WordPress runs over 40 percent of the web. That reach makes it a prime target, but most attacks go after the same handful of weak spots. The good news is that a few straightforward hardening steps close those gaps. Here is what every site owner should do.
1. Keep Everything Updated
Outdated core, themes, and plugins are the single most common way attackers get in. WordPress can handle minor and security updates automatically. Turn that on. For major updates, test on a staging site first if you can, but do not sit on them for weeks. Most managed WordPress hosts apply these updates for you as part of your plan.
2. Use Strong Passwords and Two-Factor Authentication
Weak passwords are still the easiest door to kick in. Use a password manager so every account gets a unique, complex password. On top of that, turn on two-factor authentication for any user who can publish or manage settings. The Two Factor plugin from WordPress is free and takes about five minutes to set up.
3. Limit Login Attempts
Brute force tools try thousands of password guesses a minute. Just capping login attempts to five or ten before a temporary lockout stops these attacks cold. A number of plugins handle this automatically with sensible defaults out of the box.
4. Disable File Editing in the Dashboard
WordPress lets administrators edit theme and plugin files directly from the admin panel by default. If an attacker compromises an admin account, that feature lets them inject malicious code trivially. Add define('DISALLOW_FILE_EDIT', true); to your wp-config.php file and that capability disappears.
5. Secure wp-config.php and .htaccess
Your wp-config.php holds database credentials and security keys. If your server layout allows it, move it one directory above the WordPress root. Either way, set its file permissions to 600 or 640 so the rest of the system cannot read it. On Apache servers, a well-crafted .htaccess can block access to sensitive files and disable directory listing entirely.
6. Install a Web Application Firewall
A WAF filters bad traffic before it reaches WordPress. Cloudflare offers a free WAF that blocks SQL injection, cross-site scripting, and common exploit patterns. For WordPress-specific rules, a security plugin at the application layer can add another level of protection tailored to the platform.
7. Back Up Regularly and Test Your Restores
Even locked-down sites can get hit. Automated nightly backups stored off-site are your safety net. More importantly, test your restore process at least once a quarter. A backup file you cannot actually restore is just expensive storage.
Wrapping Up
Security is not a one-time checklist. It is an ongoing habit. Cover these seven areas and you close off the vast majority of attacks targeting WordPress sites today. If you would rather focus on running your business and let someone else handle the hardening, our maintenance plans include all of these measures as standard and monitor your site around the clock.
Related reading: The Cloudflare WAF rules we recommend cover the most common WordPress exploit patterns. If you are new to securing your site, start with cybersecurity basics for small business.
