
Every website with an online admin panel is a target for hackers and well-known CMS are especially vulnerable. If you are new to WordPress (and even if you are not!) here are a few tips for ensuring the security of your website.

1. Make sure your WordPress site has a firewall
As soon as your site goes live, make sure you have a firewall installed. There are a number of security plugins available in the WordPress directory. Our favourite, with over 2 million active and installations and 3,351 five-star ratings to date is Wordfence . The free version is brilliant for most small sites, it is easy to configure and blocks malicious attempts very effectively.
2. Never use the default “admin” as a username
In order to frustrate any brute-force logins, make it difficult to guess any part of your login details. Choose usernames which are not simple to guess.
Ensure you configure your firewall plugin to limit the number of login attempts, to immediately block any login attempt using “admin” or any non-existent usernames.
3. Choose secure passwords for ALL logins
You should insist that anyone who has a login for the site must use a secure password. Secure passwords are at least 8 characters long.
They should include:
- at least one uppercase letter [A-Z]
- at least one lowercase letter [a-z]
- a number
- a special character such as ! @ $ % ^ & * ( ) – _ = + [ ] ; : ‘ ” , < . > / ?
Ideally, a secure password should NOT be a real word and certainly should not include personal details such as birthdays, email addresses or pet names.
4. Consider using two-factor authentication for your login
This ensures that if anyone attempts a login with your username and correct password, you will receive an authentication code (usually via your mobile) which must be added to complete the login.
5. Hide your WordPress version
All WordPress installations show the WP version in the page source code by default. You should remove this because it could provide a potential hacker with information about any vulnerabilities on your site if you don’t keep WordPress up to date at all times.
Setting WordPress to update automatically is also a smart move.
6. Keep all your plugins up to date at all times
Out of date plugins are a vulnerability. Many updates are created because a weakness has been found in a plugin and the plugin owner has created a patch to mend this.
7. Only install plugins from the WordPress Directory
All the plugins in the WordPress Directory are monitored to ensure security and this provides peace of mind.
8. Never continue to use an abandoned plugin
A plugin which has not been updated in a year or more will be marked as abandoned. This means no-one appears to be checking for vulnerabilities. An abandoned plugin may be perfectly secure, but is it worth the risk? A good security plugin will alert you to abandoned plugins.
If a plugin you are using is removed from the WP Directory, you should find an alternative. Occasionally a plugin is sold on to another developer after it appears in the directory. Sometimes the purchaser might modify the plugin for their own ends. It is possible to use an insecure plugin to create a “back door” into the website in order to add rogue content. The Directory removes plugins with known vulnerabilities.
9. Use SSL to encrypt the data sent between visitor browsers and your server
Having an SSL certificate for your website will make it difficult to breach the connection or to spoof your information. All browsers now mark sites which do not have an SSL certificate as “Not secure” in an attempt to encourage everyone to secure their connection. Your visitors may well be put off by the “Not secure” message.
10. Back up your site regularly
This is a simple but REALLY important thing to do! Take backups of the site files AND the database and download them to a secure location. If you should get hacked, you then will have a fall-back copy of the site which can be restored on your server.
Don’t wait for your site to get hacked before you take steps to secure it. That’s rather like buying a burglar alarm after you’ve been burgled!