Most hacked WordPress sites were not targeted by a clever attacker. They were caught by automated bots that scan thousands of sites for the same easy weaknesses: old plugins, weak passwords and exposed login pages. The good news is that a few simple habits close most of those doors. Here are five security basics every site owner should have in place.
1. Keep everything updated
Outdated plugins and themes are the most common way into a WordPress site. When a vulnerability is published, attackers start scanning for it within hours. Enable automatic updates for plugins you trust, and check the Updates screen at least once a week for the rest. Take a backup before major updates so you can roll back if something breaks.
2. Use strong, unique passwords and two-factor authentication
Reused or short passwords are easily guessed or taken from other data leaks. Use a password manager to generate a long, unique password for every administrator account, and add two-factor authentication (2FA) with an authenticator app. Even if a password leaks, the attacker cannot log in without the second factor.
3. Limit login attempts and avoid the default admin name
Bots constantly try common usernames such as “admin” against wp-login.php. Do not use that username, and add a login protection feature that blocks an address after several failed attempts. Many security plugins and most good hosts include this. You can also use a different public display name than your login name so the login name is not shown in posts.
4. Make regular, tested backups
No setup is perfectly safe, so plan for the worst. Keep automatic backups of both files and database, store them somewhere other than your web server, and keep several recent versions. A backup you have never restored is only a hope, so try a test restore at least once.
5. Remove what you do not use
Every installed plugin or theme is more code that can contain a flaw, even when it is deactivated. Delete unused plugins and themes, and remove accounts that no longer need access. Give each user only the role they really need: an editor does not need administrator rights.
Bonus: use HTTPS and a reputable host
Make sure your whole site loads over HTTPS, and choose hosting that provides server-level protection such as a firewall and malware scanning. These layers work quietly in the background and catch problems before they reach your dashboard.
Quick checklist
- Turn on updates and review them weekly.
- Use a password manager and enable 2FA for admins.
- Limit login attempts; do not use “admin”.
- Back up files and database off-site, and test a restore.
- Delete unused plugins, themes and user accounts.
None of these steps takes long, and together they stop the vast majority of automated attacks.