ServerNeed — This Year's Best Offers For You

ServerNeed — More Than Hosting
WordPress

WordPress Security Checklist:Practical Steps to Protect Your Site

Step-by-step WordPress hardening: updates, logins and 2FA, user roles, file permissions, wp-config settings, backups and choosing the security plugin features you actually need.

5 min read
Padlock and chain securing a rusty gate
Table of Contents
  1. 1. Keep everything updated
  2. 2. Remove what you do not use
  3. 3. Protect the login
  4. 4. Use the right user roles
  5. 5. Harden wp-config.php
  6. 6. Set sensible file permissions
  7. 7. Serve the site over HTTPS only
  8. 8. Disable what you do not need
  9. 9. Keep tested backups off the server
  10. 10. Choose security plugin features deliberately
  11. 11. Watch for signs of trouble
  12. Checklist summary
  13. Frequently Asked Questions
  14. Related reading
  15. Sources

The most effective WordPress security measures are not exotic: keep WordPress, themes and plugins updated, protect logins with strong passwords and two-factor authentication, give each user only the access they need, keep tested backups, and remove anything you do not use. Most compromised WordPress sites are broken into through an outdated plugin or a stolen password, not through WordPress core.

Work through this checklist in order. Each item lists why it matters and how to do it.

1. Keep everything updated

  • Enable automatic updates for WordPress minor releases (on by default) and consider them for trusted plugins.
  • Review pending updates at least weekly.
  • Remove plugins and themes that are no longer maintained; the plugin directory shows when a plugin was last updated.

See how to update WordPress safely for a routine that avoids breaking the site.

2. Remove what you do not use

Deactivated plugins and unused themes still sit on the server and can still contain exploitable code. Delete them. Keep one default theme as a fallback.

3. Protect the login

Changing the login URL can reduce automated noise but is not a security control on its own.

4. Use the right user roles

Give each person the lowest role that lets them do their job:

Role Can
Administrator Everything, including plugins, themes and users
Editor Publish and manage all posts and pages
Author Publish and manage their own posts
Contributor Write posts but not publish them
Subscriber Manage only their profile

Review the user list regularly and remove people who have left.

5. Harden wp-config.php

Add these lines above the "That's all, stop editing!" comment:

define( 'DISALLOW_FILE_EDIT', true );   // removes the theme and plugin file editor
define( 'FORCE_SSL_ADMIN', true );      // admin over HTTPS only

Also make sure the authentication keys and salts are set to unique random values. Regenerating them logs everyone out, which is useful after a suspected compromise.

6. Set sensible file permissions

Typical safe values on shared hosting are 644 for files and 755 for folders, and stricter (for example 600 or 640) for wp-config.php where the server supports it. Never use 777.

7. Serve the site over HTTPS only

Install an SSL certificate and redirect all HTTP traffic to HTTPS. See how to force HTTPS and fix mixed content.

8. Disable what you do not need

  • XML-RPC (xmlrpc.php) is used by some apps and Jetpack features but is a common brute-force target. If nothing uses it, block it.
  • Comments, if your site does not need them.
  • User registration, under Settings → General, unless you need it.

9. Keep tested backups off the server

Backups are your recovery plan if everything else fails. Keep automatic daily backups stored away from the hosting account and test a restore occasionally. See WordPress backups: what to back up and how to restore.

10. Choose security plugin features deliberately

Security plugins bundle several features. The useful ones are:

  • login protection and 2FA;
  • a web application firewall (plugin-level, or better, at server or CDN level; see what is a web application firewall);
  • malware scanning and file-change alerts;
  • activity logging.

You do not need several overlapping security plugins; they slow the site and can conflict. If your host already provides a server firewall and malware scanning, a lighter plugin may be enough.

11. Watch for signs of trouble

Unknown admin users, unexpected redirects, spam pages in search results, or warnings from Google or your host all mean you should investigate immediately. See how to clean a hacked WordPress site.

Checklist summary

  • Core, themes and plugins updated; abandoned ones replaced
  • Unused plugins and themes deleted
  • Strong passwords and 2FA for privileged users
  • Login attempts limited
  • Least-privilege user roles reviewed
  • DISALLOW_FILE_EDIT and unique salts in wp-config.php
  • Permissions 644/755, never 777
  • HTTPS enforced
  • XML-RPC, comments and registration off if unused
  • Off-site backups tested
  • One security plugin, configured deliberately

Frequently Asked Questions

Is WordPress secure?

WordPress core has a dedicated security team and is updated regularly. Most problems come from outdated plugins and themes, weak passwords and poor hosting, which this checklist addresses.

Do I need a premium security plugin?

Not necessarily. Many essential protections are available in free plugins or at the server level. Choose based on the features you need, not on the number of features.

Should I hide my WordPress version?

It does little harm, but it is not real protection. Keeping the version up to date matters far more than hiding it.

For general security beyond WordPress, see website security basics. For the WordPress overview, see WordPress hosting: what it is and how to choose, and compare ServerNeed WordPress hosting.

Sources

Last updated 7 October 2026

View All Articles