Opens in a new tab
Yasir Shabbir Logo
Yasir ShabbirFull-Stack AI Developer
Let's Talk

WordPress Security Checklist: What Gets Sites Hacked and How to Harden Yours

Oct 5, 2026Yasir Shabbir6 min read

Note: I may earn a commission from links on my site. This doesn't influence my reviews or project evaluations.

Shield with a padlock inside a hexagon barrier deflecting attacks

The short answer: most hacked WordPress sites are not broken into through WordPress itself. They are compromised through plugins, weak logins and missing updates. According to Patchstack’s State of WordPress Security in 2026, 91% of the 11,334 new vulnerabilities found in 2025 were in plugins, only 6 were in WordPress core, and 46% had no patch available when they were publicly disclosed.

I fix compromised and unstable sites for a living, and the same handful of weaknesses show up again and again. This article explains what actually gets sites hacked, then gives you a hardening checklist you can work through in an afternoon, with the official WordPress guidance behind each step.

What actually gets WordPress sites hacked?

Almost always one of the causes in the table below. They are boring, which is exactly why they work: attackers scan the internet automatically for known weaknesses instead of targeting individual sites.

CauseHow it happensFix
Vulnerable plugin or themeA known flaw is exploited soon after disclosureUpdate fast, remove what you don’t use
Abandoned pluginNo developer left to patch known flawsReplace it with a maintained alternative
Weak or reused passwordAutomated login guessing succeedsStrong passwords plus two-factor login
Too many admin accountsOne stolen login gives full controlGive each person the lowest role they need
Nulled or pirated pluginsHidden malware ships inside the downloadOnly install from trusted sources
No tested backupRecovery takes days instead of minutesAutomatic off-site backups, restore-tested

Two details from the Patchstack data deserve emphasis. First, it reports a weighted median of about five hours between disclosure and first mass exploitation of heavily targeted flaws, with roughly half of high-impact ones exploited within 24 hours. Second, premium plugins are not automatically safer: the same report found premium components had three times more known exploited vulnerabilities than free ones. Paying for a plugin does not remove the need to update it.

What is the WordPress security checklist?

Work through these in order. The first five give the biggest reduction in risk for the least effort. Where the official WordPress hardening guide covers a step, I’ve followed its recommendations.

1. Update everything, and do it on a schedule

WordPress core, themes and plugins all need regular updates. Given how quickly critical flaws get exploited, enable automatic updates for security releases and check the rest weekly. On a business site, test updates on a staging copy first, with a backup taken before each batch, so an update never takes your shop offline.

2. Remove what you don’t use

Deactivated plugins still sit on your server, and their code can still be reached. Delete unused plugins and themes entirely. Replace anything that hasn’t been updated in a long time with a maintained alternative. Every plugin you remove is one fewer door to defend.

3. Lock down logins

  • Use long, unique passwords stored in a password manager.
  • Turn on two-step authentication for every administrator and editor.
  • Avoid obvious usernames such as admin, as the official guide advises.
  • Limit login attempts and block repeated failures.

4. Use the lowest role that does the job

Writers don’t need Administrator access, and contractors shouldn’t keep their accounts after the work ends. Review your user list quarterly and remove anyone who no longer needs access. A stolen low-privilege login does far less damage than a stolen admin one.

5. Take backups you have actually restored

A backup you have never restored is a hope, not a backup. Store copies off the server, keep several versions, and do a test restore at least once. This is the single step that turns a catastrophe into an inconvenience.

6. Harden the configuration

These come straight from the WordPress hardening guide:

  • Add define( 'DISALLOW_FILE_EDIT', true ); to wp-config.php so the dashboard code editor cannot be abused.
  • Keep file permissions tight: directories at 755 and files at 644, with wp-config.php restricted further.
  • Give the database user only the privileges WordPress needs, not the ability to drop or alter tables.
  • Transfer files over SFTP, never plain FTP.

Treat this configuration step as a one-time job at build time. A developer who sets it up once, documents it and checks it after major updates saves you from the kind of silent drift where a permission or setting quietly loosens over time.

7. Add monitoring and a firewall layer

Uptime monitoring and file-change alerts tell you about a problem in minutes instead of weeks. Add a web application firewall as a second layer, remembering it supplements patching rather than replacing it.

Doing security yourself

  • The basics cost almost nothing: updates, 2FA, fewer plugins, backups
  • You learn how your own site is put together
  • Fine for a small brochure site with few plugins

When it stops being practical

  • Critical flaws can be exploited within hours, so weekly checks leave gaps
  • Testing updates safely needs a staging setup and time
  • Recovering from a compromise is slow if you have never done it
  • Stores, memberships and client data raise the stakes

How do you choose plugins that won’t become a liability?

Because plugins are the main attack surface, the choice of what you install matters as much as how you maintain it. Before adding one, check it against this short list:

  • Recently updated. If the last update was a long time ago, the developer may have walked away.
  • Actively used. Very small install counts mean fewer eyes finding and reporting flaws.
  • Compatible with your WordPress and PHP versions. Mismatches cause both bugs and security gaps.
  • From a trusted source. Install from the official directory or the vendor directly. Never use pirated or “nulled” copies of premium plugins, which commonly ship with hidden malware.
  • Really needed. If a feature takes ten lines of custom code, a plugin is a permanent dependency you don’t need.

A plugin that passes today can still fail later, which is why the routine matters more than the one-time choice. Review your plugin list every quarter, and replace anything that has stopped receiving updates.

What should you do if your site is already hacked?

A hacked site is stressful, but the response is mechanical. The mistake people make is rushing to remove the visible damage first, which destroys evidence and leaves the way in open.

Act in this order: take the site offline or enable maintenance mode, back up the infected state for analysis, change every password and key, restore from a clean backup if you have one, then update everything before going live again. Cleaning only the visible symptom usually leaves a backdoor behind, so the site is reinfected within days.

I cover the full range of failures, including the non-security ones, in what actually breaks WordPress sites. If you need hands-on help, my WordPress troubleshooting service handles malware cleanup and recovery, and security hardening closes the gaps afterwards so it doesn’t repeat.

How do you keep a WordPress site secure long term?

Turn the checklist into a routine: automatic security updates, a weekly review of the rest, monthly backup tests and a quarterly review of users and plugins. The hosting you run on matters too, since a managed environment handles server-level patching for you; see my managed WordPress hosting option. If you are choosing a developer to look after the site, my guide on how to hire a WordPress developer lists the security questions to ask them.

Want your WordPress site hardened and monitored?

I audit, harden and maintain WordPress sites: updates tested on staging, tested backups, login protection and monitoring, all documented.

Get your site secured

Frequently Asked Questions

Through vulnerable or abandoned plugins. Patchstack’s 2026 report found 91% of new WordPress vulnerabilities in 2025 were in plugins, against 9% in themes and 6 in WordPress core. Weak passwords and missing updates are the next most common causes.

WordPress core is well maintained and rarely the problem. Security depends on how the site is run: which plugins are installed, how quickly updates are applied, how logins are protected and whether backups exist. A well-maintained WordPress site is secure, a neglected one is not.

A security plugin can add useful layers such as login protection and firewall rules, but it does not replace updates, backups and fewer plugins. Patchstack found hosting-level defences blocked only 26% of vulnerability attacks, so patching remains your main protection.

Enable automatic updates for security releases and review the rest at least weekly. For heavily targeted flaws, mass exploitation can begin within about five hours of disclosure, so critical updates should not wait. Test on staging first for business-critical sites.

Warning signs include unknown admin users, redirects to other sites, search results showing spam, unexpected files, sudden slowdowns and host or browser warnings. File-change monitoring and uptime alerts catch many compromises within minutes rather than weeks.

Good security is mostly unglamorous maintenance done consistently. If you’d like a second pair of eyes on your site’s setup, or want someone to take the routine off your plate, book a free consultation and we’ll go through it together.

Yasir ShabbirWritten by

Yasir Shabbir

Full-Stack AI Developer & Automation Specialist

I'm Yasir Shabbir, a full-stack AI developer and automation specialist with 7+ years of experience and 500+ delivered client projects across 27 countries. I write about site speed, costs and what breaks WordPress.

Share this Article
LinkedInWhatsApp

How was this content?

Comments

No comments yet — be the first to share your thoughts.

Leave a Comment

Your email address won’t be published.

Free Consultation

Let's Discuss Your Project

Book a free 30-minute call to discuss your project requirements, get expert advice, and receive a custom quote tailored to your needs.

30-minute free consultationDiscuss your project requirementsGet a custom strategy & quoteNo obligation to proceed