WordPress Security Checklist: 12 Essentials
WordPress powers a huge share of the web, which makes it a popular target. The good news is that nearly all successful attacks exploit the same small set of weaknesses, and every one of them is preventable. This checklist covers the twelve essentials. Work through it once, then repeat the maintenance items on a schedule. None of these require technical expertise.
The 12 essentials
- Keep WordPress, themes, and plugins updated. Updates patch known vulnerabilities, and attackers specifically target sites running old versions. Check for updates weekly and apply them promptly.
- Delete what you do not use. Every inactive plugin and theme is a potential unlocked door. If you are not using it, delete it entirely, not just deactivate it.
- Use strong, unique passwords. Every account gets its own long password, especially admin accounts. Never reuse a password from another service. See Strong Passwords and Two-Factor Authentication.
- Turn on two-factor authentication. Even if a password leaks, a second factor stops the login. Enable it for WordPress admins, cPanel, and your client area.
- Do not use “admin” as a username. It is the first username every automated attack tries. Use something unique, and remove any leftover “admin” account.
- Limit admin accounts. Give administrator access only to people who genuinely need it. Everyone else gets the lowest role that lets them do their job, such as Editor.
- Install plugins only from trusted sources. Stick to the official WordPress plugin directory or reputable commercial developers. Check ratings, update frequency, and install counts before adding anything. See How to Choose Plugins Without Slowing Your Site.
- Keep reliable backups. Automatic server backups plus your own downloaded copies, taken before every major change. Backups do not prevent attacks, but they make recovery fast. See How Website Backups Work, and How to Restore One.
- Use SSL across the whole site. Encrypted connections protect logins and form data. See How to Install a Free SSL Certificate.
- Protect the login page. Limit login attempts so automated password guessing gets blocked, and consider restricting wp-admin access if your team works from fixed locations. A reputable security plugin can handle the login protection for you.
- Keep your own computer clean. Malware on your computer can steal the passwords you type into your own site. Keep your operating system and antivirus current, especially on machines used to manage the website.
- Have a recovery plan before you need it. Know where your backups are, who has admin access, and how to reach support. Read How to Recover a Hacked WordPress Site now, while everything is fine, so the steps are familiar if the day comes.
Make it a routine, not a project
Security fails when it is treated as a one time setup. Put a monthly reminder on your calendar: apply updates, delete anything unused, review the user list for accounts that should not be there, and confirm a recent backup exists. Thirty minutes a month keeps all twelve essentials alive. If the site is ever compromised despite this, the same checklist plus your backups is your recovery path.
What about security plugins?
A well-regarded security plugin adds useful layers like login protection, file change alerts, and malware scanning. It is a complement to this checklist, not a replacement. No plugin fixes weak passwords or outdated software. Pick one reputable plugin, configure it sensibly, and do not stack several security plugins on top of each other; they can conflict and slow your site.
Still stuck? Open a support ticket and tell us which items you would like help with. We can check your site’s update status and backup situation from our side.