Securing a WordPress site is not a one-time activity. It combines configuration, processes and monitoring. This guide gives a practical checklist with priorities, examples and number-based guidelines you can apply immediately.
I cover updates, roles, 2FA, backups, hardening and monitoring — step by step. No marketing fluff. Just what to do and why it matters.
Start with an inventory
- List active plugins and themes. Fewer components mean fewer attack surfaces.
- Document user accounts and roles. Revoke access you no longer need.
- Check hosting details: PHP version, automatic server updates, and snapshot frequency.
Make a short risk list of five items. That becomes your priority roadmap.
Updates: policy and frequency
Most compromises exploit outdated core, plugins or themes.
- Enable automatic core security updates. Schedule feature updates on a staging site.
- Check plugins and themes weekly. If you receive many updates, triage by security impact and user-facing risk.
- Always test updates on staging for business-critical sites.
Suggested settings:
- Core security updates: automatic.
- Plugins/themes: weekly testing and manual deploy.
Roles and access control
Follow least-privilege principles.
- Remove or rename default 'admin' user.
- Use developer accounts with expiration for contractors (e.g., 30 days).
- Assign roles strictly: editor vs administrator.
- Configure max login attempts: 5 attempts in 15 minutes is a good baseline.
For a small team, limit administrators to one or two people.
Two-factor authentication (2FA)
2FA stops most brute-force and credential-stuffing attacks. Enforce it for all administrative accounts.
Steps:
- Require 2FA for users with administrator privileges.
- Prefer TOTP apps or hardware keys (FIDO2) for critical logins.
- For external teams, issue time-limited access and require 2FA.
Cost example: commercial 2FA plugins or services typically cost €0–€30/month per site; this can vary per project.
Backups: strategy and testing
Backups are your last line of defense.
- Schedule daily automated backups of files and database.
- Keep at least 30 days of history; consider 90 days offsite for important sites.
- Test restores quarterly.
Example table: backup options
Hosting snapshots
- Benefit
- Fast, whole-system
- Drawback
- Host-dependent
- Indicative cost (per month)
- €5–€30 (can vary per project)
External backup service
- Benefit
- Offsite, automated
- Drawback
- Extra cost
- Indicative cost (per month)
- €10–€50 (can vary per project)
Manual exports
- Benefit
- Low cost
- Drawback
- Error prone
- Indicative cost (per month)
- €0–€10 (can vary per project)
| Type | Benefit | Drawback | Indicative cost (per month) |
|---|---|---|---|
| Hosting snapshots | Fast, whole-system | Host-dependent | €5–€30 (can vary per project) |
| External backup service | Offsite, automated | Extra cost | €10–€50 (can vary per project) |
| Manual exports | Low cost | Error prone | €0–€10 (can vary per project) |
Follow the WordPress backup guidance for scripts and detailed procedures: https://developer.wordpress.org/advanced-administration/security/backup/.
Hardening: practical steps
Hardening reduces the number of ways an attacker can succeed. The official WordPress hardening guide lists pragmatic measures: https://developer.wordpress.org/advanced-administration/security/hardening/.
Key actions:
- Remove unused themes and plugins.
- Disable XML-RPC if unused.
- Set correct file permissions: usually 644 for files, 755 for directories.
- Protect wp-config.php and set secure salts.
- Disable PHP execution in the uploads directory via server rules.
Note: aggressive hardening can break legacy plugins. Always test on staging.
Monitoring and detection
Monitoring finds issues early.
- Enable server and application logs.
- Configure alerts for multiple failed logins, file integrity changes, and spikes in 404/500 errors.
- Add uptime monitoring and a WAF for additional protection.
Send alerts to email or Slack. Expect basic monitoring services to cost €10–€80/month; this can vary per project.
Incident response: who does what
- Define roles: who contacts hosting, who restores backups, who handles external communication.
- Keep a template for internal and external messages.
- Take a forensic snapshot before you overwrite compromised files.
Checklist (step-by-step)
- Inventory plugins, themes and accounts.
- Enable automatic security core updates.
- Schedule weekly plugin/theme updates on staging.
- Remove unused plugins and themes.
- Remove or rename default admin users.
- Set strong password policies and max login attempts (5 attempts).
- Enforce 2FA for administrators.
- Schedule daily backups with 30+ days retention and test restores quarterly.
- Apply hardening (wp-config protection, file permissions, disable xml-rpc).
- Activate monitoring and alerts.
- Document incident response and run tabletop tests.
Tools and cost examples
- Managed hosting with security and snapshots: €15–€150/month (can vary per project).
- Backup service: €5–€50/month (can vary per project).
- Security/WAF plugin or service: €0–€80/month (can vary per project).
If you prefer not to run this yourself, DevCru is a senior-led web and app development shop offering maintenance and managed security. During a website redesign this checklist is a good reset moment.
Closing
Security is ongoing. Follow the order: inventory, updates, roles, 2FA, backups, hardening, monitoring. Use the WordPress hardening and backup guides as concrete references: https://developer.wordpress.org/advanced-administration/security/hardening/ and https://developer.wordpress.org/advanced-administration/security/backup/.
Need help implementing this checklist or a security audit? Request a quote via /quote.
Källor
Alla siffror och riktlinjer i denna artikel kan kontrolleras i källorna nedan.
- Hardening WordPress — WordPress.org
- WordPress backups — WordPress.org
- OWASP Top 10 — OWASP
Har du ett projekt i åtanke?
Berätta kort vad du vill bygga. Du får en ärlig bedömning av omfattning, pris och tidsplan inom en arbetsdag.
Begär en offertRelaterade tjänster
Fortsätt på sidan som matchar detta ämne.
Läs mer
Andra artiklar som passar bra med den här.

