Our servers run a firewall (ConfigServer Security & Firewall) that blocks thousands of attacks a day, but your WordPress security also depends on you. These steps protect the most.
1. Keep everything updated
Most hacked sites run outdated plugins or themes.
- Under Dashboard → Updates, update WordPress, plugins and themes at least once a week.
- Turn on automatic updates for plugins you trust.
- Delete plugins and themes you do not use (even deactivated ones can have flaws).
2. Users and passwords
- Do not use the
adminusername. Create an administrator with another name and delete the old one. - Use long, unique passwords; a password manager helps.
- Turn on two-step verification with a plugin such as Wordfence Login Security or Two Factor.
- Give each person only the role they need (Editor, Author…), not Administrator.
3. Limit login attempts
Install a security plugin such as Wordfence, Solid Security or Limit Login Attempts Reloaded to block whoever tries passwords over and over.
4. Protect the files
- Download plugins and themes only from wordpress.org or their author. "Free premium" themes often carry malicious code.
- Add
define('DISALLOW_FILE_EDIT', true);towp-config.phpto turn off the dashboard file editor. - Do not leave copies like
backup.ziporwp-config.php.bakinsidepublic_html.
5. Always have a backup
If something goes wrong, a recent copy brings your site back in minutes. See the backups guide in this section.
Think you were hacked?
Signs: redirects to other sites, users you did not create or Google warnings. Change every password (WordPress, cPanel and FTP), restore a clean copy and open a ticket: we review your account and help you clean it.