WordPress Security Hardening Checklist: 25 Practical Steps
A practical WordPress security hardening checklist covering accounts, updates, wp-config.php, file permissions, server settings, backups and monitoring.
A WordPress security hardening checklist covers six areas: user accounts, software updates, WordPress settings, file permissions, server configuration, and backups with monitoring. Most hacks we clean up trace back to one weak spot in that list, usually an outdated plugin or a stolen password. Fixing these basics stops most automated attacks before they start.
This checklist is based on WordPress.org’s official hardening guide and what we see when we clean up hacked sites. Some steps are for site owners, some for whoever manages your server. If your site has already been hacked, start with our guide to the first hour after a WordPress hack instead, and harden after the cleanup.
Accounts and logins
Stolen and reused passwords are one of the most common ways in. These steps make an account much harder to take over.
- Use two-factor authentication for every administrator. Two-factor authentication, or 2FA, asks for a code from a phone app in addition to the password. WordPress.org’s hardening guide recommends it. Several well-maintained plugins add it.
- Use long, unique passwords from a password manager. This includes hosting, database, SFTP, domain registrar and email accounts, not only WordPress.
- Give each person their own account. Shared logins make it impossible to remove one person’s access or see who did what.
- Use the lowest role that works. Most content editors do not need the Administrator role. Editor or Author is usually enough.
- Remove stale accounts. Former staff, past agencies and old freelancers should not still have access. Review the user list every quarter.
- Review application passwords. Application passwords let tools connect to your site without the main password. Revoke any that are no longer used, from each user’s profile screen.
- Limit login attempts. Blocking repeated failed logins slows down password-guessing attacks. Many hosts and firewall services do this for you; otherwise, use a plugin.
Updates and software
Outdated and abandoned plugins are the entry point we find most often during cleanups.
- Keep WordPress core, plugins and themes up to date. Security fixes only protect you once they are installed. Test updates on a staging site first; our guide to safe WordPress updates with staging and tests explains how.
- Remove plugins and themes you do not use. Deactivated plugins and unused themes still sit on the server and can still be attacked. Keep one default theme as a fallback and delete the rest.
- Replace abandoned plugins. A plugin that has not been updated in a long time may never get its next security fix. Check the “Last updated” date on its WordPress.org page.
- Install software only from trusted sources. “Nulled” or pirated premium plugins often come with malware built in.
- Run a supported PHP version. PHP versions past their end of life no longer get security fixes. The PHP supported versions page shows current dates, and our guide to upgrading PHP for WordPress covers doing it safely.
WordPress configuration
Several of the most useful settings live in wp-config.php.
- Turn off the built-in file editor. By default, administrators can edit theme and plugin code from the dashboard. If an attacker gets an admin login, that editor lets them add malware in seconds. WordPress.org recommends disabling it:
define( 'DISALLOW_FILE_EDIT', true );
- Consider blocking all file changes from the dashboard. The stricter
DISALLOW_FILE_MODSconstant also blocks installing and updating plugins and themes from the dashboard. Use it only if your updates run another way, such as through deployment or WP-CLI. - Use unique secret keys and salts. These protect login cookies. Generate fresh ones with the WordPress.org secret key generator, and replace them after any security incident. With WP-CLI, the WordPress command-line tool, run
wp config shuffle-salts. - Force secure logins. Serve the whole site over HTTPS, and add
define( 'FORCE_SSL_ADMIN', true );so logins and admin pages always use an encrypted connection. - Turn off debug output on the live site.
WP_DEBUG_DISPLAYshould befalsein production, so error messages do not reveal file paths and other details to visitors.
Files and permissions
- Set sensible file permissions. WordPress.org’s hardening guide recommends
755for folders and644for files, withwp-config.phpreadable only by you and the web server, which usually means400or440. Your host’s setup may differ, so check with them before changing permissions in bulk. - Block PHP in the uploads folder. The uploads folder should hold media, not code. Blocking PHP there stops a common type of backdoor from running. On Apache, a
.htaccessfile insidewp-content/uploadscan do this:
<FilesMatch "\.php$">
Require all denied
</FilesMatch>
On Nginx, the same rule goes in the server configuration. Test the site afterwards, since a small number of plugins expect to run code from uploads.
- Protect
wp-config.phpfrom direct requests. WordPress.org’s guide shows an Apache rule that denies all web access to the file. You can also move it one folder above the site’s root, which WordPress supports. - Turn off directory listing. Visitors should not be able to browse the contents of a folder that has no index file. On Apache,
Options -Indexesdoes this.
Server and network
- Use a web application firewall. A web application firewall, or WAF, filters out known attack traffic before it reaches WordPress. It can run at your host, at a content delivery network, or as a plugin.
- Keep sites separate. On shared hosting, one hacked site can infect every other site in the same account. Give important sites their own account or server user. Our guide to managed WordPress hosting vs. a VPS covers the trade-offs.
- Turn off services you do not use. If nothing on your site uses XML-RPC, an older remote publishing interface, you can block it to reduce password-guessing traffic. Check first: some apps and plugins still rely on it. Likewise, close old FTP accounts and use SFTP or SSH instead.
Backups and monitoring
- Keep off-site backups and test them. WordPress.org recommends regular, complete backups kept in a trusted place. Store at least one copy away from your hosting account, keep several weeks of history, and restore a backup to a test site now and then to confirm it works.
Beyond the numbered list, watch for problems so you hear about them in hours, not weeks:
- Set up Google Search Console so Google can alert you to security issues.
- Get alerts when new administrator accounts are created.
- Monitor for unexpected file changes, especially in core files and the uploads folder.
- Keep server logs long enough to investigate an incident.
If you want to know what attackers typically leave behind, our guide to finding WordPress backdoors shows where to look.
Where to start if you are short on time
You do not have to do all 25 steps this week. If you only have an hour, start with the steps that block the most common attacks:
- Turn on two-factor authentication for every administrator.
- Install pending updates, after a backup, and delete plugins and themes you do not use.
- Remove user accounts that no longer need access.
- Add
DISALLOW_FILE_EDITtowp-config.php. - Confirm that a recent off-site backup exists and can be restored.
Then work through the rest of the list section by section, starting with the areas where your site is weakest.
What hardening does not do
Hardening reduces risk. It does not remove it. A new vulnerability in a popular plugin can still affect a well-hardened site, which is why fast updates, backups and monitoring matter as much as any setting. Some common advice also helps less than it seems: hiding the WordPress version or renaming the login page may cut down noise in your logs, but it will not stop an attacker who is targeting a known plugin flaw.
Treat this checklist as something you repeat, not a one-time project. We review these items as part of ongoing WordPress maintenance, and we count gaps such as stale admin accounts and missing hardening as security exposure when we measure technical debt.
Want this done for you?
Our WordPress maintenance service covers updates, backups, monitoring and regular hardening reviews, and our server management service handles the server-side items. We give a fixed quote after an assessment. Contact us and we will start with a review of where your site stands today.
Frequently asked questions
- What is WordPress hardening?
- Hardening means changing settings and habits so a site is harder to break into and does less damage if something goes wrong. It covers accounts, software updates, file permissions, server settings, backups and monitoring.
- Do I need a security plugin to harden WordPress?
- A security plugin can help with login protection, scanning and alerts, but it is not a replacement for hardening. Many of the most important steps, such as updates, file permissions and server settings, happen outside any plugin.
- Should I change the WordPress database table prefix?
- On a new site, using a prefix other than wp_ is easy and WordPress.org notes it can block some SQL injection attacks. On an existing site, changing it is risky and gives little benefit, so we focus on other steps first.
- How often should I review WordPress security settings?
- Check updates and backups every week, and review users, plugins and server settings at least every quarter. Review everything again after any security incident or major change.