Securing a WordPress site is not a one-time activity. It combines configuration, processes and monitoring. This guide gives a practical checklist with priorities, examples and number-based guidelines you can apply immediately.
I cover updates, roles, 2FA, backups, hardening and monitoring — step by step. No marketing fluff. Just what to do and why it matters.
Start with an inventory
- List active plugins and themes. Fewer components mean fewer attack surfaces.
- Document user accounts and roles. Revoke access you no longer need.
- Check hosting details: PHP version, automatic server updates, and snapshot frequency.
Make a short risk list of five items. That becomes your priority roadmap.
Updates: policy and frequency
Most compromises exploit outdated core, plugins or themes.
- Enable automatic core security updates. Schedule feature updates on a staging site.
- Check plugins and themes weekly. If you receive many updates, triage by security impact and user-facing risk.
- Always test updates on staging for business-critical sites.
Suggested settings:
- Core security updates: automatic.
- Plugins/themes: weekly testing and manual deploy.
Roles and access control
Follow least-privilege principles.
- Remove or rename default 'admin' user.
- Use developer accounts with expiration for contractors (e.g., 30 days).
- Assign roles strictly: editor vs administrator.
- Configure max login attempts: 5 attempts in 15 minutes is a good baseline.
For a small team, limit administrators to one or two people.
Two-factor authentication (2FA)
2FA stops most brute-force and credential-stuffing attacks. Enforce it for all administrative accounts.
Steps:
- Require 2FA for users with administrator privileges.
- Prefer TOTP apps or hardware keys (FIDO2) for critical logins.
- For external teams, issue time-limited access and require 2FA.
Cost example: commercial 2FA plugins or services typically cost €0–€30/month per site; this can vary per project.
Backups: strategy and testing
Backups are your last line of defense.
- Schedule daily automated backups of files and database.
- Keep at least 30 days of history; consider 90 days offsite for important sites.
- Test restores quarterly.
Example table: backup options
Hosting snapshots
- Benefit
- Fast, whole-system
- Drawback
- Host-dependent
- Indicative cost (per month)
- €5–€30 (can vary per project)
External backup service
- Benefit
- Offsite, automated
- Drawback
- Extra cost
- Indicative cost (per month)
- €10–€50 (can vary per project)
Manual exports
- Benefit
- Low cost
- Drawback
- Error prone
- Indicative cost (per month)
- €0–€10 (can vary per project)
| Type | Benefit | Drawback | Indicative cost (per month) |
|---|---|---|---|
| Hosting snapshots | Fast, whole-system | Host-dependent | €5–€30 (can vary per project) |
| External backup service | Offsite, automated | Extra cost | €10–€50 (can vary per project) |
| Manual exports | Low cost | Error prone | €0–€10 (can vary per project) |
Follow the WordPress backup guidance for scripts and detailed procedures: https://developer.wordpress.org/advanced-administration/security/backup/.
Hardening: practical steps
Hardening reduces the number of ways an attacker can succeed. The official WordPress hardening guide lists pragmatic measures: https://developer.wordpress.org/advanced-administration/security/hardening/.
Key actions:
- Remove unused themes and plugins.
- Disable XML-RPC if unused.
- Set correct file permissions: usually 644 for files, 755 for directories.
- Protect wp-config.php and set secure salts.
- Disable PHP execution in the uploads directory via server rules.
Note: aggressive hardening can break legacy plugins. Always test on staging.
Monitoring and detection
Monitoring finds issues early.
- Enable server and application logs.
- Configure alerts for multiple failed logins, file integrity changes, and spikes in 404/500 errors.
- Add uptime monitoring and a WAF for additional protection.
Send alerts to email or Slack. Expect basic monitoring services to cost €10–€80/month; this can vary per project.
Incident response: who does what
- Define roles: who contacts hosting, who restores backups, who handles external communication.
- Keep a template for internal and external messages.
- Take a forensic snapshot before you overwrite compromised files.
Checklist (step-by-step)
- Inventory plugins, themes and accounts.
- Enable automatic security core updates.
- Schedule weekly plugin/theme updates on staging.
- Remove unused plugins and themes.
- Remove or rename default admin users.
- Set strong password policies and max login attempts (5 attempts).
- Enforce 2FA for administrators.
- Schedule daily backups with 30+ days retention and test restores quarterly.
- Apply hardening (wp-config protection, file permissions, disable xml-rpc).
- Activate monitoring and alerts.
- Document incident response and run tabletop tests.
Tools and cost examples
- Managed hosting with security and snapshots: €15–€150/month (can vary per project).
- Backup service: €5–€50/month (can vary per project).
- Security/WAF plugin or service: €0–€80/month (can vary per project).
If you prefer not to run this yourself, DevCru is a senior-led web and app development shop offering maintenance and managed security. During a website redesign this checklist is a good reset moment.
Closing
Security is ongoing. Follow the order: inventory, updates, roles, 2FA, backups, hardening, monitoring. Use the WordPress hardening and backup guides as concrete references: https://developer.wordpress.org/advanced-administration/security/hardening/ and https://developer.wordpress.org/advanced-administration/security/backup/.
Need help implementing this checklist or a security audit? Request a quote via /quote.
Sources
Every figure and guideline in this article can be checked in the sources below.
- Hardening WordPress — WordPress.org
- WordPress backups — WordPress.org
- OWASP Top 10 — OWASP
Got a project in mind?
Tell us briefly what you want to build. You get an honest read on scope, price and timeline within one business day.
Request a quoteRelated services
Continue on the page that matches this topic.
Keep reading
Other articles that pair well with this one.

