISALLOW_FILE_EDIT', true);`

    9. Correct File Permissions - Files: 644 - Directories: 755 - wp-config.php: 600

    10. Database Prefix The default is `wp_`. Change it to `wp_xY9k_` or similar. Recommended plugin: iThemes Security.

    11. Web Application Firewall (WAF) - Wordfence (free tier) - Sucuri (paid) - Cloudflare WAF

    12. Whitelist Only Local IPs for Admin Panel Wordfence Country Blocking.

    13. SSL Certificate Let's Encrypt, free.

    14. Daily Backups UpdraftPlus + Google Drive. 90-day retention.

    15. Malware Scanning Wordfence or Sucuri SiteCheck. Run weekly.

    wp-config.php Security Settings

    define('DISALLOW_FILE_EDIT', true);
    define('FORCE_SSL_ADMIN', true);
    define('WP_AUTO_UPDATE_CORE', 'minor');
    

    .htaccess Security Rules

    # Disable direct access to wp-config.php
    <Files wp-config.php>
    order allow,deny
    deny from all
    </Files>

    # Disable XML-RPC <Files xmlrpc.php> order deny,allow deny from all </Files> `

    Signs That Your Site Has Been Hacked

    • Strange redirects to other pages
    • Unknown admin users
    • Unexplained slow performance
    • Google "This site may be hacked" warning
    • Malware notification from your hosting provider
    • Spam emails originating from your domain

    Summary

    WordPress is secure if it is maintained. Continuous self-maintenance requires expertise—or a professional management partner.

    Need help with your website?

    Our team maintains, optimises and protects your website. Pricing is agreed based on scope.

    Request a quote

    About the author

    Meiko Neuman Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.

    Related articles