Lock Down WordPress: A Beginner Security Checklist
A beginner-friendly WordPress security checklist: updates, strong logins, trusted plugins, backups, HTTPS and more to keep your site safe from common attacks.

WordPress powers a very large number of websites, and that popularity makes it a frequent target. The good news is that most attacks exploit simple weaknesses: outdated software, weak passwords and untrusted add-ons. If you cover the basics, you stop the large majority of common problems. This checklist walks through them in a sensible order.
Why WordPress sites get hacked
The WordPress core software is actively maintained and reviewed. Most compromises come from the things around it:
- Outdated plugins or themes with known vulnerabilities.
- Weak or reused administrator passwords.
- Plugins and themes downloaded from unofficial sources, sometimes packaged with hidden malware.
- Poorly configured hosting or file permissions.
- Stolen credentials obtained from phishing or from other breaches.
Attackers usually scan the internet automatically for known weaknesses, so small sites are targeted just as readily as big ones.
1. Keep everything updated
Updates are your first line of defense because many of them fix security flaws that are publicly known. Update WordPress core, plugins, themes and the PHP version used by your hosting. Where it is safe for your site, enable automatic updates for minor core releases and for trusted plugins. Before large updates, make a backup so you can roll back if something breaks.
2. Use strong logins
- Create a long, unique password for every user, ideally generated by a password manager.
- Do not use "admin" as a username. Create a new administrator with a different name and remove the old one.
- Turn on two-factor authentication for administrators and editors. Several well-regarded plugins add this feature.
- Give each person their own account with only the permissions they need. A writer does not need to be an administrator.
- Remove accounts for people who no longer work with you.
3. Limit login attempts
Bots try thousands of password guesses against the login page. A limit on failed attempts, either through a plugin or at the hosting or firewall level, slows them down dramatically. Some sites also add a challenge on the login form, or restrict the login page by IP address if only a few people use it.
4. Be selective with plugins and themes
Every plugin adds code that has to be kept secure. Before installing one, check these points:
- It is downloaded from the official WordPress directory or from the developer's own reputable site.
- It has been updated recently and is marked compatible with your WordPress version.
- It has a healthy number of active installations and sensible reviews.
- You actually need it. Fewer plugins means fewer risks.
Delete, rather than just deactivate, any plugins and themes you do not use. Never install "nulled" or pirated premium plugins. They are a well-known way to distribute malware.
5. Choose good hosting
Your host affects your security more than you might expect. Look for providers that keep server software up to date, isolate accounts from one another, offer a web application firewall, provide regular backups and give you access to a recent PHP version. Cheap hosting is not always bad, but check what security features are included before you commit.
6. Use HTTPS everywhere
HTTPS encrypts traffic between your visitors and your site, including login details. Most hosts offer free certificates. Once installed, make sure your site address in Settings uses https and that all pages redirect from http to https. Browsers flag sites without it as not secure.
7. Back up your site
Even a well-protected site can fail or get hacked. Keep regular backups of both the files and the database, store at least one copy away from your hosting account, and test restoring one occasionally. A recent clean backup turns a serious attack into a manageable repair. For more on this, see the 3-2-1 backup rule.
Quick reference: protections and effort
| Protection | What it prevents | Effort |
|---|---|---|
| Regular updates | Exploits of known vulnerabilities | Low |
| Strong passwords and 2FA | Account takeover and brute-force attacks | Low |
| Login attempt limits | Automated password guessing | Low |
| Removing unused plugins | Vulnerabilities in forgotten code | Low |
| HTTPS | Eavesdropping on logins and form data | Low |
| Off-site backups | Permanent data loss after an attack or failure | Medium |
| Web application firewall | Many malicious requests before they reach your site | Medium |
| Activity logging | Hard-to-spot changes by users or attackers | Medium |
8. Harden the configuration
Once the basics are in place, a few additional steps add useful layers:
- Set correct file permissions so that the web server cannot write to more than it needs to.
- Disable the built-in file editor in the dashboard by adding a line to your configuration file, so a hijacked admin account cannot easily edit code.
- Protect the wp-config.php file and keep it out of public access.
- Disable XML-RPC if you do not use it, since it can be abused for password guessing.
- Use a different database table prefix on new installs, though this is a minor measure.
- Hide detailed error messages on the live site, since they can reveal paths and other information.
9. Monitor and scan
Security is not only prevention, it is also noticing problems early. A reputable security plugin or service can scan for malware, watch for modified core files and alert you to suspicious logins. Check your user list regularly for accounts you do not recognize, and review Search Console or hosting notices for warnings about your site.
What to do if the site is compromised
- Put the site in maintenance mode or take it offline if it is harming visitors.
- Contact your hosting provider. They can often help identify the problem.
- Change all passwords: WordPress users, hosting, database, FTP and email accounts tied to the site.
- Restore from a clean backup made before the infection, or remove malicious files with a trusted cleanup process.
- Update everything, remove unused plugins and themes, and replace any suspicious ones.
- Find out how the attacker got in, otherwise it may happen again.
Final thoughts
You do not need to be a developer to keep a WordPress site secure. Keep everything updated, use strong logins with two-factor authentication, install only plugins you trust and need, enable HTTPS and keep tested backups off-site. Put those habits on a monthly calendar reminder and your site will be far harder to attack than the average one.


