WordPress powers a large share of the web, which makes it a frequent target. The good news is that most attacks exploit outdated software or weak passwords, so a few consistent habits keep your site safe.
Keep Everything Updated
- Update WordPress core as soon as new versions arrive.
- Update plugins and themes regularly.
- Delete plugins and themes you no longer use.
- Never install nulled or pirated plugins, which often contain malware.
Secure Your Logins
- Use a strong, unique password for every admin account.
- Avoid the username
admin. - Limit login attempts with a security plugin.
- Enable two-factor authentication.
Lock Down Key Files
Protect sensitive files with .htaccess rules in your public_html folder:
<Files wp-config.php>
Require all denied
</Files>
Also set wp-config.php permissions to 600 so only you can read it.
Add Layers of Protection
| Layer | Benefit | | --- | --- | | Free SSL via AutoSSL | Encrypts all traffic | | Web application firewall | Filters malicious requests | | Security plugin | Scans and blocks attacks | | Regular backups | Fast recovery if compromised |
Maintain Good Habits
- Scan for malware periodically in cPanel.
- Remove inactive user accounts.
- Keep PHP on a current, supported version.
- Back up before every major update.
Security is ongoing rather than a one-time task. Combining updates, strong credentials, a firewall, and reliable backups removes nearly every common attack path. If you suspect a compromise, contact support on WhatsApp at +254 796 358081.