Most WordPress security advice is scattered across a dozen different articles, each covering one piece. Here’s the whole picture in one place — the practices that actually reduce risk, organized by how much they matter.
The fundamentals (do these first)
- Keep core, themes, and plugins updated. This remains the single highest-impact security practice on this entire list. See our full guide on update timing for specifics.
- Use strong, unique passwords and two-factor authentication on every account with administrator access, without exception.
- Remove admin accounts nobody uses anymore. Every account with access is another possible entry point — former employees, old developer accounts, and test logins should be deleted, not just disabled.
- Take daily, off-server backups. Not a direct prevention measure, but the single most important thing standing between an incident and a disaster.
Reducing your attack surface
- Delete unused plugins and themes instead of just deactivating them — inactive code sitting on your server can still be exploited if it contains a known vulnerability.
- Disable XML-RPC if you’re not using it for a specific integration (like remote publishing) — it’s a well-known target for brute-force amplification attacks.
- Disable the theme and plugin file editor in wp-admin. If an admin account is ever compromised, this closes off one of the easiest paths to planting malicious code.
- Use a non-default admin username. A login page with a valid username already guessed removes half of what an attacker needs.
Detection and monitoring
- Malware and file-change scanning so unauthorized changes get caught quickly rather than discovered months later.
- Uptime monitoring that alerts you the moment your site goes down, rather than waiting for a customer to mention it.
- Regular login and user account audits — an unfamiliar administrator account is one of the clearest signs a site has already been compromised.
Prevention and detection are both necessary, and neither is sufficient alone. Even a well-hardened site can be affected by a zero-day vulnerability in a plugin nobody could have patched in time. That’s exactly why monitoring and a tested backup matter as much as the hardening steps above.
Infrastructure-level practices
- HTTPS everywhere, with HSTS enabled, not just on pages that collect sensitive information.
- Security headers like X-Content-Type-Options and X-Frame-Options, which cost nothing to add and close off entire categories of common web attacks.
- Least-privilege user roles — not every team member who needs to edit content needs full administrator access.
The honest summary
None of this is complicated in isolation. What makes WordPress security hard in practice isn’t any single item on this list — it’s maintaining every item on this list at the same time, indefinitely, while everything else about running a business also demands attention. That consistency, more than any individual setting, is what a managed Care Plan is actually built to provide.
Keep Your WordPress Site Protected
Daily backups, security monitoring, and updates — handled for you, starting at $59/mo.
See Our Care Plans