
WordPress Security Guide: 15 Essential Steps
WordPress powers 43% of the web, making it a prime target for hackers. These 15 steps will protect your site from vulnerabilities.
Author: Meiko Neuman
Founder and web strategist, Kodulehe Haldus
Why is WordPress a Target?
43% of the world's websites = millions of similar vulnerabilities. One vulnerable plugin = millions of potential victims. Bots are scanning constantly.
15 Steps to Protect WordPress
1. Update Everything WordPress core, plugins, and themes. 60% of hacks result from outdated software.
2. Remove Unused Plugins and Themes Even inactive plugins serve as attack vectors.
3. Strong Admin Password + 2FA WP 2FA plugin (free). Google Authenticator.
4. Change the Admin Username "admin" is the first one a bot tries. Create a new admin user and delete the old one.
5. Change the Login URL WPS Hide Login plugin. /wp-admin → /secure-login
6. Limit Login Attempts Use the "Limit Login Attempts Reloaded" plugin. 3 failed attempts = IP blocked.
7. Disable XML-RPC `xmlrpc.php` is a frequent attack vector. If you don't use it, block it.
8. Disable File Editing in the Admin Panel Add to `wp-config.php`: `define('DISALLOW_FILE_EDIT', true);`
9. Correct File Permissions - Files: 644 - Directories: 755 - wp-config.php: 600
10. Database Prefix The default is `wp_`. Change it to `wp_xY9k_` or similar. Recommended plugin: iThemes Security.
11. Web Application Firewall (WAF) - Wordfence (free tier) - Sucuri (paid) - Cloudflare WAF
12. Whitelist Only Local IPs for Admin Panel Wordfence Country Blocking.
13. SSL Certificate Let's Encrypt, free.
14. Daily Backups UpdraftPlus + Google Drive. 90-day retention.
15. Malware Scanning Wordfence or Sucuri SiteCheck. Run weekly.
wp-config.php Security Settings
define('DISALLOW_FILE_EDIT', true);
define('FORCE_SSL_ADMIN', true);
define('WP_AUTO_UPDATE_CORE', 'minor');
.htaccess Security Rules
# Disable direct access to wp-config.php
<Files wp-config.php>
order allow,deny
deny from all
</Files># Disable XML-RPC
<Files xmlrpc.php>
order deny,allow
deny from all
</Files>
`
Signs That Your Site Has Been Hacked
- Strange redirects to other pages
- Unknown admin users
- Unexplained slow performance
- Google "This site may be hacked" warning
- Malware notification from your hosting provider
- Spam emails originating from your domain
Summary
WordPress is secure if it is maintained. Continuous self-maintenance requires expertise—or a professional management partner.
Need help with your website?
Our team maintains, optimises and protects your website. Pricing is agreed based on scope.
Request a quoteAbout the author
Meiko Neuman — Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.