Short answer
Keep core, themes and plugins updated, use a long unique admin password, remove anything you are not using, and keep backups you control. Outdated plugins are how the overwhelming majority of WordPress sites get compromised.
Learn more
- How to secure a WordPress siteA practical WordPress security checklist for shared hosting: updates, logins, users, file permissions, wp-config.php and backups.
- Keeping website software updatedWhy updates are the most important security task, what needs updating beyond the CMS itself, and a routine that keeps a small site current.
- Strong passwords and password managersWhat actually makes a password strong, why reuse is the real danger, and how a password manager makes unique passwords effortless.
- Brute-force login attacks: how to recognise and stop themSpot automated login attacks in your access log and stop them wasting resources, with login limits, xmlrpc blocking and strong passwords.
Step-by-step
- Secure a new website and hosting accountIntermediate · 45 min · 9 steps
Not hosting with Traxio yet? WordPress hosting from 99p a month is free for 30 days with no card, then £0.99 a month.