Saurabh Web Solutions Subscribe
Security

WordPress Security Checklist: 20 Steps to Protect Your Site in 2026

2 free files — jump to downloads
WordPress Security Checklist: 20 Steps to Protect Your Site in 2026 - cover image
On this page
  1. Part 1: Logins and user accounts
  2. 1. Use a unique, strong password for every admin
  3. 2. Turn on two-factor authentication
  4. 3. Do not use "admin" as a username
  5. 4. Give everyone the lowest role they need
  6. 5. Limit login attempts
  7. 6. Remove old accounts
  8. Part 2: Core, plugins and themes
  9. 7. Keep everything updated
  10. 8. Delete what you do not use
  11. 9. Only install plugins from trusted sources
  12. 10. Never use nulled themes or plugins
  13. 11. Use a supported PHP version
  14. Part 3: Backups
  15. 12. Schedule automatic backups
  16. 13. Keep a copy off the server
  17. 14. Test a restore
  18. Part 4: Server and configuration hardening
  19. 15. Use HTTPS everywhere
  20. 16. Disable the file editor in the dashboard
  21. 17. Force HTTPS for the dashboard
  22. 18. Stop directory listing
  23. Part 5: Monitoring
  24. 19. Scan for malware
  25. 20. Monitor uptime and Search Console
  26. Your monthly security routine
  27. What to do if your WordPress site is hacked
  28. Download the files

WordPress powers a huge share of the web, which makes it a popular target for automated attacks. The good news is that attackers rarely break WordPress itself. They walk in through an old plugin, a reused password or a "free" premium theme downloaded from the wrong place. Close those doors and you stop the vast majority of attacks before they start.

This WordPress security checklist is the routine I follow on client sites. It is split into logins, software, backups, server settings and monitoring, with a clear plan for what to do if something goes wrong. Grab the printable PDF and the copy-paste snippets at the end.

Part 1: Logins and user accounts

1. Use a unique, strong password for every admin

A long random password stored in a password manager beats any clever password you can remember. Never reuse your WordPress password on another site; when that site leaks, bots try the same email and password everywhere.

2. Turn on two-factor authentication

Two-factor authentication (2FA) asks for a code from an app on your phone after the password. Even if a password leaks, the attacker cannot log in. Enable it for every administrator and editor, using a reputable 2FA or security plugin.

3. Do not use "admin" as a username

"admin" is the first username every bot tries. If your site still has one, create a new administrator with a different username, log in with it, and delete the old account (WordPress will let you reassign its posts).

4. Give everyone the lowest role they need

WordPress roles exist for a reason. A writer needs the Author role, not Administrator. If an Author account is compromised, the damage is limited to their own posts.

  • Administrator: full control. Keep this to one or two people.
  • Editor: manages all posts and pages.
  • Author: writes and publishes their own posts.
  • Contributor: writes posts but cannot publish.
  • Subscriber: manages only their profile.

5. Limit login attempts

Bots try thousands of password combinations. Limiting failed attempts per IP address slows them down to the point where guessing becomes useless. Many hosts do this at the server level; otherwise a security plugin can.

6. Remove old accounts

Former employees, freelancers and test users are forgotten doors. Review Users every month and delete anyone who no longer needs access.

Part 2: Core, plugins and themes

7. Keep everything updated

Security fixes arrive through updates. Outdated plugins are the number one cause of hacked WordPress sites. Check Dashboard > Updates at least weekly, and take a backup before major updates.

8. Delete what you do not use

A deactivated plugin is still code on your server, and some vulnerabilities can be exploited even when a plugin is inactive. Delete unused plugins and themes completely. Keep one default WordPress theme as a fallback.

9. Only install plugins from trusted sources

Use the official WordPress.org directory or the developer's own website. Before installing, check when the plugin was last updated, how many active installations it has and whether support questions get answered.

10. Never use nulled themes or plugins

"Free" copies of paid plugins from download sites are the most common way malware gets into WordPress. They also receive no security updates. If a premium plugin is too expensive, look for a free alternative on WordPress.org instead.

11. Use a supported PHP version

Old PHP versions stop receiving security fixes. In your hosting panel, choose a current version your theme and plugins support. Test on a staging copy first if your site is old.

Part 3: Backups

12. Schedule automatic backups

Back up both the files and the database. Daily backups suit stores and busy blogs; weekly is fine for small brochure sites.

13. Keep a copy off the server

If your hosting account is compromised or deleted, backups stored in the same account disappear with it. Send at least one copy to cloud storage or download it regularly.

14. Test a restore

A backup you have never restored is a hope, not a plan. Restore one to a staging site once, so you know the process works and how long it takes.

Part 4: Server and configuration hardening

15. Use HTTPS everywhere

Activate the free SSL certificate in your hosting panel and make sure both addresses in Settings > General start with https://.

16. Disable the file editor in the dashboard

WordPress lets administrators edit theme and plugin code from the dashboard. If an attacker gets into an admin account, that editor lets them plant malicious code in seconds. Add this line to wp-config.php, above the "stop editing" comment:

define( 'DISALLOW_FILE_EDIT', true );

17. Force HTTPS for the dashboard

Once SSL works, this line makes sure logins are always encrypted:

define( 'FORCE_SSL_ADMIN', true );

18. Stop directory listing

Without protection, some servers show a list of files in folders that have no index page. On Apache and LiteSpeed hosts (including Hostinger), add Options -Indexes to your .htaccess file. The downloadable snippets file includes this and a rule that blocks direct access to wp-config.php.

Part 5: Monitoring

19. Scan for malware

Use your host's malware scanner or a reputable security plugin to watch for changed files and known malware. Read the reports instead of letting the emails pile up.

20. Monitor uptime and Search Console

A free uptime monitor emails you when the site goes down. Google Search Console's Security issues report warns you if Google detects hacked content, often before visitors notice.

Your monthly security routine

Put a one-hour "maintenance hour" in your calendar once a month:

  1. Confirm a fresh backup exists.
  2. Apply updates, then click through the homepage, a contact form and checkout.
  3. Review user accounts.
  4. Read malware scan results.
  5. Check Search Console for security warnings.

This small habit prevents the big emergencies. If you build sites for clients, offer this routine as a monthly care plan; it protects them and gives you recurring income (see how to price website projects).

What to do if your WordPress site is hacked

  1. Change every password: WordPress users, hosting account, database, FTP/SFTP and email.
  2. Restore a clean backup from before the problem started.
  3. Update everything and remove unknown admin users, plugins and files.
  4. Ask your host for help. Many hosts scan and clean infected sites.
  5. Request a review in Google Search Console once the site is clean, so any warning in search results is removed.
Tip: Speed and security go together. Removing unused plugins improves both. When you are done here, work through our WordPress speed optimization guide.

Download the printable checklist and the wp-config snippets below. Print the PDF, tick each box, and repeat the monthly section every month.

Download the files

Free to use in your own and client projects · no sign-up · tested before upload. Always try files on a staging site first and keep a backup.

Download not working? Tell me and I'll fix it.

Frequently asked questions

Is WordPress secure enough for a business website?

Yes. WordPress core is maintained by a dedicated security team and is safe when kept updated. Most hacks come from outdated or pirated plugins and themes, weak passwords and missing backups, which this checklist addresses.

Do I need a security plugin?

Not always. Many good hosts already provide a firewall, malware scanning and login protection at the server level. A security plugin is useful when your host does not offer these features or when you want two-factor authentication and activity logs inside WordPress.

How often should I back up WordPress?

Match the backup frequency to how often the site changes. A brochure site can be backed up weekly, while a store or busy blog should be backed up daily. Keep at least one copy outside your hosting account.

Should I turn on automatic plugin updates?

For well-maintained plugins from reputable developers, automatic minor updates are usually a good idea on small sites. For business-critical plugins such as WooCommerce or your page builder, update manually after taking a backup, ideally testing on staging first.

What is the first thing to do if my site is hacked?

Change every password, including hosting, database, FTP and email, so the attacker loses access. Then restore a clean backup from before the hack, update everything and remove unknown users and plugins.