Have a web emergency? We'll fix your site free!
WP Farm Guide

How to Secure WordPress

Most WordPress hacks are preventable. This is the practical security playbook we run across our own fleet, written by the team that hardens and recovers sites for a living.

Updated June 2026 · 9 min read · WP Farm engineering team

Why WordPress is a target

WordPress powers a huge share of the web, which makes it the biggest target by sheer numbers. Attackers do not usually pick you on purpose. They run automated bots that scan the entire internet looking for known weaknesses: outdated plugins, weak passwords, exposed login pages. If your site has a gap, a bot will find it, whether you are a Fortune 500 or a hobby blog.

That is the reassuring part. Because most attacks are automated and opportunistic, closing the common gaps stops the overwhelming majority of them. You are not defending against a determined human hacker. You are making sure your site is not the easy door the bots walk through. This guide covers the gaps that matter, in order.

Lock down the basics

The fundamentals stop most attacks on their own. They are not glamorous, but skipping them is how most sites get compromised:

  • Update core, plugins, and themes promptly. Outdated software is the number one way sites get hacked.
  • Use strong, unique passwords and turn on two-factor authentication for every admin account.
  • Remove unused plugins and themes entirely. Inactive code can still be exploited.
  • Limit admin accounts to people who truly need them, and delete the default “admin” username.
  • Force HTTPS with a valid SSL certificate so traffic is encrypted end to end.

The hardest part of updates is consistency. A single plugin left unpatched for months is all it takes. This is exactly why we force weekly updates across every site we host, so a known hole never sits open waiting to be found.

Firewall and malware scanning

A web application firewall sits in front of your site and blocks malicious requests before they ever reach WordPress. It stops common attack patterns, brute-force login attempts, and traffic from known bad actors. Pairing a host-level firewall like Imunify360 with a network edge like Cloudflare gives you two layers, one at the server and one before traffic even arrives.

Malware scanning is the other half. A good scanner watches your files for unexpected changes and known malicious signatures, so if something does slip through, you find out fast instead of discovering it weeks later when your site gets blacklisted. Detection speed matters as much as prevention. The sooner you know, the smaller the cleanup.

Harden the server and config

Beyond WordPress itself, the server and its configuration matter. Keep the operating system and PHP patched, ideally with live kernel patching like KernelCare so security fixes apply without reboots or downtime. Lock down file permissions, disable file editing from the WordPress dashboard, and make sure sensitive files like wp-config are not exposed.

On shared hosting, you also inherit your neighbors’ risk: a compromise next door can spill over. Isolated, properly configured hosting removes that whole category of problem. Hardening is layered work, and most of it is set-and-forget once it is done right, which is why it belongs at the host level rather than on your plate every week.

Back up off-site, always

Backups are not a security measure until they are off-site. A backup stored on the same server as your site is useless if that server is compromised or fails, because the attacker or the failure takes the backup with it. Real protection means a full copy written somewhere separate, like Wasabi S3, on a schedule, with enough retention that you can roll back past the moment a problem started.

Test that your backups actually restore. A backup you have never restored is a hope, not a plan. The whole point is that on your worst day, recovery is a quick, proven restore instead of a frantic rebuild. We keep 60 days of off-site backups on every site for exactly this reason.

Have a recovery plan

Even with everything above, assume something could still go wrong one day and know what you would do. A recovery plan is simple: a recent off-site backup you trust, a way to take the site offline if needed, and someone who can clean an infection and find how it got in so it does not happen again. The difference between a bad afternoon and a bad month is having that plan ready before you need it.

If a site is already compromised, do not just delete the visible symptom. Malware usually leaves backdoors so it can return. Proper cleanup means removing the infection, closing the entry point, rotating credentials, and confirming the site is clean before it goes back up. That is specialist work, and it is worth getting right the first time.

Let WP Farm handle your security.

Every WP Farm site ships with Imunify360, KernelCare, Cloudflare, weekly updates, and off-site backups. Security is standard on every plan, and if you have been hacked, we clean up fast.

Common Questions

What people ask about security.

Through outdated software, far more than anything else. An unpatched plugin, theme, or core install with a known vulnerability is the most common entry point, and automated bots scan constantly for them. Weak passwords and missing two-factor authentication are the next most common gaps. Keeping everything updated closes most of the risk.

A firewall and malware scanning are valuable, but where they run matters. Host-level protection like Imunify360 plus a network edge like Cloudflare is stronger and lighter than a heavy plugin doing the same job inside WordPress. The goal is layered protection that blocks bad traffic before it reaches your site.

Daily at minimum, stored off-site, with enough retention to roll back past a problem you did not catch immediately. We keep 60 days of off-site backups so you are never stuck with only a recent copy that already contains the issue. And always confirm your backups actually restore.

Take it offline or into maintenance mode if you can, then get expert eyes on it rather than just deleting the obvious symptom. Malware usually leaves backdoors, so proper cleanup means removing the infection, closing the entry point, and rotating credentials. We handle hacked-site cleanup and hardening if you need it done right.

Generally yes. Managed WordPress hosting isolates your site, keeps the server patched, and bakes in firewalls, scanning, and backups. On crowded shared hosting you inherit your neighbors’ risk and handle hardening yourself. Good managed hosting removes whole categories of common problems before they reach you.

Keep reading

Speed Guide

How to speed up WordPress, from hosting to Core Web Vitals.

Migration Guide

How to move your site to a new host with zero downtime.

Malware Removal

Hacked or infected? See how we clean and harden sites.

Never worry about your website again with WP Farm at the helm.

WP Farm makes it easy to build, manage, and maintain your website with ease.