WordPress powers over 43% of all websites, which makes it the single most targeted CMS for hackers. A Sucuri report found that over 70% of hacked WordPress sites were compromised through easily preventable vulnerabilities. This guide walks you through 10 proven security steps that anyone can implement today.
Table of Contents
- Keep WordPress, Themes & Plugins Updated
- Use Strong Passwords and a Non-Admin Username
- Install an SSL Certificate
- Enable Two-Factor Authentication (2FA)
- Change Your Login URL
- Install a Security Plugin
- Set Correct File Permissions
- Back Up Regularly
- Remove Unused Themes and Plugins
- Use a Web Application Firewall (WAF)
- Comparison Summary
- FAQ
1. Keep WordPress, Themes & Plugins Updated
Outdated software is the leading cause of WordPress compromises. Security researchers discover and patch vulnerabilities regularly — but only sites that apply updates are protected.
How to do it
- Go to Dashboard → Updates → click "Update Now" for WordPress core
- Update all plugins with available newer versions
- Update themes, including inactive ones
- Enable automatic updates for security releases: Dashboard → Updates → "Automatic updates for all new versions"
Tip: Always back up before major updates to catch any theme or plugin compatibility issues.
2. Use Strong Passwords and a Non-Admin Username
The username "admin" is the first thing bots try during brute force attacks. Changing both your username and password dramatically reduces your attack surface.
Guidelines
- Username: Use something unpredictable like "jsmith_wp" instead of "admin"
- Password: At least 16 characters, mixing numbers, symbols, and mixed case
- Use a password manager like Bitwarden or 1Password
- Configure Login Attempt Limits to lock accounts after repeated failures
3. Install an SSL Certificate
SSL (HTTPS) encrypts all data transmitted between the user's browser and your server — especially critical for login pages and any data collection.
Why SSL matters
- Prevents Man-in-the-Middle Attacks: hackers can't intercept passwords or session data
- Google prioritizes HTTPS in search rankings
- Displays the padlock icon, building visitor trust
- On AsiaGB Hosting, SSL can be installed for free via DirectAdmin
4. Enable Two-Factor Authentication (2FA)
Even if a hacker obtains your password, 2FA blocks access by requiring a one-time code from your phone. It's one of the most effective security layers available.
Recommended 2FA plugins
- WP 2FA: Simple, free, supports Authenticator apps and email OTP
- Google Authenticator – WordPress Two Factor Authentication
- Solid Security (iThemes Security): Bundles 2FA with other security features
5. Change Your Login URL
WordPress's default login URL (/wp-login.php or /wp-admin) is known by every bot on the internet. Changing it stops automated attacks from finding your login page at all.
How to change it
- Use WPS Hide Login — free, simple, works from Settings
- Or use Solid Security which includes this feature
- Choose something memorable but unguessable, like
/my-site-login-2026
Important: Save your new login URL before making the change. If you forget it, you'll lose access to your admin panel.
6. Install a Security Plugin
A security plugin acts as an automated security guard — scanning files, detecting intrusions, and blocking suspicious IP addresses.
Top security plugin comparison
| Plugin | Free/Paid | Key Strengths |
|---|---|---|
| Wordfence Security | Free/Pro | Real-time Firewall + Malware Scanner |
| Solid Security (iThemes) | Free/Pro | All-in-one: 2FA + Brute Force + File Change |
| Sucuri Security | Free/Pro | Cloud WAF + Malware Removal Service |
| All-In-One Security | Free/Pro | Beginner-friendly visual Security Score |
For beginners, Wordfence Free offers the most comprehensive free-tier feature set.
7. Set Correct File Permissions
Overly permissive file permissions allow attackers who have gained partial access to modify critical files more easily.
Correct values
- WordPress root directory: 755
- PHP and HTML files: 644
wp-config.php: 440 or 400 (read-only).htaccess: 644
Set these via the File Manager in DirectAdmin or via FTP clients like FileZilla.
8. Back Up Regularly
Backups don't prevent hacking, but they're your emergency recovery plan — letting you restore your site in hours rather than rebuilding from scratch.
Backup solutions
- UpdraftPlus: Most popular plugin, backs up to Google Drive, Dropbox, Amazon S3
- Duplicator: Great for backup and site migration
- DirectAdmin Backup Manager: Backup directly through the control panel
- AsiaGB Hosting includes twice-monthly automated backups (1st and 15th of each month)
Recommended: Keep backups in at least two separate locations — your server and an external cloud storage service.
9. Remove Unused Themes and Plugins
Deactivated plugins and themes still have PHP files on your server. Hackers can exploit vulnerabilities in those files even when the plugin is inactive.
What to remove
- Themes you don't use (keep only one default theme as a fallback)
- Test plugins you installed but never actually deployed
- Plugins not updated in over a year
10. Use a Web Application Firewall (WAF)
A WAF acts as a checkpoint that filters suspicious traffic before it reaches your site, blocking SQL Injection, XSS, DDoS, and other attacks.
WAF options
- Cloudflare Free: CDN + Basic WAF for free, also reduces server load
- Wordfence Premium: Real-time rule updates for WordPress-specific threats
- Sucuri WAF: Cloud-based WAF with malware removal service
Comparison Summary
| Method | DIY? | Free? | Priority |
|---|---|---|---|
| Update Core/Plugin/Theme | ✅ | ✅ | Critical |
| Strong Password + Username | ✅ | ✅ | Critical |
| SSL Certificate | ✅ | ✅ (on AsiaGB) | Critical |
| 2FA | ✅ | ✅ | High |
| Change Login URL | ✅ | ✅ | Medium |
| Security Plugin | ✅ | ✅ (free tier) | High |
| File Permissions | ✅ | ✅ | Medium |
| Regular Backups | ✅ | ✅ (some plans) | Critical |
| Remove Unused Plugins/Themes | ✅ | ✅ | Medium |
| WAF | ✅ | ✅ (Cloudflare) | High |
Summary
WordPress security is not a one-time task — it's an ongoing process. Doing just the first three steps (updates + strong password + SSL) prevents over 70% of common attacks. Completing all 10 puts your site's security well above the majority of sites that fall victim to hackers.
Frequently Asked Questions
Is WordPress really frequently hacked?
Yes. WordPress powers 43% of the web, making it the #1 target for hackers. Most attacks exploit outdated plugins, weak passwords, and unpatched core vulnerabilities.
Do I need multiple security plugins?
No. One comprehensive plugin like Wordfence or Solid Security is sufficient. Running multiple security plugins can cause conflicts and slow your site.
Does changing the login URL really help?
It significantly reduces automated brute force attacks, but it's not a primary defense. Always combine it with a strong password and 2FA.
How essential is SSL for WordPress?
Essential. SSL encrypts all data between the browser and server, preventing man-in-the-middle attacks. It also positively impacts your Google search ranking.
How often should I back up WordPress?
Daily for sites with frequent content updates. AsiaGB Hosting includes twice-monthly automated backups (1st and 15th of each month) as a baseline — add a plugin for more frequent backups.
Should I delete deactivated plugins?
Yes, always. Deactivated plugins still have PHP files on the server that can be exploited through known vulnerabilities, even if they're not actively running.