You don’t need a heavyweight security suite. These measures prevent the vast majority of WordPress compromises.
1. Keep everything updated
Core, plugins and themes. Enable auto-updates for trusted plugins. Updating WordPress, themes and plugins safely
2. Delete what you don’t use
Unused plugins and themes, even deactivated, can be exploited. Delete them.
3. Lock down logins
- Unique, long passwords for every user, stored in a password manager
- No user called
admin - Two-factor authentication through a reputable plugin
- Limit login attempts (Brute-force login attacks: how to recognise and stop them)
4. Review users
Users → All Users: remove old accounts, and give each person the lowest role they need. Editors don’t need to be Administrators.
5. Protect wp-config.php and disable file editing
Add to wp-config.php:
define('DISALLOW_FILE_EDIT', true);
This removes the built-in theme and plugin editor, which attackers use to insert code once they’ve logged in.
6. Sensible file permissions
Folders 755, files 644, wp-config.php 640 or 600 if your site still works. Never 777. File permissions explained (644, 755 and why never 777)
7. Block PHP in uploads
Create wp-content/uploads/.htaccess containing:
<FilesMatch "\.php$">
Require all denied
</FilesMatch>
Uploaded images never need to run as code.
8. HTTPS everywhere
How to force HTTPS (redirect HTTP to HTTPS)
9. Backups you can restore
Kept off the server. How to back up WordPress
If it’s already compromised
Everything in this guide works on Traxio’s WordPress hosting: 30 days free, then £0.99 a month.