← Back to blog

WordPress Security: 9 Steps That Actually Work

21/07/2026

When someone tells me their site got hacked, the story is almost always the same: a plugin that hadn''t been updated in eight months, or a password like company2023. Attackers rarely pick WordPress sites deliberately. Bots scan the internet and try known vulnerabilities against everything they find. That''s actually good news, because it means defence is about discipline, not budget.

Here are nine steps, ordered roughly by security gained per minute spent.

1. Update core, themes and plugins

Boring advice that solves more problems than anything else on this list. When a security patch ships, the vulnerability details become public — and bots start scanning for it the same day. Enable automatic updates for minor core releases and for plugins you trust. Test bigger changes on staging first.

2. Delete what you don''t use

A deactivated plugin is not a safe plugin. The code still sits on the server and in some cases remains reachable via a direct URL. Remove every theme except the active one and a fallback, and every plugin you haven''t opened in six months. The average site we take on for migration has 24 plugins installed and genuinely uses nine.

3. Strong passwords and a password manager

A 16-character random password is effectively immune to brute force. An eight-character password with a number on the end falls in hours. Use Bitwarden, 1Password or similar — one password you remember, everything else generated.

4. Two-factor authentication

Even if your password leaks in a breach on some unrelated site, 2FA stops the login. Wordfence Login Security or the Two Factor plugin are enough for WordPress. Make it mandatory for every account with the Administrator role.

5. Limit login attempts

By default WordPress allows unlimited attempts against wp-login.php. Set a limit of five attempts followed by a temporary IP block. This also cuts server load — a brute-force run can generate thousands of requests per hour.

6. Least privilege for user roles

The person writing blog posts needs Author or Editor, not Administrator. When an agency finishes a project, disable their account instead of leaving it "just in case". Every admin account is another door.

7. A WAF and DDoS protection in front of the site

A web application firewall filters malicious requests before they reach WordPress — SQL injection attempts, known exploit patterns, bad bots. This is the layer that protects you on the day you forget to update a plugin. Every plan at SEOhosting.rs includes WAF and DDoS protection at no extra cost.

8. Backups on the 3-2-1 rule

Backups don''t prevent attacks, but they''re the only guarantee of recovery. Three copies, two different media, one off-site. A daily automated backup stored on separate infrastructure means your worst case costs an hour instead of a week. Test a restore at least once a year — an untested backup is a hypothesis, not a backup.

9. HTTPS everywhere, no exceptions

An SSL certificate protects data in transit: logins, form submissions, payment details. Force the HTTP to HTTPS redirect at server level and clean up any mixed content warnings. Free SSL is standard now, so there''s no reason for any site to go without.

If you think you''re already compromised

Strange redirects, unfamiliar admin accounts, a warning in Google Search Console — don''t patch on the fly. Take the site offline, rotate every credential including FTP and database, restore a clean backup from before the incident, then update everything and close the hole they came through.

Good hosting handles points 7 and 8 for you. The other seven are discipline, and together they take less than an afternoon. If you''re choosing where to host, take a look at our SEO hosting plans — NVMe storage, daily backups, WAF and free SSL are included across the board.

100% GUARANTEE30-day money back

30-day money back

No questions asked. Full refund if you are not satisfied.