Practical guide · WordPress

How to Secure a WordPress Website

Secure a WordPress website by protecting the accounts and server first, then reducing extension risk, testing backups and monitoring important changes. Apply controls in layers so that one failure does not become a…

Secure a WordPress website by protecting the accounts and server first, then reducing extension risk, testing backups and monitoring important changes. Apply controls in layers so that one failure does not become a complete loss.

1. Inventory the system

  • Domain and DNS provider
  • Hosting and server environment
  • WordPress and PHP versions
  • Active and inactive themes/plugins
  • Administrator and supplier accounts
  • External APIs, email and payment services
  • Backup locations and retention

2. Recover control of critical accounts

The business should own the domain, hosting, administrator email and licences. Change unknown or shared passwords, enable multi-factor authentication where available and store recovery codes securely.

3. Back up before hardening

Create a complete backup and verify access to it. Security changes can block legitimate administration or expose an existing incompatibility, so keep a rollback path.

4. Update the full software stack

  1. Review release notes and compatibility.
  2. Test higher-risk updates on staging.
  3. Update WordPress core, themes and plugins.
  4. Move PHP/database versions through the host’s supported process.
  5. Verify public pages, forms, login, scheduled tasks and checkout.

5. Remove unnecessary code and access

  • Delete unused themes and plugins after a safe backup
  • Remove former staff, test and duplicate administrator accounts
  • Disable functions and integrations that the site does not use
  • Replace abandoned extensions with supported alternatives

6. Harden administration and files

Require HTTPS, use encrypted file transfer, restrict file permissions and protect configuration. Consider disabling dashboard file editing when it fits the maintenance process. Do not copy generic server rules without confirming compatibility.

7. Protect logins without locking out the business

Use strong credentials, multi-factor authentication, rate limiting or suitable login protection. Test password reset and emergency access. A control that only the former developer can bypass creates another risk.

8. Monitor critical events

Useful security monitoring
EventResponse
New administratorVerify the request immediately
Unexpected file or plugin changePreserve evidence and investigate the account used
Repeated failed loginsReview source, strengthen controls and check for successful access
Malware or redirect alertContain the site and use an incident process
Backup failureRepair before the next risky change
Form/checkout failureTreat as both an operational and possible security signal

9. Prepare incident recovery

Document who can restrict the site, contact the host, reset accounts, assess personal-data impact and restore a known-good version. Keep contact details outside WordPress.

10. Recheck after every supplier handover

Revoke old access, transfer licences, rotate shared secrets and confirm the new maintainer can update and restore the site.

Practical next step

Complete the inventory and account-control steps first. Do not add a security plugin until the business owns the hosting, administrator email and backup recovery path.

Verify rather than assume

After hardening, attempt the legitimate workflows: password recovery, editor login, form submission, payment callback, scheduled publishing and software updates. Security settings can block required traffic, so the acceptance test must cover the real business.

Third-party administrator access

Create a named temporary account, use the lowest role that permits the work and agree how credentials will be transmitted. For hosting-level access, prefer delegated users or temporary credentials where the provider supports them. Review logs and revoke access when the work ends.

What not to publish

  • Server paths and detailed error traces.
  • Backup download links.
  • API keys, webhooks or database credentials.
  • Screenshots containing customer or administrator data.
  • Exact defensive configuration merely for cosmetic reassurance.

Sources and date checked

This guide was checked on 21 July 2026. WordPress, hosting environments and extensions change, so recheck the relevant official documentation before making a major change.

Keep the decision under your control

Retain the relevant accounts, source material, supplier terms and recovery information. Recheck changing prices, interfaces and rules before acting.