Skip to content
Maintenance & Security 8 min read Sajid Aslam

WordPress Security: A Practical Guide for Business Sites

Most WordPress hacks are automated and boringly preventable. Here is what actually stops them, in order of value.

Layers of WordPress security from hosting to user accounts

Short answer

Most WordPress sites are compromised through outdated plugins or themes, or through weak and reused passwords. The measures that matter most are keeping everything updated, removing unused plugins, two-factor authentication on every admin account, few admin users, decent hosting, a firewall, and off-site backups you have tested. Obscurity tricks add little.

WordPress security for a business site is mostly about doing a handful of unglamorous things consistently. The overwhelming majority of compromises are automated: bots scan the internet for sites running a plugin version with a known hole, or try leaked passwords against login pages. Neither is personal, and both are preventable.

This guide covers how WordPress sites actually get compromised, the security measures worth your time in order of value, and the popular ones that add very little.

How do WordPress sites actually get hacked?

Understanding the routes in tells you where to spend effort.

RouteHow it worksWhat stops it
Vulnerable plugin or themeA flaw is published; bots scan for sites still running the old versionPrompt updates; fewer plugins
Abandoned pluginThe flaw is found but never fixed because the developer has moved onRemoving and replacing abandoned plugins
Stolen or weak passwordsPasswords leaked elsewhere are tried against your loginUnique passwords plus two-factor authentication
Nulled (pirated) themes or pluginsDownloaded "free" copies of paid software with a backdoor includedOnly installing from the official directory or the vendor
Compromised hosting or FTPOld FTP credentials, shared server neighbours, weak hosting controlsSFTP, good hosting, rotated credentials
Former staff or suppliersAccounts nobody removedRegular user reviews

WordPress core itself is rarely the weak point. It has a dedicated security team and, by default, installs minor security releases automatically. The risk sits in the plugins, themes and people around it.

The measures that matter, in order

If you only do the first five, you have covered most of the realistic risk.

1. Keep everything updated

Plugins, themes, WordPress core and the PHP version on the server. Security fixes are only useful once they are installed, and the window between a vulnerability being published and bots scanning for it can be short.

The trade-off is that updates can break things, so the process matters: staging first, backup before going live, then a check. How to update WordPress safely covers the routine. Security releases deserve to go on quickly rather than waiting for the monthly pass.

2. Remove what you do not use

Every installed plugin is code that can be exploited, even when it is deactivated — the files are still on the server. If a plugin is not doing a job today, delete it. The same goes for unused themes: keep the active theme and one default theme as a fallback, and remove the rest.

Also look for plugins that are installed and active but have not been updated by their developer in more than a year. Those need replacing, not just updating.

3. Two-factor authentication on every admin account

Passwords leak. Two-factor authentication (an authenticator app code on top of the password) means a leaked password alone is not enough. It is free, takes a couple of minutes per user to set up, and closes off the credential-stuffing route almost entirely.

Pair it with a password manager so every account has a long, unique password.

4. Fewer people with admin rights

WordPress has roles for a reason. Someone who writes blog posts needs Editor or Author, not Administrator. Review users quarterly, remove former staff and suppliers, and check that nobody has quietly been promoted.

RoleCan doGive it to
AdministratorEverything, including installing plugins and adding usersThe owner, and whoever maintains the site
EditorPublish and edit anyone's contentSomeone who manages content
AuthorPublish their own postsRegular contributors
ContributorWrite but not publishOccasional guest writers
Shop manager (WooCommerce)Manage orders and productsStaff running the shop

5. Off-site backups you have tested

Backups do not prevent a hack, but they decide how bad it gets. A clean backup from before the compromise turns a disaster into an afternoon. What a proper backup strategy looks like explains how often, where, and for how long.

6. Decent hosting

Good hosting isolates your site from other customers on the same server, keeps PHP current, runs a server-level firewall and malware scanning, and offers SFTP or SSH rather than plain FTP. Cheap shared hosting is not automatically insecure, but the variation between hosts is large. Choosing web hosting for a UK small business covers what to ask.

7. A web application firewall

A firewall filters malicious requests before they reach WordPress — blocking known exploit patterns and limiting repeated login attempts. It can run at the host, at a DNS-level service such as Cloudflare or Sucuri, or as a WordPress plugin such as Wordfence. One layer, configured properly, is the goal.

8. Monitoring for changes you did not make

File integrity monitoring compares your core files against the official versions and flags anything altered. Combined with alerts for new admin users, it catches a compromise early, before Google or a customer does.

Hardening settings worth applying

These are small configuration changes, usually done once:

  • Disable the built-in file editor (the DISALLOW_FILE_EDIT setting in wp-config.php), so a compromised admin account cannot edit theme and plugin code from the dashboard.
  • Force HTTPS across the whole site, including the admin area.
  • Set correct file permissions, so the web server cannot write to files it has no reason to change.
  • Block PHP execution in the uploads folder, where it has no legitimate reason to run.
  • Disable XML-RPC if nothing on the site uses it (some apps and Jetpack features do; check first).
  • Limit login attempts, at the firewall or with a plugin.

What is mostly security theatre

These get recommended often and do little against how sites are actually compromised.

MeasureWhy it adds little
Changing the database table prefixExploits that reach the database usually discover the prefix anyway
Hiding the WordPress version numberBots test for vulnerable plugins directly rather than reading the version
Moving the login URLCuts log noise; does nothing about vulnerable plugins
Renaming the admin usernameTwo-factor authentication solves the same problem properly
Installing three security pluginsThey conflict, slow the site and duplicate each other

None of these are harmful in themselves. The problem is when they take the place of updates, two-factor authentication and backups.

Where plugin quality fits

A large share of WordPress security is decided when plugins are chosen. Before installing anything, check:

  1. When it was last updated, and whether it supports your WordPress version
  2. Active installs and the developer's track record
  3. Whether there are open, unpatched entries in a vulnerability database such as WPScan, Patchstack or Wordfence Intelligence
  4. Whether a single plugin is doing a job that a few lines of theme code could do

If you are commissioning custom plugins, WordPress plugin development security best practices covers what a developer should be doing in the code itself.

Security and personal data

If your site collects personal data — enquiry forms, accounts, orders — a compromise may also be a personal data breach under UK GDPR. If a breach is likely to put people's rights at risk, the ICO generally needs to be told within 72 hours of you becoming aware of it. The ICO's guidance on personal data breaches explains how to judge whether a report is needed. It is another reason to keep form submissions out of the WordPress database if you do not need them stored there.

A one-hour security pass for an existing site

If you have inherited a site, or simply never looked, this is a sensible first hour. Take a backup before you start.

  1. List the administrators. Users, filtered by Administrator. Downgrade or remove anyone who does not need it.
  2. Turn on two-factor authentication for every remaining administrator, starting with your own account.
  3. Open the plugins page. Delete anything deactivated. Note anything active that has not been updated by its developer in a year.
  4. Apply pending updates, ideally on staging first. If there is no staging, at least take a fresh backup and update one plugin at a time, checking the site between each.
  5. Check Site Health (Tools, then Site Health) for the PHP version and any critical warnings. PHP versions out of security support need upgrading via the host.
  6. Check where backups go. If they only live on the same server, set up off-site storage today.
  7. Check Search Console for any security issues or manual actions.
  8. Set up an uptime monitor and file change alerts so you hear about problems first.

That hour will not make a site invulnerable, but it closes the routes most automated attacks rely on.

Why security is a process, not a product

Security plugins and firewalls are sold as if installing one ends the matter. It does not. A firewall cannot protect a plugin that has a published flaw and no update applied; a scanner cannot help if nobody reads its alerts; a backup cannot save you if it has been failing silently for three months.

What keeps a site secure is somebody doing the routine — reading the alerts, applying the updates, reviewing the users — every month, including the months when nothing seems wrong. That is the real cost of security, and it is time rather than software.

A realistic WordPress security routine

FrequencyTask
ContinuousFirewall, malware scanning, uptime and file change alerts
As releasedSecurity updates for plugins, themes and core
MonthlyRoutine updates on staging, review login and security logs
QuarterlyUser and role review, plugin audit, restore test
AnnuallyHosting and PHP version review, password rotation for shared logins

If the worst has already happened, go straight to how to fix a hacked WordPress site. For the wider picture of keeping a site healthy, the website maintenance guide puts security alongside everything else. And if you would rather this ran without you having to think about it, security monitoring and updates are part of the website maintenance service.

Worked examples

Related services

Related reading

FAQ

Questions about this

If yours isn't here, send it over — I reply within one working day.

Yes, when it is maintained. WordPress core has a dedicated security team and ships fixes quickly. The weak points are third-party plugins and themes, weak passwords and neglected updates. A well-maintained WordPress site with a sensible plugin set is a reasonable choice for a business; an abandoned one is not.

It is useful but not essential if your host already provides a firewall, malware scanning and login protection. Check what the host does first, then add only what is missing. Running two security plugins at once often causes conflicts and slowdowns without adding protection.

It reduces noise from automated login attempts, which can make logs easier to read and reduce server load. It does not stop a determined attacker, and it does nothing about vulnerable plugins, which is how most sites are actually compromised. Treat it as a minor convenience, not a security measure.

Check when it was last updated, how many active installs it has, whether the developer responds to support threads, and whether it has unpatched entries in a vulnerability database such as WPScan, Patchstack or Wordfence Intelligence. A plugin untouched for over a year is a risk, however good it once was.