WordPress

How to protect your WordPress site from attacks

Our servers run a firewall (ConfigServer Security & Firewall) that blocks thousands of attacks a day, but your WordPress security also depends on you. These steps protect the most.

1. Keep everything updated

Most hacked sites run outdated plugins or themes.

  • Under Dashboard → Updates, update WordPress, plugins and themes at least once a week.
  • Turn on automatic updates for plugins you trust.
  • Delete plugins and themes you do not use (even deactivated ones can have flaws).

2. Users and passwords

  • Do not use the admin username. Create an administrator with another name and delete the old one.
  • Use long, unique passwords; a password manager helps.
  • Turn on two-step verification with a plugin such as Wordfence Login Security or Two Factor.
  • Give each person only the role they need (Editor, Author…), not Administrator.

3. Limit login attempts

Install a security plugin such as Wordfence, Solid Security or Limit Login Attempts Reloaded to block whoever tries passwords over and over.

4. Protect the files

  • Download plugins and themes only from wordpress.org or their author. "Free premium" themes often carry malicious code.
  • Add define('DISALLOW_FILE_EDIT', true); to wp-config.php to turn off the dashboard file editor.
  • Do not leave copies like backup.zip or wp-config.php.bak inside public_html.

5. Always have a backup

If something goes wrong, a recent copy brings your site back in minutes. See the backups guide in this section.

Think you were hacked?

Signs: redirects to other sites, users you did not create or Google warnings. Change every password (WordPress, cPanel and FTP), restore a clean copy and open a ticket: we review your account and help you clean it.