WordPress Security Hardening: What Actually Works
Reducing the risk of a WordPress site being compromised by updating software, limiting access, choosing plugins carefully and configuring the server securely.
Where most projects go wrong
The usual mistakes:
- Nulled or pirated plugins
- Shared admin accounts
- Abandoned plugins with no updates
- Writable file permissions everywhere
What good looks like instead
- Keep core, themes and plugins updated
- Remove unused plugins and themes
- Use strong passwords and two-factor authentication for admins
- Disable the dashboard file editor
- Keep off-site backups and test restores
Why it matters
WordPress's popularity makes it a constant target, and most compromises come from outdated plugins, weak passwords or poor hosting configuration.
The specs that matter
| Measure | Figure |
|---|---|
| Updates | core, themes and plugins need regular updates |
| Least privilege | users should have only the roles they need |
| File editing | the dashboard file editor can be disabled in wp-config.php |
| Guidance | WordPress publishes a hardening guide |
Knowing when to hand it over
Tip: Bring in help when a WordPress site has been hacked, or when managing many sites with different plugins.
Where this comes from
- WordPress Developer Resources — Hardening WordPress
- OWASP — Vulnerable Dependency Management Cheat Sheet
The figures and practices above come from the sources listed.
Working on something like this?
We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.