WordPress Security Checklist: 20 Steps to Protect Your Site in 2026
2 free files — jump to downloads
On this page
- Part 1: Logins and user accounts
- 1. Use a unique, strong password for every admin
- 2. Turn on two-factor authentication
- 3. Do not use "admin" as a username
- 4. Give everyone the lowest role they need
- 5. Limit login attempts
- 6. Remove old accounts
- Part 2: Core, plugins and themes
- 7. Keep everything updated
- 8. Delete what you do not use
- 9. Only install plugins from trusted sources
- 10. Never use nulled themes or plugins
- 11. Use a supported PHP version
- Part 3: Backups
- 12. Schedule automatic backups
- 13. Keep a copy off the server
- 14. Test a restore
- Part 4: Server and configuration hardening
- 15. Use HTTPS everywhere
- 16. Disable the file editor in the dashboard
- 17. Force HTTPS for the dashboard
- 18. Stop directory listing
- Part 5: Monitoring
- 19. Scan for malware
- 20. Monitor uptime and Search Console
- Your monthly security routine
- What to do if your WordPress site is hacked
- Download the files
WordPress powers a huge share of the web, which makes it a popular target for automated attacks. The good news is that attackers rarely break WordPress itself. They walk in through an old plugin, a reused password or a "free" premium theme downloaded from the wrong place. Close those doors and you stop the vast majority of attacks before they start.
This WordPress security checklist is the routine I follow on client sites. It is split into logins, software, backups, server settings and monitoring, with a clear plan for what to do if something goes wrong. Grab the printable PDF and the copy-paste snippets at the end.
Part 1: Logins and user accounts
1. Use a unique, strong password for every admin
A long random password stored in a password manager beats any clever password you can remember. Never reuse your WordPress password on another site; when that site leaks, bots try the same email and password everywhere.
2. Turn on two-factor authentication
Two-factor authentication (2FA) asks for a code from an app on your phone after the password. Even if a password leaks, the attacker cannot log in. Enable it for every administrator and editor, using a reputable 2FA or security plugin.
3. Do not use "admin" as a username
"admin" is the first username every bot tries. If your site still has one, create a new administrator with a different username, log in with it, and delete the old account (WordPress will let you reassign its posts).
4. Give everyone the lowest role they need
WordPress roles exist for a reason. A writer needs the Author role, not Administrator. If an Author account is compromised, the damage is limited to their own posts.
- Administrator: full control. Keep this to one or two people.
- Editor: manages all posts and pages.
- Author: writes and publishes their own posts.
- Contributor: writes posts but cannot publish.
- Subscriber: manages only their profile.
5. Limit login attempts
Bots try thousands of password combinations. Limiting failed attempts per IP address slows them down to the point where guessing becomes useless. Many hosts do this at the server level; otherwise a security plugin can.
6. Remove old accounts
Former employees, freelancers and test users are forgotten doors. Review Users every month and delete anyone who no longer needs access.
Part 2: Core, plugins and themes
7. Keep everything updated
Security fixes arrive through updates. Outdated plugins are the number one cause of hacked WordPress sites. Check Dashboard > Updates at least weekly, and take a backup before major updates.
8. Delete what you do not use
A deactivated plugin is still code on your server, and some vulnerabilities can be exploited even when a plugin is inactive. Delete unused plugins and themes completely. Keep one default WordPress theme as a fallback.
9. Only install plugins from trusted sources
Use the official WordPress.org directory or the developer's own website. Before installing, check when the plugin was last updated, how many active installations it has and whether support questions get answered.
10. Never use nulled themes or plugins
"Free" copies of paid plugins from download sites are the most common way malware gets into WordPress. They also receive no security updates. If a premium plugin is too expensive, look for a free alternative on WordPress.org instead.
11. Use a supported PHP version
Old PHP versions stop receiving security fixes. In your hosting panel, choose a current version your theme and plugins support. Test on a staging copy first if your site is old.
Part 3: Backups
12. Schedule automatic backups
Back up both the files and the database. Daily backups suit stores and busy blogs; weekly is fine for small brochure sites.
13. Keep a copy off the server
If your hosting account is compromised or deleted, backups stored in the same account disappear with it. Send at least one copy to cloud storage or download it regularly.
14. Test a restore
A backup you have never restored is a hope, not a plan. Restore one to a staging site once, so you know the process works and how long it takes.
Part 4: Server and configuration hardening
15. Use HTTPS everywhere
Activate the free SSL certificate in your hosting panel and make sure both addresses in Settings > General start with https://.
16. Disable the file editor in the dashboard
WordPress lets administrators edit theme and plugin code from the dashboard. If an attacker gets into an admin account, that editor lets them plant malicious code in seconds. Add this line to wp-config.php, above the "stop editing" comment:
define( 'DISALLOW_FILE_EDIT', true );
17. Force HTTPS for the dashboard
Once SSL works, this line makes sure logins are always encrypted:
define( 'FORCE_SSL_ADMIN', true );
18. Stop directory listing
Without protection, some servers show a list of files in folders that have no index page. On Apache and LiteSpeed hosts (including Hostinger), add Options -Indexes to your .htaccess file. The downloadable snippets file includes this and a rule that blocks direct access to wp-config.php.
Part 5: Monitoring
19. Scan for malware
Use your host's malware scanner or a reputable security plugin to watch for changed files and known malware. Read the reports instead of letting the emails pile up.
20. Monitor uptime and Search Console
A free uptime monitor emails you when the site goes down. Google Search Console's Security issues report warns you if Google detects hacked content, often before visitors notice.
Your monthly security routine
Put a one-hour "maintenance hour" in your calendar once a month:
- Confirm a fresh backup exists.
- Apply updates, then click through the homepage, a contact form and checkout.
- Review user accounts.
- Read malware scan results.
- Check Search Console for security warnings.
This small habit prevents the big emergencies. If you build sites for clients, offer this routine as a monthly care plan; it protects them and gives you recurring income (see how to price website projects).
What to do if your WordPress site is hacked
- Change every password: WordPress users, hosting account, database, FTP/SFTP and email.
- Restore a clean backup from before the problem started.
- Update everything and remove unknown admin users, plugins and files.
- Ask your host for help. Many hosts scan and clean infected sites.
- Request a review in Google Search Console once the site is clean, so any warning in search results is removed.
Tip: Speed and security go together. Removing unused plugins improves both. When you are done here, work through our WordPress speed optimization guide.
Download the printable checklist and the wp-config snippets below. Print the PDF, tick each box, and repeat the monthly section every month.
Download the files
Free to use in your own and client projects · no sign-up · tested before upload. Always try files on a staging site first and keep a backup.
-
WordPress security checklist (printable PDF)wordpress-security-checklist.pdf · 5.6 KB · v2026Download WordPress security checklist (printable PDF) (5.6 KB)
-
wp-config.php and .htaccess security snippetswp-config-security-snippets.txt · 1 KB · v1.0Download wp-config.php and .htaccess security snippets (1 KB)
Download not working? Tell me and I'll fix it.
Frequently asked questions
Is WordPress secure enough for a business website?
Yes. WordPress core is maintained by a dedicated security team and is safe when kept updated. Most hacks come from outdated or pirated plugins and themes, weak passwords and missing backups, which this checklist addresses.
Do I need a security plugin?
Not always. Many good hosts already provide a firewall, malware scanning and login protection at the server level. A security plugin is useful when your host does not offer these features or when you want two-factor authentication and activity logs inside WordPress.
How often should I back up WordPress?
Match the backup frequency to how often the site changes. A brochure site can be backed up weekly, while a store or busy blog should be backed up daily. Keep at least one copy outside your hosting account.
Should I turn on automatic plugin updates?
For well-maintained plugins from reputable developers, automatic minor updates are usually a good idea on small sites. For business-critical plugins such as WooCommerce or your page builder, update manually after taking a backup, ideally testing on staging first.
What is the first thing to do if my site is hacked?
Change every password, including hosting, database, FTP and email, so the attacker loses access. Then restore a clean backup from before the hack, update everything and remove unknown users and plugins.


