Save up to 40% on annual plans plus a free domain for your first year.Learn More ›

Hardening a WordPress site that is already live

You do not need a security plugin so much as a short list of habits. These are the ones that actually correlate with sites that never get compromised.

Update, or accept the consequence

Almost every compromise we clean up came in through a known vulnerability in an out-of-date plugin, months after a fix shipped. Turn on automatic updates for minor releases and review the majors monthly.

Reduce the surface

Deactivating a plugin does not make it safe; the files are still on disk and still reachable. Delete what you do not use, and remove themes you are not running.

Make the admin harder to reach

Two-factor on every account with write access, and no shared logins: team accounts exist so that each person has their own and you can revoke one without changing anything else.

  • Enforce two-factor for the whole team
  • Give editors editor accounts, not administrator accounts
  • Disable file editing from the dashboard
  • Rotate any credential that has ever been in a chat message

Assume it will happen anyway

Backups are the only control that works after the fact. Ours are daily and kept for thirty days, restores are self-service, and it is worth doing one deliberately now so that you already know how it works when it matters.

1 min read

Recommended for you

Leave a Comment