
WordPress powers over 43% of all websites, which makes it the most targeted CMS by hackers. Most successful attacks are not zero-day exploits — they exploit outdated plugins, weak passwords, and default configurations that site owners never changed. This guide covers every practical hardening step you can take right now.
Key stat: Over 90% of hacked WordPress sites were compromised through outdated plugins, themes, or brute-force login attacks — all preventable with the steps in this guide.
1. Keep Everything Updated
The single most important security practice is keeping WordPress core, themes, and plugins up to date. Most updates patch known vulnerabilities that hackers actively scan for.
- Enable auto-updates for minor WordPress releases in Dashboard → Updates
- Check plugins and themes weekly — delete ones you don't use
- Remove nulled (pirated) themes/plugins — they often contain backdoors
- Subscribe to the WPScan Vulnerability Database for alerts
2. Protect the Login Page
Change the Default Login URL
By default WordPress login is at /wp-login.php — every bot knows this. Use a plugin like WPS Hide Login to change it to a custom URL like /admin-portal.
Limit Login Attempts
Install Limit Login Attempts Reloaded to block IPs after repeated failed logins. Recommended settings:
- Lockout after 5 failed attempts
- Lockout duration: 20 minutes
- Longer lockout after repeated lockouts: 24 hours
Enable Two-Factor Authentication (2FA)
Use WP 2FA or Google Authenticator plugin to require a time-based OTP for all admin accounts. Even if your password is leaked, attackers cannot log in without the second factor.
Use Strong, Unique Passwords
- Minimum 16 characters, mix of letters, numbers, symbols
- Use a password manager (Bitwarden, 1Password) — never reuse passwords
- Change the default admin username from "admin" to something unique
3. Secure wp-config.php and File Permissions
wp-config.php Hardening
Add these constants to wp-config.php to restrict access:
// Disallow file editing from WordPress dashboard
define('DISALLOW_FILE_EDIT', true);
// Disallow plugin/theme installation
define('DISALLOW_FILE_MODS', true);
// Force HTTPS for admin
define('FORCE_SSL_ADMIN', true);
Correct File Permissions
| File/Directory | Permission |
|---|---|
wp-config.php | 600 (owner read/write only) |
| All directories | 755 |
| All files | 644 |
.htaccess | 644 |
4. Disable XML-RPC
XML-RPC is a legacy API used by older mobile apps and tools like Jetpack. If you don't use it, disable it — it's a common target for brute-force and DDoS amplification attacks.
Add this to your .htaccess:
# Block XML-RPC
<Files xmlrpc.php>
Order Deny,Allow
Deny from all
</Files>
5. Install a Security Plugin
A dedicated security plugin adds multiple layers of protection:
- Wordfence Security — Free firewall, malware scanner, live traffic monitor
- Sucuri Security — Malware scanning, activity audit log, integrity monitoring
- iThemes Security — 30+ security hardening measures in one plugin
Run a full malware scan after installation. If Wordfence detects infected files, it can restore them from the original WordPress repository.
6. Disable XML-RPC and Restrict REST API
XML-RPC is a legacy remote procedure protocol included in every WordPress installation. Attackers use it for brute-force attacks (it allows unlimited login attempts per request) and DDoS amplification via the pingback feature. If you don't use mobile apps or Jetpack, disable it entirely.
Add this to your .htaccess:
# Completely block XML-RPC
<Files xmlrpc.php>
Order Deny,Allow
Deny from all
</Files>
To restrict the REST API to authenticated users only, add this to your Child Theme's functions.php:
// Restrict REST API to logged-in users
add_filter('rest_authentication_errors', function($result) {
if (!is_user_logged_in()) {
return new WP_Error('rest_not_logged_in', 'Authentication required.', ['status' => 401]);
}
return $result;
});
Note: If you use WooCommerce, Jetpack, or any plugin that relies on the REST API, do not restrict it without testing first. Check plugin documentation before applying.
7. Harden HTTP Security Headers
Security headers instruct the browser to enforce important security policies that stop a class of attacks — Clickjacking, MIME-type confusion, and cross-site scripting — before they can execute. Add these to your .htaccess:
<IfModule mod_headers.c>
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set X-XSS-Protection "1; mode=block"
Header always set Permissions-Policy "geolocation=(), microphone=(), camera=()"
</IfModule>
| Header | Protects Against |
|---|---|
X-Frame-Options: SAMEORIGIN | Clickjacking — embedding your page in a malicious iframe |
X-Content-Type-Options: nosniff | MIME sniffing — browsers misinterpreting file types |
X-XSS-Protection | Reflected XSS in older browsers |
Referrer-Policy | Leaking sensitive URL parameters to third parties |
You can verify your security headers score at securityheaders.com — aim for an A or A+ rating.
8. Use Server-Level Malware Protection
WordPress-level security plugins are important, but server-level protection adds a deeper layer. AsiaGB Hosting includes Imunify360 — a real-time antivirus and Intrusion Prevention System (IPS) that scans uploaded files and blocks attacking IPs automatically.
- Imunify360 scans PHP files in real-time as they are written to disk, catching injected malware before it executes
- Blocks brute-force IPs at the server firewall level, not just WordPress level
- If you suspect a compromise, scan your site with Sucuri SiteCheck for a quick external malware report
- Review your DirectAdmin Access Logs and Error Logs monthly to spot unusual patterns
Warning signs of a compromise: Unexpected redirects, new admin accounts you didn't create, Google Search Console warnings about malware, or sudden drops in search rankings. Act immediately — restore from a clean backup and change all passwords.
9. Keep Regular Backups
Even the most hardened WordPress site can be compromised. Without backups, recovery is extremely difficult. Schedule daily or weekly automatic backups using:
- UpdraftPlus — backs up to Google Drive, Dropbox, or S3
- DirectAdmin Backup Manager — if you host with AsiaGB, use the built-in backup tool
- Test your restore process at least once a year — a backup that can't be restored is useless
Important: Always store backups off-site. If your server is compromised, on-server backups may also be infected or deleted by the attacker.
Security Hardening Checklist
| Task | Status |
|---|---|
| WordPress core, plugins, themes updated | ☐ |
| Login URL changed from /wp-login.php | ☐ |
| Login attempts limited | ☐ |
| 2FA enabled for admin accounts | ☐ |
| DISALLOW_FILE_EDIT set in wp-config.php | ☐ |
| XML-RPC disabled (if not used) | ☐ |
| Security plugin installed and scanned | ☐ |
| Off-site backups scheduled | ☐ |
WordPress Hosting with DirectAdmin — Secure & Fast
AsiaGB Hosting includes DirectAdmin control panel, one-click WordPress install, SSL, and automatic backups. 99% uptime SLA. Starting at 500 THB/year.
View Hosting Plans →