DevCru — Web & App Development Agency
Säkerhet
4 min lästid

Secure a WordPress Site: Complete Checklist

A practical, step-by-step checklist to securely configure a WordPress site: updates, roles, 2FA, backups, hardening and monitoring.

Dela:

Securing a WordPress site is not a one-time activity. It combines configuration, processes and monitoring. This guide gives a practical checklist with priorities, examples and number-based guidelines you can apply immediately.

I cover updates, roles, 2FA, backups, hardening and monitoring — step by step. No marketing fluff. Just what to do and why it matters.

Start with an inventory

  • List active plugins and themes. Fewer components mean fewer attack surfaces.
  • Document user accounts and roles. Revoke access you no longer need.
  • Check hosting details: PHP version, automatic server updates, and snapshot frequency.

Make a short risk list of five items. That becomes your priority roadmap.

Updates: policy and frequency

Most compromises exploit outdated core, plugins or themes.

  • Enable automatic core security updates. Schedule feature updates on a staging site.
  • Check plugins and themes weekly. If you receive many updates, triage by security impact and user-facing risk.
  • Always test updates on staging for business-critical sites.

Suggested settings:

  • Core security updates: automatic.
  • Plugins/themes: weekly testing and manual deploy.

Roles and access control

Follow least-privilege principles.

  • Remove or rename default 'admin' user.
  • Use developer accounts with expiration for contractors (e.g., 30 days).
  • Assign roles strictly: editor vs administrator.
  • Configure max login attempts: 5 attempts in 15 minutes is a good baseline.

For a small team, limit administrators to one or two people.

Two-factor authentication (2FA)

2FA stops most brute-force and credential-stuffing attacks. Enforce it for all administrative accounts.

Steps:

  • Require 2FA for users with administrator privileges.
  • Prefer TOTP apps or hardware keys (FIDO2) for critical logins.
  • For external teams, issue time-limited access and require 2FA.

Cost example: commercial 2FA plugins or services typically cost €0–€30/month per site; this can vary per project.

Backups: strategy and testing

Backups are your last line of defense.

  • Schedule daily automated backups of files and database.
  • Keep at least 30 days of history; consider 90 days offsite for important sites.
  • Test restores quarterly.

Example table: backup options

Hosting snapshots

Benefit
Fast, whole-system
Drawback
Host-dependent
Indicative cost (per month)
€5–€30 (can vary per project)

External backup service

Benefit
Offsite, automated
Drawback
Extra cost
Indicative cost (per month)
€10–€50 (can vary per project)

Manual exports

Benefit
Low cost
Drawback
Error prone
Indicative cost (per month)
€0–€10 (can vary per project)

Follow the WordPress backup guidance for scripts and detailed procedures: https://developer.wordpress.org/advanced-administration/security/backup/.

Hardening: practical steps

Hardening reduces the number of ways an attacker can succeed. The official WordPress hardening guide lists pragmatic measures: https://developer.wordpress.org/advanced-administration/security/hardening/.

Key actions:

  • Remove unused themes and plugins.
  • Disable XML-RPC if unused.
  • Set correct file permissions: usually 644 for files, 755 for directories.
  • Protect wp-config.php and set secure salts.
  • Disable PHP execution in the uploads directory via server rules.

Note: aggressive hardening can break legacy plugins. Always test on staging.

Monitoring and detection

Monitoring finds issues early.

  • Enable server and application logs.
  • Configure alerts for multiple failed logins, file integrity changes, and spikes in 404/500 errors.
  • Add uptime monitoring and a WAF for additional protection.

Send alerts to email or Slack. Expect basic monitoring services to cost €10–€80/month; this can vary per project.

Incident response: who does what

  • Define roles: who contacts hosting, who restores backups, who handles external communication.
  • Keep a template for internal and external messages.
  • Take a forensic snapshot before you overwrite compromised files.

Checklist (step-by-step)

  • Inventory plugins, themes and accounts.
  • Enable automatic security core updates.
  • Schedule weekly plugin/theme updates on staging.
  • Remove unused plugins and themes.
  • Remove or rename default admin users.
  • Set strong password policies and max login attempts (5 attempts).
  • Enforce 2FA for administrators.
  • Schedule daily backups with 30+ days retention and test restores quarterly.
  • Apply hardening (wp-config protection, file permissions, disable xml-rpc).
  • Activate monitoring and alerts.
  • Document incident response and run tabletop tests.

Tools and cost examples

  • Managed hosting with security and snapshots: €15–€150/month (can vary per project).
  • Backup service: €5–€50/month (can vary per project).
  • Security/WAF plugin or service: €0–€80/month (can vary per project).

If you prefer not to run this yourself, DevCru is a senior-led web and app development shop offering maintenance and managed security. During a website redesign this checklist is a good reset moment.

Closing

Security is ongoing. Follow the order: inventory, updates, roles, 2FA, backups, hardening, monitoring. Use the WordPress hardening and backup guides as concrete references: https://developer.wordpress.org/advanced-administration/security/hardening/ and https://developer.wordpress.org/advanced-administration/security/backup/.

Need help implementing this checklist or a security audit? Request a quote via /quote.

Källor

Alla siffror och riktlinjer i denna artikel kan kontrolleras i källorna nedan.

Har du ett projekt i åtanke?

Berätta kort vad du vill bygga. Du får en ärlig bedömning av omfattning, pris och tidsplan inom en arbetsdag.

Begär en offert

Relaterade tjänster

Fortsätt på sidan som matchar detta ämne.

Läs mer

Andra artiklar som passar bra med den här.