How secure is your WordPress website?

Your WordPress website could be seriously vulnerable to malware if it's built from multiple free extensions, a survey shows.

16 Mar

2022

Glödande blå WordPress-logotyp på en mörk bakgrund med upprepade mindre logotyper.
Daniel Herstedt
Managing Director
Security
5
Min

WordPress powers over 43% of all websites on the internet – making it the most targeted CMS on the market. A site that isn’t actively maintained is a matter of when it gets hacked, not if.

The good news: the vast majority of attacks can be prevented with relatively simple measures. Here we walk through the most important steps.

Why hackers love WordPress

It’s rarely because you specifically are a target. Attacks on WordPress are mostly automated – bots scan the internet for known vulnerabilities in outdated plugins, themes and WordPress versions. If your site has a known vulnerability, they’ll find it.

The most common attacks are:

  • Brute force – bots try to guess your password through thousands of login attempts
  • Plugin vulnerabilities – outdated plugins with known holes are exploited automatically
  • SQL injections – attacks against your database via forms or URLs
  • Malware injection – malicious code is hidden in your site’s files
  • DDoS attacks – your server is overwhelmed with traffic until it goes down

10 concrete steps for better WordPress security

1. Keep WordPress, plugins and themes updated

The single most important thing you can do. When a security flaw is found in a plugin, an update is released – often within days. If you don’t update quickly, you’re vulnerable.

Enable automatic updates for minor security releases. For major updates, always test on staging before updating the live site.

2. Remove plugins and themes you don’t use

Inactive plugins and themes are still a security risk. Delete them completely rather than just deactivating them. Fewer plugins means a smaller attack surface.

3. Use strong passwords and two-factor authentication

“admin” as username and “password123” as password are still combinations people use. Use a unique, long password of at least 16 characters and enable 2FA on all admin users.

4. Limit login attempts

Block IP addresses that try to log in repeatedly. Plugins like Limit Login Attempts Reloaded do this automatically and effectively eliminate brute force attacks.

5. Change the default login URL

By default, the WordPress login is accessible via /wp-admin or /wp-login.php. Every hacker knows this. Plugins like WPS Hide Login let you change it to something unique.

6. Install a security plugin

Wordfence and Sucuri are the most widely used security plugins. They offer a firewall, malware scanning, real-time monitoring and blocking of suspicious traffic.

7. Choose a secure host

Hosting is the foundation. A good WordPress host offers automatic backups, server-side firewall, malware scanning and isolated environments so a compromised site doesn’t affect others on the same server.

8. Take regular backups

No matter how securely you build, something can go wrong. A current backup is your last line of defence. Back up daily and store copies off-server – for example in Google Drive or Amazon S3.

9. Use SSL (HTTPS)

SSL encrypts the connection between the browser and your server and is now a basic requirement. Google actively warns visitors when a site lacks SSL. Most hosts offer free SSL via Let’s Encrypt.

10. Monitor and review regularly

Use Google Search Console to check your site isn’t flagged as malicious. Review your user accounts regularly and remove inactive ones. Check your plugins against Wordfence Intelligence for known vulnerabilities.

What to do if your WordPress site has been hacked

Signs you’ve been hacked: the site redirects to another page, Google warns visitors, your host shuts the site down, you see unknown user accounts or unusual traffic in Analytics.

If it’s happened: take the site offline, restore from a clean backup, scan with Wordfence or Sucuri, change all passwords and check the file system for unknown files. Contact your host immediately.

Don’t wait – start today

WordPress security isn’t something you do once and forget. It requires ongoing attention – updates, monitoring and regular backups.

If you don’t have the time or expertise for that, our WordPress support agreement handles everything – updates, security monitoring, backups and technical support. Read more about how we build WordPress websites with security as a core principle, or contact us for a review.

Innehåll

Kanske detta också intresserar dig...

Boka rådgivning

Whether you want to create something new, sharpen what you already have or just ball an idea, book a first meeting with us. No obligations, just a good conversation.

Get started now
Steps ! 1/! 3
Utförlig och dynamisk gest av en gula tecknad hand, med blå rörelseslinjer, som symboliserar varumärkeskommunikation och engagemang i en aktiv marknadsföringsambiente.

Hey! What's your name?

Glad you want to get started! We start with a name, first names are fine, but you are welcome to add last names if you want to be really formal.
En återförsäljare använder händer för att leda kunden åt höger till ett varumärkesmottagning, en tydlig design som visar riktning och uppmärksamhet på detaljer.

How do we reach you?

We need your email so you can hear from us. Would you rather we call? Leave your number and we'll make it work.
Smileys med vänliga ögon och leende mun symboliserar varumärkes positivitet och lyckosamma interaktioner, vanliga i digital kommunikation inom marknadsföring och varumärkesbyggande för en glad kundupplevelse.

What can we help you with?

Do you have anything in particular in mind? Please tell us briefly about the project, the need or the idea, and we will be a little more informed when we hear from you.
By submitting your personal data, you consent according to our privacy policy.
Thank you!
We are very pleased that you have shown interest. We'll get back to you as soon as we can. We wish we could send you a coffee right now ☕️ — but we'll have to wait until we see you!
Oops! Something went crazy. Please try again.