WordPress is secure when maintained, but its popularity makes it a target. Hardening reduces your attack surface across logins, files, and the admin area.
Secure the Login
- Never use
adminas a username; create a unique administrator name. - Enforce strong passwords for every account.
- Add two-factor authentication with a plugin.
- Limit login attempts to slow brute-force attacks.
- Consider moving the login page away from the default
/wp-adminpath.
Lock Down Files
Set correct permissions through cPanel File Manager:
| Item | Permission | |---|---| | Folders | 755 | | Files | 644 | | wp-config.php | 600 or 640 |
Disable file editing from the dashboard by adding this to wp-config.php:
define( 'DISALLOW_FILE_EDIT', true );
Stay Updated and Monitored
- Keep core, themes, and plugins current, since outdated code is the leading cause of compromise.
- Remove plugins and themes you no longer use.
- Install a security plugin such as Wordfence or Sucuri for firewall and malware scanning.
- Take regular off-site backups so you can recover quickly.
Only install plugins and themes from reputable sources, since nulled or pirated extensions are a frequent source of hidden malware.