WordPress security: how to protect your site
WordPress core is secure when it is looked after. Almost every compromised site we have seen was not hacked because WordPress is weak — it was neglected. Here is the practical version: why sites get targeted, the handful of things that actually protect you, and what to do if the worst happens.
By the Media On Tap editorial team · Published 10 September 2026 · Updated 10 September 2026
Security is the unglamorous work that protects everything else, and it is the part clients most often did not know to ask about. The reassuring truth is that it is mostly habit, not wizardry — a handful of sensible practices, kept up, prevent the overwhelming majority of problems on a WordPress site.
Why WordPress gets targeted
WordPress powers a huge share of the web, which makes it a big target — not because it is insecure, but because attackers automate against the most common software. Those automated attacks overwhelmingly look for the easy way in: out-of-date software, an abandoned plugin with a known vulnerability, or a weak password. They are not sophisticated; they are opportunistic. Which is good news, because it means closing the easy doors stops most of them.
The essentials
Do these and you have handled most of the risk:
- Keep everything updated. WordPress core, themes and plugins — promptly. Out-of-date software is the number-one cause of compromises.
- Strong logins and two-factor authentication. No “admin” usernames, no reused passwords, 2FA on every account.
- Reputable plugins and themes only. From trusted sources, actively maintained; remove anything unused or abandoned.
- Least privilege. Give each person the lowest role they need — not everyone should be an administrator.
Hosting and backups
Good hosting is a security decision as much as a speed one — a quality host hardens its servers, isolates sites and helps you recover. And backups are your safety net: regular, automatic, off-site backups mean that even a worst-case compromise is an inconvenience rather than a catastrophe, because you can restore. Test that you can actually restore from them; a backup you have never verified is a hope, not a plan. Our WordPress hosting guide covers what to look for.
Hardening the site
Beyond the essentials, a few measures raise the bar further: serve the whole site over HTTPS (SSL), limit login attempts to blunt brute-force attacks, use a reputable security plugin or web application firewall to filter malicious traffic, keep sensible file permissions, and remove the default admin account. None of this is exotic, and you do not need all of it on every small site — but on a business site that matters, it is cheap insurance against an expensive problem.
If your site is hacked
Do not panic, and do not just delete things at random. Take the site offline or into maintenance mode, change all passwords, and restore from a known-clean backup if you have one. Scan for and remove the malicious code, update everything, and work out how they got in so it does not happen again — usually an out-of-date plugin. If that is beyond you, get a professional in quickly; the longer a compromised site stays live, the more damage it does to your visitors and your search reputation. Prevention through regular maintenance is far cheaper than recovery.
Want your WordPress site built and looked after properly? We build sites that are secure by default and keep them that way — updates, backups and hardening handled. Our website design and development service is fixed price; get a fixed-price quote.
Frequently asked questions
WordPress core is actively maintained and secure when kept up to date. Most compromised WordPress sites were neglected — running out-of-date software, an abandoned plugin, or a weak password. Security is a maintenance habit, not a one-off setting: timely updates, strong logins, reputable plugins, backups and sensible hardening handle the overwhelming majority of risk.
Keep WordPress core, themes and plugins updated promptly; use strong passwords and two-factor authentication with no ‘admin’ usernames; install only reputable, maintained plugins and remove unused ones; choose good hosting; take regular off-site backups; serve everything over HTTPS; and consider a security plugin or firewall. That handful of habits prevents the vast majority of attacks.
A reputable security plugin or firewall is worthwhile on a business site — it filters malicious traffic, limits login attempts and adds monitoring. But it is not a substitute for the basics: a security plugin on an out-of-date site with a weak password is a lock on an open door. Get updates, logins and backups right first, then add a plugin as an extra layer.
Almost always because of neglect, not because WordPress is weak. Attackers automate against the most common software, looking for out-of-date core, themes or plugins, abandoned plugins with known vulnerabilities, or weak passwords. They are opportunistic rather than sophisticated, which is why keeping everything current and using strong logins stops most of them.
Promptly — ideally within days of updates being released, because many patch security vulnerabilities that attackers actively exploit. That means WordPress core, your theme and every plugin. On a business site this is best handled as part of a regular maintenance routine, with backups taken before updates so you can roll back if anything conflicts.
Go deeper on the decision
The platform guides and the framework behind this comparison.
WordPress website design
How WordPress works end to end, and when it fits.
Read the guide WordPressWordPress maintenance
Why a site is never ‘finished’, and what upkeep actually involves.
Read the guide WordPressWordPress hosting
Why hosting is a security and speed decision, and what to look for.
Read the guide Website pillarWebsite design that ranks and converts
The full picture — strategy, structure, performance and ownership.
Read the guide