Skip to content
Development

Secure WordPress: 10 essential tips

WordPress is the most popular CMS on the market. Check out tips to protect your WordPress site against the most common hacker attempts.

Secure WordPress: 10 essential tips
WordPress is the most popular CMS (Content Management System). Used by countless websites, it receives frequent updates and has open-source code that makes it easy to integrate new features. In this article, I’ve put together 10 tips to protect your WordPress site against the most common hacker attempts.

10 tips for a secure WordPress site

 

1. Database

  • By default, WordPress uses the "wp_" prefix during installation.
  • As a precaution, set up regular, automatic database backups. We recommend the SBackup tool.

2. Users and passwords

  • Always use passwords with uppercase and lowercase letters, numbers, and special characters;
  • Don't use common usernames, such as admin or manager;
  • Always remove users who are no longer needed;

3. Hosting

  • Disable FTP access on your server. Allow access only through SSH or SFTP;
  • Set folder and file permissions according to the WordPress security documentation;
  • Install Fail2Ban on the server and configure the WP Fail2Ban plugin;

4. Updates

Keep WordPress, themes, and plugins up to date. Updates include several security fixes. Learn more about why you should update WordPress.

5. Tell Google no when necessary

By configuring the robots.txt file correctly, you can prevent sensitive site content from being indexed. Here's an example of what to exclude from Google's index to keep your WordPress site secure:
 Useragent: *
 Disallow: /feed/
 Disallow: /trackback/
 Disallow: /wpadmin/
 Disallow: /wpcontent/
 Disallow: /wpincludes/
 Disallow: /xmlrpc.php
 Disallow: /wp

6. Delete unnecessary files

Certain WordPress files can expose information about the platform. Always delete the following files:
  • /wpconfigsample.php
  • /readme.html
  • /license.txt
  • /wpadmin/install.php

7. Choose your themes and plugins carefully

Because WordPress is an open-source tool, many developers create solutions for it. But not everything developed for WordPress is secure. Always check ratings and comments, and test plugins and themes in a staging environment before putting them into production. Never pirate a paid plugin or theme. Besides being illegal, pirated versions may not include the latest fixes, especially security updates.

8. Protect your dashboard

Restrict access to the admin dashboard to prevent attempts to crack your password through brute-force attacks.

9. Install an SSL certificate

SSL certificates help keep your site secure. They're what make HTTPS possible. Although SSL certificates are more commonly used on sites that handle financial transactions, such as online banking and e-commerce sites, they can also help protect you against hacking attempts. SSL uses more bandwidth than usual, so if you can't implement it across your entire site, at least enable it for the WordPress admin directory (wp-admin).

10. Useful plugins

Several plugins can help secure WordPress, including WP Fail2Ban, mentioned in this article. Check out this list of Tip: 4 security plugins for WordPress that can help with this task.