WordPress powers over 43% of all websites on the internet – making it the most targeted CMS on the market. A site that isn’t actively maintained is a matter of when it gets hacked, not if.
The good news: the vast majority of attacks can be prevented with relatively simple measures. Here we walk through the most important steps.
Why hackers love WordPress
It’s rarely because you specifically are a target. Attacks on WordPress are mostly automated – bots scan the internet for known vulnerabilities in outdated plugins, themes and WordPress versions. If your site has a known vulnerability, they’ll find it.
The most common attacks are:
- Brute force – bots try to guess your password through thousands of login attempts
- Plugin vulnerabilities – outdated plugins with known holes are exploited automatically
- SQL injections – attacks against your database via forms or URLs
- Malware injection – malicious code is hidden in your site’s files
- DDoS attacks – your server is overwhelmed with traffic until it goes down
10 concrete steps for better WordPress security
1. Keep WordPress, plugins and themes updated
The single most important thing you can do. When a security flaw is found in a plugin, an update is released – often within days. If you don’t update quickly, you’re vulnerable.
Enable automatic updates for minor security releases. For major updates, always test on staging before updating the live site.
2. Remove plugins and themes you don’t use
Inactive plugins and themes are still a security risk. Delete them completely rather than just deactivating them. Fewer plugins means a smaller attack surface.
3. Use strong passwords and two-factor authentication
“admin” as username and “password123” as password are still combinations people use. Use a unique, long password of at least 16 characters and enable 2FA on all admin users.
4. Limit login attempts
Block IP addresses that try to log in repeatedly. Plugins like Limit Login Attempts Reloaded do this automatically and effectively eliminate brute force attacks.
5. Change the default login URL
By default, the WordPress login is accessible via /wp-admin or /wp-login.php. Every hacker knows this. Plugins like WPS Hide Login let you change it to something unique.
6. Install a security plugin
Wordfence and Sucuri are the most widely used security plugins. They offer a firewall, malware scanning, real-time monitoring and blocking of suspicious traffic.
7. Choose a secure host
Hosting is the foundation. A good WordPress host offers automatic backups, server-side firewall, malware scanning and isolated environments so a compromised site doesn’t affect others on the same server.
8. Take regular backups
No matter how securely you build, something can go wrong. A current backup is your last line of defence. Back up daily and store copies off-server – for example in Google Drive or Amazon S3.
9. Use SSL (HTTPS)
SSL encrypts the connection between the browser and your server and is now a basic requirement. Google actively warns visitors when a site lacks SSL. Most hosts offer free SSL via Let’s Encrypt.
10. Monitor and review regularly
Use Google Search Console to check your site isn’t flagged as malicious. Review your user accounts regularly and remove inactive ones. Check your plugins against Wordfence Intelligence for known vulnerabilities.
What to do if your WordPress site has been hacked
Signs you’ve been hacked: the site redirects to another page, Google warns visitors, your host shuts the site down, you see unknown user accounts or unusual traffic in Analytics.
If it’s happened: take the site offline, restore from a clean backup, scan with Wordfence or Sucuri, change all passwords and check the file system for unknown files. Contact your host immediately.
Don’t wait – start today
WordPress security isn’t something you do once and forget. It requires ongoing attention – updates, monitoring and regular backups.
If you don’t have the time or expertise for that, our WordPress support agreement handles everything – updates, security monitoring, backups and technical support. Read more about how we build WordPress websites with security as a core principle, or contact us for a review.




