WordPress

How to Secure a WordPress Website

Reduce risk with maintained software, least-privilege access, backups and an incident plan.

WordPress security combines software maintenance, access management and recoverability. HTTPS is necessary, but it does not prevent a vulnerable plugin or compromised administrator account from changing the site.

Practical steps

  1. Keep WordPress, themes and plugins supported and updated. Test important updates in staging and remove software you no longer use.
  2. Give each person their own account with the minimum required role. Use strong unique passwords and enable suitable multi-factor authentication where supported.
  3. Protect hosting and registrar access as well as WordPress. Limit where secrets are stored and avoid leaving database exports or backup archives in publicly reachable directories.
  4. Maintain independent recovery copies where appropriate and define who responds to suspicious changes. Record known-good configurations and update history for investigation.

Check the result

Review administrator accounts, update status, HTTPS and backup restorability. Check whether staging or old copies are publicly reachable and remove unnecessary exposure.

Before you proceed

If compromise is suspected, preserve evidence and request a recovery assessment. A simple restore may reintroduce the vulnerability or erase orders; malware removal is not automatically part of hosting.