Knowledgebase

WordPress Security Hardening Checklist Print

  • wordpress, security, plugins, permissions, php, hacked, themes, ssl, https, backup
  • 0

Work through this list on every site you host with us. Most compromises we see come from skipping two or three of these items.

  1. Keep everything updated — core, themes and plugins. Out-of-date plugins are the most common entry point.
  2. Never install nulled themes or plugins. Cracked premium software almost always ships with a backdoor.
  3. Delete what you do not use. An inactive plugin is still code on the server and can still be exploited.
  4. Do not use "admin" as a username, and use a long unique password.
  5. Enable two-factor authentication for every administrator account.
  6. Limit login attempts so brute-force attacks are locked out.
  7. Disable the built-in file editor so a stolen login cannot be used to inject PHP.
  8. Use HTTPS everywhere with AutoSSL and forced redirects.
  9. Set correct file permissions — 755 for folders, 644 for files, 600 for wp-config.php.
  10. Disable XML-RPC if you do not use the WordPress mobile app or Jetpack.
  11. Take regular off-server backups that you have actually tested restoring.
  12. Remove unused user accounts, and give contributors the lowest role that lets them do their job.
  13. Run a security plugin such as Wordfence or Solid Security, and act on what it reports.

Our servers run ImunifyAV scanning at the account level, but server-side scanning is a safety net, not a substitute for the list above.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot