Knowing how to secure your WordPress website matters because WordPress powers around 43% of the web, which is exactly why attackers love it. In 2025, researchers logged 11,334 new WordPress vulnerabilities, a 42% jump from the year before, and roughly 13,000 WordPress sites are compromised every day. Most of those sites weren’t hacked by some genius. They were hacked because nobody had bothered with the basics.
If you run a WordPress site, security isn’t an upgrade. It’s the cost of being online. The good news is that most attacks are preventable, and most of the work is a one-time setup followed by a habit of keeping things current. Here’s what to do, in plain order.

Why WordPress Security Should Be Your Problem
Small sites get hacked more than big ones, not less. Bots scan the internet looking for any site with a standard /wp-login.php path and a known plugin version. They don’t care whose site it is. They care whether they can get in. If your site is reachable and out of date, it’s a target.
Six things are at stake when WordPress security falls down.
- Customer data. If people trust you with their details, you owe them a reasonable lock on the door.
- Reputation. A hacked site is a story your customers tell other customers.
- Revenue. Downtime, cleanup, and lost sales add up fast. Industry estimates put small business recovery cost around US$14,500.
- Search visibility. Google flags compromised sites and de-indexes the worst. Traffic disappears overnight.
- Time. Cleaning a hacked site takes far longer than securing one that isn’t.
- Future cost. Prevention is dramatically cheaper than recovery. It’s not close.
Most owners only think about security after something goes wrong. That’s the most expensive moment to start.
What WordPress Is Actually Up Against
WordPress core itself is solid. The core team works hard, and core vulnerabilities are rare. According to Patchstack’s State of WordPress Security in 2026 (February 2026), 96% of WordPress vulnerabilities live in plugins and themes, not core. So the real risk is what you bolt on top.
A few patterns repeat in almost every WordPress breach.
Unauthorised access. Either by brute force (bots guessing username and password combinations) or by phishing (someone is fooled into handing over their login). Once an attacker is inside as an admin, they can do anything you can do.
Distributed denial of service (DDoS) attacks. A flood of fake traffic that knocks your site offline. Sometimes it’s a competitor. Sometimes it’s someone who didn’t like what you said. Either way, the site goes dark.
Malware. Software that gets onto your site to do harm. Ransomware locks you out and demands payment. Spyware quietly collects data. Conditional redirects send your visitors somewhere nasty. Trojans pretend to be helpful and aren’t.
Injection attacks. When an attacker types code into a form field instead of a normal answer. SQL injection uses database commands to read or destroy your data. Cross-Site Scripting (XSS) injects JavaScript that runs in your visitors’ browsers, often to steal session tokens or redirect them.
Patchstack’s 2026 report found the median time from a vulnerability being disclosed to attackers exploiting it at scale is now around five hours. Five hours. That’s the window. Which is why the rest of this list matters.
12 Ways to Secure Your WordPress Website
These are in rough order of importance. Do the first few even if you do nothing else.
1. Keep WordPress Core Updated
WordPress pushes updates every few months, and many of them patch security holes. Minor updates install automatically. Major releases need you (or someone) to click the button. If you’ve left a major release waiting, do it today after backing up.
2. Audit Your Plugins and Themes
Plugins and themes are where most attacks start. Every plugin you install is another door. The average WordPress site runs 20 to 30 of them, and each one is a potential way in.
A few rules.
- Update plugins and themes as soon as patches are released. The five-hour exploitation window means delay is dangerous.
- Remove anything you don’t actively use. Deactivated isn’t enough. Delete it.
- Stop using plugins that haven’t been updated in over a year. They’re abandoned, and abandoned code gets exploited.
- Only install plugins from trusted sources. Free nulled premium plugins from shady sites usually come with extras you didn’t ask for.
3. Strengthen How People Log In
Brute force attacks are the bluntest tool attackers have. They’re also the most preventable.
Use a strong password. Long beats clever. At least 16 characters, mixed case, numbers, symbols. Use a password manager so you’re not reusing the same thing across sites.
Don’t use “admin” as a username. It’s the first thing every brute force script tries. If your account is named admin, half the work is already done for the attacker.
Turn on two-factor authentication. A password plus a one-time code from your phone. Even if someone steals your password, they’re stuck without your device.
Limit login attempts. A plugin can lock out an IP after a handful of failed tries. This kills most brute force attempts cold.
Auto log out idle sessions. If you walk away from a logged-in dashboard on a shared computer, auto log out covers you.
Define user roles properly. Not everyone needs to be an admin. Editors, authors, and contributors all have less access on purpose. If one of those accounts gets compromised, the damage is limited.
4. Pay for Hosting That Takes Security Seriously
Cheap shared hosting is cheap because everyone is sharing the same resources, and sometimes the same vulnerabilities. If one site on the server is compromised, the whole neighbourhood is exposed.
Managed WordPress hosting from a reputable provider costs more but does more. Server hardening, automatic backups, malware scanning, regular patching, and isolation between sites. For any business website, this is one of the few places where spending more genuinely buys more.
If you’re not sure what your current host actually provides, ask them. Specifically. Get answers in writing.
5. Install a WordPress Security Plugin
A good security plugin handles a lot of the grunt work. Login monitoring, file integrity checks, malware scans, blocklist checks, and alerts when something looks off.
The well-known options are Sucuri, Wordfence, MalCare, Solid Security (formerly iThemes Security), and Jetpack. Pick one, configure it properly, and don’t run three at once. They’ll fight each other.
6. Turn On a Web Application Firewall
A Web Application Firewall (WAF) sits between your site and the internet and filters out malicious requests. It blocks the obvious stuff before it ever reaches WordPress. That includes SQL injection attempts, XSS payloads, known bad IPs, and common exploit patterns.
Some security plugins include a WAF. Cloudflare offers one for free at the network level, which has the bonus of also speeding up your site. Be aware that Patchstack’s 2026 research found around 87.8% of WordPress-specific exploits still slip past standard hosting firewalls, so a WAF is one layer in a stack, not a magic shield.
7. Back Up Your Website
Backups are the safety net under everything else. Even if you do everything right, you want a clean copy of your site sitting somewhere safe.
A few principles.
- Back up automatically. Manual backups get forgotten.
- Store backups off-site. A backup on the same server is no help when the server is compromised.
- Test that your backups actually restore. An untested backup is a guess.
- Keep multiple versions. The most recent backup might already contain the malware.
Most quality hosts include automated backups. If yours doesn’t, services like UpdraftPlus, BlogVault, and Solid Backups (formerly BackupBuddy) fill the gap.
8. Install an SSL Certificate
SSL (or more accurately, TLS) encrypts the connection between your site and your visitors. It’s been a baseline requirement for years now, both for security and for trust. Browsers actively warn users away from sites without it, and Google factors HTTPS into search rankings.
Most hosts include a free SSL certificate via Let’s Encrypt. If yours doesn’t, get one. There’s no good reason to run a modern site without HTTPS.
9. Secure the Computers You Log In From
This bit gets skipped a lot. Your WordPress site is only as secure as the device you use to log into it. If your laptop has malware, that malware can grab your session and walk straight into your dashboard.
Keep your operating system current. Run antivirus. Be careful with browser extensions, especially the ones you can’t remember installing. Don’t log into your WordPress admin from public computers or untrusted networks.
10. Get DDoS Protection
For most small sites, DDoS protection comes bundled with Cloudflare’s free tier, which is hard to argue with. Larger sites with more to lose should look at paid DDoS protection from Cloudflare, Sucuri, or similar. If your site going offline for a day would hurt the business, this is worth the conversation.
11. Change Default WordPress Configurations
Obscurity isn’t security on its own. It is a useful layer on top of everything else. The fewer hints you give an attacker about what’s behind your front page, the more work they have to do.
A handful of changes worth making, ideally with help from a developer.
- Change your login URL. The default
/wp-adminis the first place bots look. Plugins like WPS Hide Login can move it. - Disable file editing in the dashboard. By default, admins can edit theme and plugin code directly through WordPress. Turn that off so a compromised account can’t rewrite your files.
- Lock down
wp-config.php. This file holds your database credentials. Restrict access to it via your server configuration. - Change the database table prefix. Default tables start with
wp_. Changing the prefix on a fresh install makes some automated attacks harder. - Disable directory browsing. Stops anyone from listing the contents of your folders by typing the path into a browser.
These are small changes that add up. None of them stops a determined attacker on their own. Together, they raise the cost of breaking in.
12. Have a Plan for When Something Goes Wrong
Even with everything above in place, things can still go wrong. Knowing what to do in the moment is the difference between a bad day and a much worse one.
Write it down. Three paragraphs in a shared document are enough. Who notices first, who they call, and what happens next. Where the backups live and who can restore them. Which passwords need changing, in what order, and who has access to do it? What you tell customers, and when.
A Note on What This Doesn’t Cover
The steps above are just the baseline. They will stop the vast majority of automated attacks, which are what hit most small and mid-size sites. What they won’t stop is a targeted attack from someone who actually wants in. That’s a different conversation, involving threat modelling, penetration testing, and a security posture matched to what you’re protecting.
If your site handles payments, sensitive data, or anything regulated, the twelve steps above are the floor, not the ceiling. Talk to someone who can look at your specific situation.
If the worst has already happened, what happens if my website gets hacked covers what to do next. Ongoing support and maintenance keep the basics in good shape.
Talk to us about your WordPress site.