WordPress itself is secure software. Most WordPress sites that get hacked aren't hacked because of WordPress. They're hacked because of an outdated plugin, a weak password or cheap hosting. The good news is that a few sensible habits prevent the vast majority of problems.
1. Keep everything updated
WordPress core, your theme and every plugin. Updates frequently fix security holes, and attackers actively scan for sites running old versions. Back up first, update, then check the site still works. Our maintenance guide explains a good routine.
2. Remove what you don't use
Deactivated plugins and unused themes can still be exploited. If you're not using it, delete it. Fewer plugins also means a faster site; see our list of essential WordPress plugins.
3. Only install trusted plugins and themes
Stick to the official WordPress directory or reputable developers. Never install "free" copies of premium plugins from random websites. They're a common way malware gets in.
4. Lock down logins
- Use strong, unique passwords and a password manager.
- Turn on two-factor authentication for every admin.
- Don't use "admin" as a username.
- Limit login attempts.
- Give each person their own account, with the lowest role they need.
- Remove accounts for people who've left.
5. Choose good hosting
Decent hosting includes server-level security, malware scanning, automatic backups and isolation from other sites. Very cheap shared hosting often cuts corners here. Our guide to choosing web hosting in India helps.
6. Use HTTPS everywhere
An SSL certificate encrypts data between your visitors and your site. Most hosts provide free certificates. Make sure every page loads over https.
7. Back up regularly, and off-site
Automatic daily or weekly backups, stored somewhere other than your hosting account. Test that you can actually restore one. A backup you can't restore isn't a backup.
8. Add a security plugin or firewall
A reputable security plugin or a web application firewall can block common attacks, scan for malware and alert you to suspicious activity.
If your site does get hacked
- Don't panic, and don't delete everything.
- Contact your host; many can help identify and clean infections.
- Change all passwords: WordPress, hosting, database, FTP.
- Restore a clean backup if you have one, then update everything.
- Check Google Search Console for security warnings and request a review once clean.
The simplest way to stay safe
Most security comes down to routine: updates, backups and good passwords, every month. If that's not something you want to think about, our WordPress Yearly Maintenance plan handles it for you. Get in touch.