How to secure a WordPress site

A practical WordPress security checklist for shared hosting: updates, logins, users, file permissions, wp-config.php and backups.

How-to guideIntermediate2 min readUpdated

You don’t need a heavyweight security suite. These measures prevent the vast majority of WordPress compromises.

1. Keep everything updated

Core, plugins and themes. Enable auto-updates for trusted plugins. Updating WordPress, themes and plugins safely

2. Delete what you don’t use

Unused plugins and themes, even deactivated, can be exploited. Delete them.

3. Lock down logins

4. Review users

Users → All Users: remove old accounts, and give each person the lowest role they need. Editors don’t need to be Administrators.

5. Protect wp-config.php and disable file editing

Add to wp-config.php:

define('DISALLOW_FILE_EDIT', true);

This removes the built-in theme and plugin editor, which attackers use to insert code once they’ve logged in.

6. Sensible file permissions

Folders 755, files 644, wp-config.php 640 or 600 if your site still works. Never 777. File permissions explained (644, 755 and why never 777)

7. Block PHP in uploads

Create wp-content/uploads/.htaccess containing:

<FilesMatch "\.php$">
  Require all denied
</FilesMatch>

Uploaded images never need to run as code.

8. HTTPS everywhere

How to force HTTPS (redirect HTTP to HTTPS)

9. Backups you can restore

Kept off the server. How to back up WordPress

If it’s already compromised

How to clean a hacked WordPress site

Everything in this guide works on Traxio’s WordPress hosting: 30 days free, then £0.99 a month.

Popular

Tip: press / to search from any pageSee all results