WordPress Security Checklist: What Gets Sites Hacked and How to Harden Yours
Note: I may earn a commission from links on my site. This doesn't influence my reviews or project evaluations.

The short answer: most hacked WordPress sites are not broken into through WordPress itself. They are compromised through plugins, weak logins and missing updates. According to Patchstack’s State of WordPress Security in 2026, 91% of the 11,334 new vulnerabilities found in 2025 were in plugins, only 6 were in WordPress core, and 46% had no patch available when they were publicly disclosed.
I fix compromised and unstable sites for a living, and the same handful of weaknesses show up again and again. This article explains what actually gets sites hacked, then gives you a hardening checklist you can work through in an afternoon, with the official WordPress guidance behind each step.
What actually gets WordPress sites hacked?
Almost always one of the causes in the table below. They are boring, which is exactly why they work: attackers scan the internet automatically for known weaknesses instead of targeting individual sites.
| Cause | How it happens | Fix |
|---|---|---|
| Vulnerable plugin or theme | A known flaw is exploited soon after disclosure | Update fast, remove what you don’t use |
| Abandoned plugin | No developer left to patch known flaws | Replace it with a maintained alternative |
| Weak or reused password | Automated login guessing succeeds | Strong passwords plus two-factor login |
| Too many admin accounts | One stolen login gives full control | Give each person the lowest role they need |
| Nulled or pirated plugins | Hidden malware ships inside the download | Only install from trusted sources |
| No tested backup | Recovery takes days instead of minutes | Automatic off-site backups, restore-tested |
Two details from the Patchstack data deserve emphasis. First, it reports a weighted median of about five hours between disclosure and first mass exploitation of heavily targeted flaws, with roughly half of high-impact ones exploited within 24 hours. Second, premium plugins are not automatically safer: the same report found premium components had three times more known exploited vulnerabilities than free ones. Paying for a plugin does not remove the need to update it.
What is the WordPress security checklist?
Work through these in order. The first five give the biggest reduction in risk for the least effort. Where the official WordPress hardening guide covers a step, I’ve followed its recommendations.
1. Update everything, and do it on a schedule
WordPress core, themes and plugins all need regular updates. Given how quickly critical flaws get exploited, enable automatic updates for security releases and check the rest weekly. On a business site, test updates on a staging copy first, with a backup taken before each batch, so an update never takes your shop offline.
2. Remove what you don’t use
Deactivated plugins still sit on your server, and their code can still be reached. Delete unused plugins and themes entirely. Replace anything that hasn’t been updated in a long time with a maintained alternative. Every plugin you remove is one fewer door to defend.
3. Lock down logins
- Use long, unique passwords stored in a password manager.
- Turn on two-step authentication for every administrator and editor.
- Avoid obvious usernames such as
admin, as the official guide advises. - Limit login attempts and block repeated failures.
4. Use the lowest role that does the job
Writers don’t need Administrator access, and contractors shouldn’t keep their accounts after the work ends. Review your user list quarterly and remove anyone who no longer needs access. A stolen low-privilege login does far less damage than a stolen admin one.
5. Take backups you have actually restored
A backup you have never restored is a hope, not a backup. Store copies off the server, keep several versions, and do a test restore at least once. This is the single step that turns a catastrophe into an inconvenience.
6. Harden the configuration
These come straight from the WordPress hardening guide:
- Add
define( 'DISALLOW_FILE_EDIT', true );towp-config.phpso the dashboard code editor cannot be abused. - Keep file permissions tight: directories at 755 and files at 644, with
wp-config.phprestricted further. - Give the database user only the privileges WordPress needs, not the ability to drop or alter tables.
- Transfer files over SFTP, never plain FTP.
Treat this configuration step as a one-time job at build time. A developer who sets it up once, documents it and checks it after major updates saves you from the kind of silent drift where a permission or setting quietly loosens over time.
7. Add monitoring and a firewall layer
Uptime monitoring and file-change alerts tell you about a problem in minutes instead of weeks. Add a web application firewall as a second layer, remembering it supplements patching rather than replacing it.
Doing security yourself
- The basics cost almost nothing: updates, 2FA, fewer plugins, backups
- You learn how your own site is put together
- Fine for a small brochure site with few plugins
When it stops being practical
- Critical flaws can be exploited within hours, so weekly checks leave gaps
- Testing updates safely needs a staging setup and time
- Recovering from a compromise is slow if you have never done it
- Stores, memberships and client data raise the stakes
How do you choose plugins that won’t become a liability?
Because plugins are the main attack surface, the choice of what you install matters as much as how you maintain it. Before adding one, check it against this short list:
- Recently updated. If the last update was a long time ago, the developer may have walked away.
- Actively used. Very small install counts mean fewer eyes finding and reporting flaws.
- Compatible with your WordPress and PHP versions. Mismatches cause both bugs and security gaps.
- From a trusted source. Install from the official directory or the vendor directly. Never use pirated or “nulled” copies of premium plugins, which commonly ship with hidden malware.
- Really needed. If a feature takes ten lines of custom code, a plugin is a permanent dependency you don’t need.
A plugin that passes today can still fail later, which is why the routine matters more than the one-time choice. Review your plugin list every quarter, and replace anything that has stopped receiving updates.
What should you do if your site is already hacked?
A hacked site is stressful, but the response is mechanical. The mistake people make is rushing to remove the visible damage first, which destroys evidence and leaves the way in open.
Act in this order: take the site offline or enable maintenance mode, back up the infected state for analysis, change every password and key, restore from a clean backup if you have one, then update everything before going live again. Cleaning only the visible symptom usually leaves a backdoor behind, so the site is reinfected within days.
I cover the full range of failures, including the non-security ones, in what actually breaks WordPress sites. If you need hands-on help, my WordPress troubleshooting service handles malware cleanup and recovery, and security hardening closes the gaps afterwards so it doesn’t repeat.
How do you keep a WordPress site secure long term?
Turn the checklist into a routine: automatic security updates, a weekly review of the rest, monthly backup tests and a quarterly review of users and plugins. The hosting you run on matters too, since a managed environment handles server-level patching for you; see my managed WordPress hosting option. If you are choosing a developer to look after the site, my guide on how to hire a WordPress developer lists the security questions to ask them.
Want your WordPress site hardened and monitored?
I audit, harden and maintain WordPress sites: updates tested on staging, tested backups, login protection and monitoring, all documented.
Frequently Asked Questions
Through vulnerable or abandoned plugins. Patchstack’s 2026 report found 91% of new WordPress vulnerabilities in 2025 were in plugins, against 9% in themes and 6 in WordPress core. Weak passwords and missing updates are the next most common causes.
WordPress core is well maintained and rarely the problem. Security depends on how the site is run: which plugins are installed, how quickly updates are applied, how logins are protected and whether backups exist. A well-maintained WordPress site is secure, a neglected one is not.
A security plugin can add useful layers such as login protection and firewall rules, but it does not replace updates, backups and fewer plugins. Patchstack found hosting-level defences blocked only 26% of vulnerability attacks, so patching remains your main protection.
Enable automatic updates for security releases and review the rest at least weekly. For heavily targeted flaws, mass exploitation can begin within about five hours of disclosure, so critical updates should not wait. Test on staging first for business-critical sites.
Warning signs include unknown admin users, redirects to other sites, search results showing spam, unexpected files, sudden slowdowns and host or browser warnings. File-change monitoring and uptime alerts catch many compromises within minutes rather than weeks.
Good security is mostly unglamorous maintenance done consistently. If you’d like a second pair of eyes on your site’s setup, or want someone to take the routine off your plate, book a free consultation and we’ll go through it together.


Comments
No comments yet — be the first to share your thoughts.