WordPress Security Hardening Guide

WordPress powers over 43% of all websites, which makes it the most targeted CMS by hackers. Most successful attacks are not zero-day exploits — they exploit outdated plugins, weak passwords, and default configurations that site owners never changed. This guide covers every practical hardening step you can take right now.

Key stat: Over 90% of hacked WordPress sites were compromised through outdated plugins, themes, or brute-force login attacks — all preventable with the steps in this guide.

1. Keep Everything Updated

The single most important security practice is keeping WordPress core, themes, and plugins up to date. Most updates patch known vulnerabilities that hackers actively scan for.

2. Protect the Login Page

Change the Default Login URL

By default WordPress login is at /wp-login.php — every bot knows this. Use a plugin like WPS Hide Login to change it to a custom URL like /admin-portal.

Limit Login Attempts

Install Limit Login Attempts Reloaded to block IPs after repeated failed logins. Recommended settings:

Enable Two-Factor Authentication (2FA)

Use WP 2FA or Google Authenticator plugin to require a time-based OTP for all admin accounts. Even if your password is leaked, attackers cannot log in without the second factor.

Use Strong, Unique Passwords

3. Secure wp-config.php and File Permissions

wp-config.php Hardening

Add these constants to wp-config.php to restrict access:

// Disallow file editing from WordPress dashboard
define('DISALLOW_FILE_EDIT', true);

// Disallow plugin/theme installation
define('DISALLOW_FILE_MODS', true);

// Force HTTPS for admin
define('FORCE_SSL_ADMIN', true);

Correct File Permissions

File/Directory Permission
wp-config.php600 (owner read/write only)
All directories755
All files644
.htaccess644

4. Disable XML-RPC

XML-RPC is a legacy API used by older mobile apps and tools like Jetpack. If you don't use it, disable it — it's a common target for brute-force and DDoS amplification attacks.

Add this to your .htaccess:

# Block XML-RPC
<Files xmlrpc.php>
  Order Deny,Allow
  Deny from all
</Files>

5. Install a Security Plugin

A dedicated security plugin adds multiple layers of protection:

Run a full malware scan after installation. If Wordfence detects infected files, it can restore them from the original WordPress repository.

6. Disable XML-RPC and Restrict REST API

XML-RPC is a legacy remote procedure protocol included in every WordPress installation. Attackers use it for brute-force attacks (it allows unlimited login attempts per request) and DDoS amplification via the pingback feature. If you don't use mobile apps or Jetpack, disable it entirely.

Add this to your .htaccess:

# Completely block XML-RPC
<Files xmlrpc.php>
  Order Deny,Allow
  Deny from all
</Files>

To restrict the REST API to authenticated users only, add this to your Child Theme's functions.php:

// Restrict REST API to logged-in users
add_filter('rest_authentication_errors', function($result) {
    if (!is_user_logged_in()) {
        return new WP_Error('rest_not_logged_in', 'Authentication required.', ['status' => 401]);
    }
    return $result;
});

Note: If you use WooCommerce, Jetpack, or any plugin that relies on the REST API, do not restrict it without testing first. Check plugin documentation before applying.

7. Harden HTTP Security Headers

Security headers instruct the browser to enforce important security policies that stop a class of attacks — Clickjacking, MIME-type confusion, and cross-site scripting — before they can execute. Add these to your .htaccess:

<IfModule mod_headers.c>
  Header always set X-Content-Type-Options "nosniff"
  Header always set X-Frame-Options "SAMEORIGIN"
  Header always set Referrer-Policy "strict-origin-when-cross-origin"
  Header always set X-XSS-Protection "1; mode=block"
  Header always set Permissions-Policy "geolocation=(), microphone=(), camera=()"
</IfModule>
Header Protects Against
X-Frame-Options: SAMEORIGINClickjacking — embedding your page in a malicious iframe
X-Content-Type-Options: nosniffMIME sniffing — browsers misinterpreting file types
X-XSS-ProtectionReflected XSS in older browsers
Referrer-PolicyLeaking sensitive URL parameters to third parties

You can verify your security headers score at securityheaders.com — aim for an A or A+ rating.

8. Use Server-Level Malware Protection

WordPress-level security plugins are important, but server-level protection adds a deeper layer. AsiaGB Hosting includes Imunify360 — a real-time antivirus and Intrusion Prevention System (IPS) that scans uploaded files and blocks attacking IPs automatically.

Warning signs of a compromise: Unexpected redirects, new admin accounts you didn't create, Google Search Console warnings about malware, or sudden drops in search rankings. Act immediately — restore from a clean backup and change all passwords.

9. Keep Regular Backups

Even the most hardened WordPress site can be compromised. Without backups, recovery is extremely difficult. Schedule daily or weekly automatic backups using:

Important: Always store backups off-site. If your server is compromised, on-server backups may also be infected or deleted by the attacker.

Security Hardening Checklist

Task Status
WordPress core, plugins, themes updated☐
Login URL changed from /wp-login.php☐
Login attempts limited☐
2FA enabled for admin accounts☐
DISALLOW_FILE_EDIT set in wp-config.php☐
XML-RPC disabled (if not used)☐
Security plugin installed and scanned☐
Off-site backups scheduled☐

WordPress Hosting with DirectAdmin — Secure & Fast

AsiaGB Hosting includes DirectAdmin control panel, one-click WordPress install, SSL, and automatic backups. 99% uptime SLA. Starting at 500 THB/year.

View Hosting Plans →