WordPress itself is not insecure. The overwhelming majority of compromises come from three things: an outdated plugin, a weak password, and hosting shared with somebody who had one of the first two.
This checklist is ordered by how much risk each item removes. The first five take an hour and prevent most real attacks. The rest are worth doing and matter far less than people who sell security plugins would like you to believe.
Quick Info
1. Update everything, on a schedule
This is the whole answer, and it is the item most often skipped because it is dull. Known vulnerabilities in popular plugins get exploited within days of disclosure, at scale, by automated scanners that do not care how small your site is.
No security plugin can protect a site running a plugin with a publicly documented vulnerability. The update is the security measure.
2. Fix the credentials
If you do only one thing from this entire article, turn on two-factor authentication. It removes the largest category of attack completely.
3. Limit login attempts
Rate limiting stops the automated password guessing that makes up most of the traffic hitting your login page. Any security plugin will do it, and so will most managed hosts at server level.
Changing the login URL is mild obscurity rather than security. It cuts the noise in your logs, which has some value, and it stops nobody determined.
4. Backups you have actually tested
Backups are not prevention, they are the reason a compromise is an afternoon rather than a catastrophe.
An untested backup is a belief, not a plan. I have watched somebody discover their nightly backup had been failing silently for five months on the day they needed it.
5. Choose hosting that helps
On cheap shared hosting, a neighbour's compromise can become yours if account isolation is poor. Managed hosts add server-level firewalls, malware scanning and patching, which is a meaningful part of what you are paying for.
6. Sensible hardening
Worth doing, and secondary to the five items above.
Most of these are single settings in a security plugin. Do not spend a weekend on them until updates, passwords and two-factor are done.
7. Monitor, so you find out early
8. If you are already hacked
Order matters here, and the mistake is cleaning without closing the hole, which produces a reinfection within days.
If the site handles customer data or payments, take proper advice on your notification obligations. That is a legal question rather than a technical one.
What does not help
Security is maintenance. The product you are looking for is a calendar reminder.
Frequently Asked Questions
Core WordPress is well maintained and audited. Sites get compromised through outdated plugins and themes, weak credentials and poor hosting, not through core itself.
One is useful for firewall, scanning, login limiting and two-factor. It does not substitute for updates, which prevent far more incidents.
Two-factor authentication on every admin account, then keeping plugins updated. Those two remove the large majority of realistic risk.
Daily for a site that changes, and before every update. Off-site, retained thirty days, and tested at least once.
They are not targeting you. Automated scanners look for known vulnerabilities at scale and use whatever they find for spam, redirects or mining.
The entry point was never closed. Cleaning removes the symptom; updating or deleting the vulnerable plugin removes the cause.
Before You Go
Security on WordPress is unglamorous and largely solved: update on a schedule, use a password manager, turn on two-factor, back up off-site and test the restore. That is an hour of setup and fifteen minutes a month.
The rest of the checklist reduces risk at the margins. Do it after the boring part, not instead of it. The maintenance checklist turns this into a monthly routine.
Update, two-factor, back up. Then everything else.
I'm a marketing consultant, entrepreneur and content creator. I help businesses grow through practical marketing, websites, SEO, content and AI.
More About Tariq →