WordPress Security Checklist: 30 Steps to Protect Your Website

The 30-step hardening checklist we apply to WordPress sites, including this one: updates, logins, users, plugins, server settings, headers, backups and monitoring, explained in plain English.
WordPress Security Checklist: 30 Steps to Protect Your Website, MIVAQ guide cover

WordPress powers a huge share of the web, which makes it a constant target for automated attacks. The good news is that most successful hacks exploit a small set of avoidable weaknesses: outdated plugins, weak passwords, unnecessary features left switched on and no backups. This checklist is the hardening process we apply to the WordPress sites we build and maintain, including mivaq.com itself. You do not need to do everything in one day, but every item reduces your risk.

This article is part of our complete guide: WordPress Security and Malware Removal: The Complete Guide.

Updates and software (1–6)

  1. Keep WordPress core updated. Enable automatic minor updates at minimum, and apply major updates after a quick check.
  2. Update plugins and themes promptly. Most hacks we clean began with a known vulnerability in an outdated plugin.
  3. Remove unused plugins and themes. Deactivated plugins can still be exploited if their files remain. Keep one default theme as a fallback and delete the rest.
  4. Avoid nulled (pirated) plugins and themes. They frequently contain backdoors.
  5. Choose plugins carefully. Prefer actively maintained plugins with recent updates and a good support record.
  6. Keep PHP on a supported version through your hosting control panel.

Logins and users (7–13)

  1. Use strong, unique passwords for every account, stored in a password manager.
  2. Enable two-factor authentication for all administrators.
  3. Limit login attempts to slow brute-force attacks. We use a lockout after repeated failures on our own builds.
  4. Use generic login error messages, so attackers cannot tell whether a username exists.
  5. Avoid “admin” as a username and do not display usernames publicly as author names where avoidable.
  6. Block user enumeration through author archives and the REST API users endpoint for visitors.
  7. Apply least privilege: give each person the lowest role they need, and remove accounts when people leave.

WordPress configuration (14–19)

  1. Disable file editing in the dashboard by adding define('DISALLOW_FILE_EDIT', true); to wp-config.php. If an attacker gets into an admin account, they cannot edit theme or plugin code from the dashboard.
  2. Disable XML-RPC if you do not need it (most sites do not). It is a common brute-force and amplification target.
  3. Disable application passwords if you do not use them.
  4. Hide the WordPress version from page source and feeds. It does not stop attacks, but it reduces easy fingerprinting.
  5. Close comments if you do not use them, to remove a spam channel.
  6. Use unique security keys and salts in wp-config.php, and change them after any incident.

Server and file system (20–24)

  1. Block PHP execution in the uploads folder. Uploads should contain images and documents, never executable code. A simple .htaccess rule does this on Apache and LiteSpeed servers.
  2. Set correct file permissions: typically 644 for files and 755 for folders, with wp-config.php more restricted.
  3. Protect sensitive files such as wp-config.php, .htaccess, debug logs and backup files from public access.
  4. Remove readme.html and license.txt from the root, which reveal version information.
  5. Use SFTP or SSH, never plain FTP.

HTTP security headers (25–27)

  1. HTTPS everywhere with HSTS (Strict-Transport-Security), so browsers always use a secure connection.
  2. X-Content-Type-Options: nosniff and X-Frame-Options: SAMEORIGIN to reduce content sniffing and clickjacking risks.
  3. Referrer-Policy and Permissions-Policy to limit what information is shared and which browser features are available. Remove the X-Powered-By header that reveals server software.

Backups and monitoring (28–30)

  1. Automated off-site backups of files and database, kept for at least 30 days, and tested by restoring occasionally. See WordPress backup strategy.
  2. Uptime and change monitoring, so you are alerted to downtime or unexpected file changes.
  3. Google Search Console with alerts going to a monitored inbox, so you hear about hacked content or malware quickly.

What about security plugins?

Security plugins can implement many of these items, add a firewall and scan for malware. They are useful, especially for site owners who are not comfortable editing configuration files. But they are not a substitute for updates, strong logins and good hosting, and stacking several security plugins can cause conflicts and slow the site. Choose one reputable option, or implement hardening at the server and code level, as we do on our own builds to avoid unnecessary plugins.

Write a simple incident plan

Even well-protected sites can be attacked, so decide in advance what you will do. A one-page plan is enough: who to contact (your developer, your host), where backups are stored and how to restore them, where passwords are kept and how to change them all quickly, and how to put the site into maintenance mode. Keep a list of every plugin and theme in use, with their sources and licence details, so clean reinstalls are fast. When something goes wrong, a plan turns a stressful day into a manageable task.

A monthly security routine

  1. Apply pending updates and check the site still works.
  2. Review the users list and remove accounts no longer needed.
  3. Confirm the latest backup completed and is stored off-site.
  4. Check Search Console’s Security Issues report.
  5. Review installed plugins and remove any that are no longer necessary.
  6. Run a malware scan or check your host’s scan results.

Hosting matters

Good hosting provides account isolation, a web application firewall, malware scanning, automatic backups and current PHP versions. Cheap hosting without isolation means one compromised site can affect others on the same server. When we see repeated reinfections, hosting is often part of the story.

Security and SEO

Security is an SEO issue. Hacked sites can be flagged with warnings, filled with spam pages and lose rankings. See signs your WordPress site is hacked and removing spam URLs from Google. Many hardening steps, such as HTTPS and fewer plugins, also improve speed and trust.

How to prioritise

  • Today: updates, remove unused plugins, strong passwords, two-factor authentication, backups.
  • This week: disable file editing and XML-RPC, block PHP in uploads, limit logins, review users.
  • This month: security headers, file permissions, monitoring, hosting review.

How we apply it

This checklist is part of every WordPress build and maintenance plan we run, from small business sites to stores. You can see our approach to WordPress projects on our WordPress services page and in projects such as SmartVideo. If your site has already been compromised, our malware removal service includes this hardening after the clean-up.

Related guides and services

Get expert help

Want this checklist applied to your site without the guesswork? We harden WordPress sites, set up backups and monitoring, and clean up existing infections. Start with our WordPress security and malware removal, browse real client results in our case studies, or contact us for a free, no-pressure review of your website.

Frequently asked questions

Is WordPress secure?

WordPress core is well maintained. Most hacks come from outdated plugins, weak passwords and poor hosting.

Do I need a security plugin?

Not necessarily. The key steps can be done at server and code level, but a reputable plugin helps non-technical owners.

How often should I update plugins?

Check weekly and apply security updates as soon as possible.

Does hiding wp-admin improve security?

It reduces automated noise slightly, but strong passwords, two-factor authentication and updates matter far more.

Keep reading

How to Start a Shopify Store – MIVAQ complete guide cover
ShopifyWeb
Step-by-step guide to starting a Shopify store in 2026: costs, plans, themes, products, payments, shipping, SEO and a full launch checklist.
Wix & Squarespace SEO – MIVAQ complete guide cover
SEOWeb
The complete 2026 guide to Wix SEO and Squarespace SEO: setup, titles, images, speed, local SEO, schema, redirects and fixing sites not
How to Build a WordPress Website – MIVAQ complete guide cover
WebWordPress
Step-by-step guide to building a WordPress website for your business in 2026: costs, hosting, themes, plugins, SEO, speed, security and a launch

Need help putting this into practice?

We turn ideas like these into working websites, stores and growth plans. Tell us what you are working on.