The short answer: what actually gets WordPress sites hacked
WordPress powers roughly 43% of all websites, which makes it the most targeted CMS on the internet. But most hacked-site stories share one trait: they weren’t hit by sophisticated zero-day attacks. They were hit through an outdated plugin, a weak admin password, or a misconfigured server — all things entirely within your control.
Securing WordPress in 2026 comes down to 12 steps: keep everything updated, use strong unique credentials, enable two-factor authentication, limit login attempts, install a security plugin with a firewall, force HTTPS, back up automatically offsite, harden wp-config.php, disable file editing and XML-RPC, manage user roles tightly, add a CDN, and monitor for problems. Do all twelve and you’ve closed the doors that automated attack bots knock on daily.
1. Keep WordPress core, themes, and plugins updated — always
Outdated software is the number one entry point. Attackers scan the web for known vulnerabilities in older plugin and theme versions; once they find a match, exploitation is usually automated. A single outdated plugin can compromise your entire site.
Do this today:
– Enable automatic updates for WordPress core, themes, and plugins you trust; update the rest manually the week an update drops.
– Delete every plugin and theme you’re not using — inactive code is still attack surface.
– Never install nulled (pirated) premium plugins or themes. They’re one of the most common malware delivery methods in the WordPress ecosystem.
– Ask your host to run PHP 8.2 or newer. PHP 7.4 is end-of-life and no longer receives security patches.
2. Use strong, unique credentials (no exceptions)
Weak login credentials remain a top vulnerability. Bots try username/password combinations thousands of times per hour, and a password like “admin123” falls in minutes.
The rules:
– Every account gets a 12+ character password (20+ for admins), generated by a password manager — never reused across sites.
– Never use “admin” as a username. If you already do, create a new administrator account, log in as it, and delete the old “admin” account.
– Enforce strong passwords site-wide if you have multiple users.
3. Enable two-factor authentication (2FA)
2FA is the single highest-impact step on this list. Even if a password leaks, the attacker can’t log in without the second factor.
How to set it up (free):
1. Install Wordfence Login Security (free on wordpress.org) or WP 2FA.
2. Install an authenticator app — Google Authenticator, Authy, or Microsoft Authenticator.
3. In WordPress, go to Users → Profile, scan the QR code with the app, and enter the verification code.
4. Save the recovery codes somewhere safe — not on the same computer.
5. Require 2FA for all Administrator and Editor accounts at minimum.
4. Limit login attempts and change your login URL
Bots hammer /wp-login.php and /wp-admin around the clock. Two simple moves cut that traffic dramatically:
- Limit login attempts: Install Limit Login Attempts Reloaded (or use your security plugin’s built-in feature) and set lockout after 3–5 failed attempts. This stops brute-force guessing cold.
- Change the login URL: Use WPS Hide Login to move your login page from
/wp-login.phpto a custom path. This alone blocks the vast majority of automated bot traffic.
5. Install a proper security plugin (pick one)
A security plugin acts as a bodyguard: firewall, malware scanner, login protection, and file integrity monitoring in one package. The three worth considering in 2026:
- Wordfence (free & premium) — the most complete free suite: firewall, malware scanner, brute force protection, and 2FA included. After installing, enable Extended Protection mode in the firewall settings so it loads before anything else on your site.
- Sucuri (free plugin, paid firewall) — the paid DNS-level firewall filters traffic before it reaches your server; the better choice for high-traffic sites. The free plugin covers auditing and hardening.
- Solid Security — best if you want a guided checklist that walks you through each fix.
Critical: don’t run two firewalls at once — they conflict and slow your site. One firewall, configured well, beats two fighting each other.
6. Force HTTPS everywhere
In 2026, HTTPS is non-negotiable — browsers warn visitors away from non-HTTPS sites, and Google ranks HTTPS pages higher.
Do this today:
– Activate the free SSL certificate in your hosting panel (most hosts offer Let’s Encrypt with one click).
– In WordPress Settings → General, make sure both URLs start with https://.
– Add define('FORCE_SSL_ADMIN', true); to wp-config.php to force HTTPS in the admin area.
– Add HSTS headers (your security plugin or host can do this) so browsers never attempt the insecure version.
7. Back up automatically — and store copies offsite
Backups are your last line of defense. If everything else fails, a clean backup restores your site in minutes instead of days.
The setup that works:
– Install UpdraftPlus (the most popular free backup plugin) or Duplicator.
– Schedule daily automatic backups to offsite storage — Google Drive, Dropbox, or Amazon S3. Never store your only backup on the same server as your site.
– Keep 30 days of daily backups plus 3 months of weekly ones.
– Test a restore at least quarterly. A backup you’ve never restored is a hope, not a plan.
8. Harden wp-config.php
This single file holds your database credentials, so it deserves special protection:
- Block direct access by adding this to your
.htaccessfile:
<files wp-config.php>
order allow,deny
deny from all
</files>
- Set file permissions to 400 or 440 so only the server owner can read it.
- Move it one directory above your WordPress root — WordPress will still find it, but web visitors can’t reach it.
- Regenerate the security keys and salts in the file — this forces every logged-in session to re-authenticate, instantly booting out anyone who shouldn’t be there.
- Disable dashboard file editing by adding
define('DISALLOW_FILE_EDIT', true);to wp-config.php. This stops anyone who gains admin access from editing theme and plugin files through the dashboard.
9. Disable XML-RPC (unless you actually use it)
XML-RPC is a legacy API that attackers exploit for brute-force amplification and DDoS attacks. If you don’t use the WordPress mobile app or Jetpack, you don’t need it — disable it through your security plugin (e.g., add add_filter('xmlrpc_enabled', '__return_false'); to a functionality plugin). If Jetpack is active, leave XML-RPC alone — Jetpack needs it.
10. Tighten user roles and clean house
Every extra admin account is an extra attack surface.
- Least privilege, always: owners get Administrator; content people get Editor or Author; everyone else gets Subscriber. Nobody gets admin “just in case.”
- Remove inactive users and audit roles quarterly — former contractors and test accounts are classic forgotten backdoors.
- Change the database table prefix from the default
wp_to something unique during installation. It makes automated SQL injection attempts harder.
11. Put a CDN and firewall in front of your site
A content delivery network like Cloudflare (free plan available) sits between attackers and your server: it filters malicious traffic, absorbs DDoS attacks, and speeds up your site globally. Combined with your security plugin’s firewall, this is the difference between your server handling attacks directly and attacks never reaching it.
Setup takes about 15 minutes: point your domain’s nameservers to Cloudflare, enable the proxy, and turn on “Always Use HTTPS.” It’s one of the highest-value free upgrades in all of WordPress security.
12. Monitor, scan, and stay alert
Security isn’t a one-time project. Build these into a monthly routine:
- Run a malware scan monthly with Wordfence’s scanner or the free Sucuri SiteCheck online tool, which scans your public site for known threats in seconds.
- Review activity logs — the WP Activity Log plugin (or your security plugin’s audit trail) shows failed logins, file changes, and new user accounts. Repeated failed logins from unknown IPs are your cue to block those addresses.
- Watch uptime with a free monitor like UptimeRobot. A site that goes down unexpectedly may have been compromised.
- Verify your site in Google Search Console — Google will alert you directly if it detects malware on your pages.
What to do if you’re already hacked
Don’t panic — follow this order: take the site into maintenance mode, change all passwords (hosting, WordPress, database, FTP), restore from a known-clean backup, then scan everything and update all software. After recovery, work through all 12 steps above so it doesn’t happen again.
A secure site also builds the trust signals that matter for earning from it — if you monetize your WordPress blog, read our Google AdSense approval requirements for 2026 next, since a hacked or insecure site is one of the quiet reasons applications get rejected.
For the official hardening reference, see the WordPress.org documentation and the detailed Wordfence security checklist.
Related: Critical WordPress Flaw Is Under Active Attack — Update Now
Frequently Asked Questions
Can a WordPress site be 100% hack-proof?
No — no website is 100% hack-proof. But the 12 steps above close the vulnerabilities behind the overwhelming majority of real WordPress compromises: outdated software, weak passwords, missing 2FA, and no firewall. Think of it as layers: each one makes an attack more expensive and less likely to succeed.
Which is better for WordPress security: Wordfence or Sucuri?
For most small sites, Wordfence’s free plan is the better starting point — firewall, malware scanner, brute force protection, and 2FA at no cost. Sucuri’s paid DNS-level firewall is worth it for high-traffic sites or stores where downtime costs real revenue, because it filters attacks before they reach your server. Don’t run both firewalls simultaneously.
Do I really need to change the default WordPress login URL?
It helps a lot against automated bots, which blindly attack /wp-login.php. A plugin like WPS Hide Login takes two minutes to set up and eliminates the bulk of brute-force noise. Just don’t treat it as real security on its own — 2FA plus login limits are the layers that stop determined attempts.
How often should I back up my WordPress site?
Daily, automatically, to offsite storage — with at least 30 days of daily backups and 3 months of weekly ones retained. Test restoring at least once a quarter. Sites that rarely change can back up weekly, but anything with comments, orders, or new posts needs daily backups.
What should I do first if I only have 30 minutes?
In order: update everything (core, plugins, themes), enable 2FA on all admin accounts, install Wordfence and enable Extended Protection firewall, and set up UpdraftPlus with daily offsite backups. Those four close the biggest holes fast — then work through the remaining eight steps over the following week.
