DevCru — Web & App Development Agency
Security
4 min read

Secure a WordPress Site: Complete Checklist

A practical, step-by-step checklist to securely configure a WordPress site: updates, roles, 2FA, backups, hardening and monitoring.

Share:

Securing a WordPress site is not a one-time activity. It combines configuration, processes and monitoring. This guide gives a practical checklist with priorities, examples and number-based guidelines you can apply immediately.

I cover updates, roles, 2FA, backups, hardening and monitoring — step by step. No marketing fluff. Just what to do and why it matters.

Start with an inventory

  • List active plugins and themes. Fewer components mean fewer attack surfaces.
  • Document user accounts and roles. Revoke access you no longer need.
  • Check hosting details: PHP version, automatic server updates, and snapshot frequency.

Make a short risk list of five items. That becomes your priority roadmap.

Updates: policy and frequency

Most compromises exploit outdated core, plugins or themes.

  • Enable automatic core security updates. Schedule feature updates on a staging site.
  • Check plugins and themes weekly. If you receive many updates, triage by security impact and user-facing risk.
  • Always test updates on staging for business-critical sites.

Suggested settings:

  • Core security updates: automatic.
  • Plugins/themes: weekly testing and manual deploy.

Roles and access control

Follow least-privilege principles.

  • Remove or rename default 'admin' user.
  • Use developer accounts with expiration for contractors (e.g., 30 days).
  • Assign roles strictly: editor vs administrator.
  • Configure max login attempts: 5 attempts in 15 minutes is a good baseline.

For a small team, limit administrators to one or two people.

Two-factor authentication (2FA)

2FA stops most brute-force and credential-stuffing attacks. Enforce it for all administrative accounts.

Steps:

  • Require 2FA for users with administrator privileges.
  • Prefer TOTP apps or hardware keys (FIDO2) for critical logins.
  • For external teams, issue time-limited access and require 2FA.

Cost example: commercial 2FA plugins or services typically cost €0–€30/month per site; this can vary per project.

Backups: strategy and testing

Backups are your last line of defense.

  • Schedule daily automated backups of files and database.
  • Keep at least 30 days of history; consider 90 days offsite for important sites.
  • Test restores quarterly.

Example table: backup options

Hosting snapshots

Benefit
Fast, whole-system
Drawback
Host-dependent
Indicative cost (per month)
€5–€30 (can vary per project)

External backup service

Benefit
Offsite, automated
Drawback
Extra cost
Indicative cost (per month)
€10–€50 (can vary per project)

Manual exports

Benefit
Low cost
Drawback
Error prone
Indicative cost (per month)
€0–€10 (can vary per project)

Follow the WordPress backup guidance for scripts and detailed procedures: https://developer.wordpress.org/advanced-administration/security/backup/.

Hardening: practical steps

Hardening reduces the number of ways an attacker can succeed. The official WordPress hardening guide lists pragmatic measures: https://developer.wordpress.org/advanced-administration/security/hardening/.

Key actions:

  • Remove unused themes and plugins.
  • Disable XML-RPC if unused.
  • Set correct file permissions: usually 644 for files, 755 for directories.
  • Protect wp-config.php and set secure salts.
  • Disable PHP execution in the uploads directory via server rules.

Note: aggressive hardening can break legacy plugins. Always test on staging.

Monitoring and detection

Monitoring finds issues early.

  • Enable server and application logs.
  • Configure alerts for multiple failed logins, file integrity changes, and spikes in 404/500 errors.
  • Add uptime monitoring and a WAF for additional protection.

Send alerts to email or Slack. Expect basic monitoring services to cost €10–€80/month; this can vary per project.

Incident response: who does what

  • Define roles: who contacts hosting, who restores backups, who handles external communication.
  • Keep a template for internal and external messages.
  • Take a forensic snapshot before you overwrite compromised files.

Checklist (step-by-step)

  • Inventory plugins, themes and accounts.
  • Enable automatic security core updates.
  • Schedule weekly plugin/theme updates on staging.
  • Remove unused plugins and themes.
  • Remove or rename default admin users.
  • Set strong password policies and max login attempts (5 attempts).
  • Enforce 2FA for administrators.
  • Schedule daily backups with 30+ days retention and test restores quarterly.
  • Apply hardening (wp-config protection, file permissions, disable xml-rpc).
  • Activate monitoring and alerts.
  • Document incident response and run tabletop tests.

Tools and cost examples

  • Managed hosting with security and snapshots: €15–€150/month (can vary per project).
  • Backup service: €5–€50/month (can vary per project).
  • Security/WAF plugin or service: €0–€80/month (can vary per project).

If you prefer not to run this yourself, DevCru is a senior-led web and app development shop offering maintenance and managed security. During a website redesign this checklist is a good reset moment.

Closing

Security is ongoing. Follow the order: inventory, updates, roles, 2FA, backups, hardening, monitoring. Use the WordPress hardening and backup guides as concrete references: https://developer.wordpress.org/advanced-administration/security/hardening/ and https://developer.wordpress.org/advanced-administration/security/backup/.

Need help implementing this checklist or a security audit? Request a quote via /quote.

Sources

Every figure and guideline in this article can be checked in the sources below.

Got a project in mind?

Tell us briefly what you want to build. You get an honest read on scope, price and timeline within one business day.

Request a quote

Related services

Continue on the page that matches this topic.

Keep reading

Other articles that pair well with this one.