WordPress security checklist: 15 checks and how to fix each

By the WPMate team · · 10 min read

Most hacked WordPress sites aren't victims of clever, targeted attacks. They're hit by automated bots looking for the same few weaknesses: an outdated plugin with a known hole, a guessable admin login, a setting nobody turned off. Closing those gaps stops most of the risk.

Here are fifteen checks, roughly in order of importance. Each says what to look for and how to fix it. Items marked (audit) are checked automatically by WPMate's security audit.

Updates and backups

1. Keep plugins up to date (audit)

Outdated plugins are among the most common ways WordPress sites are compromised. When a vulnerability in a popular plugin is published, bots start scanning for unpatched sites quickly. Check Dashboard → Updates at least weekly, and consider enabling automatic updates for plugins you trust. Back up first, and check the site afterwards.

2. Keep themes and WordPress core up to date (audit)

The same applies to themes, including inactive ones, and to WordPress itself. Minor core releases, which often contain security fixes, install automatically by default; major versions are worth applying promptly once your plugins support them.

3. Remove plugins and themes you don't use (audit)

Deactivated plugins are still files on your server, and some vulnerabilities can be exploited even when a plugin is inactive. Delete what you don't need. Keep your active theme and one default theme as a fallback.

4. Have backups you've actually tested

Backups are your recovery plan for everything else on this list. Keep automatic daily backups stored off the server (your host's backups, or a plugin that sends them to cloud storage), and do a test restore at least once, so you know it works before you need it.

Accounts and logins

5. Don't use “admin” as a username (audit)

Bots try “admin” first. If you have that account, create a new administrator with a unique username, sign in as the new user, then delete “admin” and assign its content to the new account.

6. Keep administrator accounts to a minimum (audit)

Every admin account is a way in. Give people the lowest role that works: Editor for content teams, Author or Contributor for writers. Remove accounts for people who have left.

7. Turn on two-factor authentication

A strong, unique password plus two-factor authentication stops most login attacks, even when a password leaks. WordPress doesn't include 2FA by default; well-maintained plugins add it. Make it mandatory for administrators.

8. Lock down registration (audit)

If Settings → General → Anyone can register is on and the default role is anything above Subscriber, anyone on the internet can create an account with real permissions. Turn registration off unless you need it; if you do, keep the default role at Subscriber.

Configuration

9. Disable the built-in file editor (audit)

WordPress lets administrators edit theme and plugin code from the dashboard. If an admin login is ever stolen, that editor makes it easy to inject malicious code. Add this line to wp-config.php:

define( 'DISALLOW_FILE_EDIT', true );

10. Don't show errors to visitors (audit)

With WP_DEBUG on, PHP errors appear on the page, revealing file paths and other details. Keep it off on the live site. If you log errors, make sure wp-content/debug.log isn't publicly downloadable, or log to a path outside the web root.

11. Disable XML-RPC if you don't use it (audit)

XML-RPC is an older remote-access interface often used for password-guessing attacks. If you don't use the WordPress mobile app, Jetpack or another service that needs it, disable it with a security plugin or at the server.

12. Use HTTPS everywhere (audit)

Without HTTPS, logins and form submissions travel unencrypted. Install a certificate (most hosts provide them free) and make sure both site addresses in Settings → General use https://.

Server and files

13. Run a supported PHP version (audit)

PHP versions stop receiving security fixes after a few years. Your hosting control panel usually lets you switch versions; test on a staging copy first if you can. Running a version that still gets security support is the goal.

14. Check core files haven't been modified (audit)

WordPress publishes checksums for every core file. Files that don't match, or extra PHP files in wp-content/uploads, which should only contain media, are classic signs of a compromise. If you find either, treat the site as possibly hacked: restore a clean backup or get professional help, and change all passwords.

15. Use a web application firewall and malware scanning

A firewall (from your host, a CDN or a security plugin) blocks many attacks before they reach WordPress, and a malware scanner looks for infections the checks above can't see. These go beyond what a configuration audit can do, and are worth having on any business site.

Run the checks in one go

Twelve of these fifteen checks are automated in WPMate's security audit. Connect your site and ask your assistant:

Run a security audit and explain each finding in plain English, most serious first.

Then fix what can be fixed safely from the same chat: updating or deleting plugins and themes goes to your approval page, and a backup copy is taken before every update or deletion. Changes to wp-config.php, PHP versions and suspicious files are left for you or your host, with exact instructions.

Check your site in under a minute

The security audit is included in WPMate Pro.

Create free account