---
title: Secure WordPress: 10 essential tips · VitaminaWeb
description: WordPress is the most popular CMS on the market. Follow these tips to protect your site against the most common hacker attempts.
source: https://vitaminaweb.digital/en/blog/secure-wordpress-10-essential-tips
lang: en
---

![Secure WordPress: 10 essential tips](https://vitaminaweb.digital/storage/blog/lsGtYcVMfslyj7yriSWWdtezPoooHy4iBJB1ZHdc.webp) WordPress is the most popular CMS (*Content Management System*). Used by countless websites, it receives frequent updates and has open-source code that makes it easy to integrate new features. In this article, I’ve put together 10 tips to protect your WordPress site against the most common *hacker* attempts.

## 10 tips for a secure WordPress site

### 1. Database

- By default, WordPress uses the "wp_" prefix during installation.
- As a precaution, set up regular, automatic database backups. We recommend the [SBackup](http://sbackup.online/) tool.

### 2. Users and passwords

- Always use passwords with uppercase and lowercase letters, numbers, and special characters;
- Don't use common usernames, such as admin or manager;
- Always remove users who are no longer needed;

### 3. Hosting

- Disable FTP access on your server. Allow access only through SSH or SFTP;
- Set folder and file permissions according to the [WordPress security documentation](https://codex.wordpress.org/pt-br:Blindando_o_WordPress);
- Install Fail2Ban on the server and configure the [WP Fail2Ban](https://br.wordpress.org/plugins/wp-fail2ban/) plugin;

### 4. Updates

 Keep WordPress, themes, and plugins up to date. Updates include several security fixes. [Learn more about why you should update WordPress](https://vitamina.digital/porque-devo-atualizar-o-wordpress/).

### 5. Tell Google no when necessary

 By configuring the robots.txt file correctly, you can prevent sensitive site content from being indexed. Here's an example of what to exclude from Google's index to keep your WordPress site secure:

```
 Useragent: *
 Disallow: /feed/
 Disallow: /trackback/
 Disallow: /wpadmin/
 Disallow: /wpcontent/
 Disallow: /wpincludes/
 Disallow: /xmlrpc.php
 Disallow: /wp
```

### 6. Delete unnecessary files

 Certain WordPress files can expose information about the platform. Always delete the following files:

- /wpconfigsample.php
- /readme.html
- /license.txt
- /wpadmin/install.php

### 7. Choose your themes and plugins carefully

 Because WordPress is an open-source tool, many developers create solutions for it. But not everything developed for WordPress is secure. Always check ratings and comments, and test plugins and themes in a staging environment before putting them into production. Never pirate a paid plugin or theme. Besides being illegal, pirated versions may not include the latest fixes, especially security updates.

### 8. Protect your dashboard

 Restrict access to the admin dashboard to prevent attempts to crack your password through [brute-force attacks](https://vitamina.digital/proteja-se-de-um-ataque-de-forca-bruta/).

### 9. Install an SSL certificate

 SSL certificates help keep your site secure. They're what make HTTPS possible. Although SSL certificates are more commonly used on sites that handle financial transactions, such as online banking and e-commerce sites, they can also help protect you against hacking attempts. SSL uses more bandwidth than usual, so if you can't implement it across your entire site, at least enable it for the WordPress admin directory (wp-admin).

### 10. Useful plugins

 Several plugins can help secure WordPress, including WP Fail2Ban, mentioned in this article. Check out this list of [Tip: 4 security plugins for WordPress](https://vitamina.digital/4-plugins-de-seguranca-para-o-wordpress/) that can help with this task.

## Read also

     What's New in Digital

### [Instituto da Maturidade Digital launches Agency Directory portal, developed by VitaminaWeb](https://vitaminaweb.digital/en/blog/instituto-da-maturidade-digital-launches-agency-directory-portal-developed-by-vitaminaweb)

Instituto da Maturidade Digital launches Agency Directory, a platform developed by VitaminaWeb to organize and make it easier to discover compani...

 03 Oct, 2026 · 5 min      Development

### [All-in-One WP Migration flaw could put millions of WordPress sites at risk](https://vitaminaweb.digital/en/blog/all-in-one-wp-migration-flaw-could-put-millions-of-wordpress-sites-at-risk)

CVE-2026-19949 affects versions up to 7.109 of the popular backup and migration plugin. An attack could escalate from SQL injection to remote cod...

 03 Sep, 2026 · 5 min      Development

### [Web Application Security: A Strategic Guide from Vulnerability to Digital Maturity](https://vitaminaweb.digital/en/blog/web-application-security-a-strategic-guide-from-vulnerability-to-digital-maturity)

This guide offers an in-depth strategic analysis of the main risks, best mitigation practices, and the integration of security into the software...

 23 Feb, 2026 · 5 min
