Get a free website with any plan

See how
WORDPRESS

Securing your WordPress site

Last updated

IN SHORT

Securing WordPress means covering the basics: strong unique passwords, two-factor authentication on admin accounts, keeping WordPress core, plugins, and themes updated, and using a security plugin like Wordfence. Flashcloud handles server-level firewall, DDoS protection, malware scanning, and daily backups automatically.

WordPress is widely deployed, which makes it a popular target for attackers. The good news: most attacks rely on out-of-date software or weak credentials. Cover the basics and your site is dramatically harder to compromise.

The essentials

1. Strong passwords

Long, unique, stored in a password manager. Especially for admin accounts.

If your admin password is "password123" or your name + a number, change it now.

2. Two-factor authentication

Adds a second login factor (phone code) on top of password. Even if your password leaks, attackers can't sign in.

Easy install: Two Factor Authentication plugin from WordPress.org. Or, for a more comprehensive option, Wordfence includes 2FA.

Enable 2FA for all admin and editor accounts.

3. Keep everything updated

Outdated WordPress core, plugins, and themes are the #1 attack vector. Most exploits target known vulnerabilities patched months or years ago.

  • Auto-update minor core releases (default).
  • Auto-update or weekly-update plugins (your call on auto vs manual).
  • Update themes promptly when updates are available.
  • Remove unused plugins and themes — even deactivated, they're still on disk and exploitable.

See Updating WordPress safely for the workflow.

4. Use a security plugin

A good security plugin runs many protections in one:

  • Firewall blocking known attack patterns.
  • Login security (rate-limit failed attempts, IP blocking).
  • Malware scanning.
  • Two-factor authentication.
  • Real-time threat intelligence.

Wordfence is the most popular. iThemes Security is a strong alternative. Pick one.

5. Don't use "admin" as username

Brute-force attacks try admin first. Use a different admin username.

If you currently have an admin account:

  1. Create a new admin user with a different name.
  2. Log in as the new user.
  3. Delete the old admin account, reassigning posts to your new user.

6. Disable file editing in WordPress admin

Add to wp-config.php:

define('DISALLOW_FILE_EDIT', true);
define('DISALLOW_FILE_MODS', true);

Now even if an attacker compromises an admin account, they can't edit theme/plugin code from inside WordPress to plant a backdoor.

You can still edit via FTP for legitimate updates.

Additional hardening

Force HTTPS

We do this automatically. Verify it's working: visit http://yourdomain.com and watch it redirect to https://. If not, see Forcing HTTPS.

Limit login attempts

Wordfence and most security plugins rate-limit failed logins. Configure to lock IPs after 5–10 failed attempts.

Hide WordPress version

By default, WordPress exposes its version in HTML and HTTP headers. This helps attackers target known vulnerabilities.

To hide:

// Add to functions.php
remove_action('wp_head', 'wp_generator');

Or use a security plugin that handles this automatically.

Custom login URL

/wp-admin and /wp-login.php are the first URLs attackers probe. Moving login to /secret-login or similar reduces brute-force traffic.

Use WPS Hide Login plugin for the simplest approach.

Strong file permissions

See File permissions. The defaults (755 for dirs, 644 for files, 600 for wp-config.php) are good. Don't use 777.

Audit users regularly

wp-admin → Users — check the list quarterly. Remove ex-employees, dormant accounts, suspicious-looking users.

Backup before changes

Always have a recent backup before installing/updating major plugins or making config changes. See Backing up your WordPress site.

What we handle for you

On Flashcloud hosting:

  • Server-level firewall — blocks known bad IPs at the edge.
  • DDoS protection — Cloudflare in front of your site.
  • Imunify360 rules — pattern-matching against attack signatures.
  • Imunify360 malware scanning — runs against your hosting account; we email you on detections.
  • Daily backups — restorable from the portal.
  • SSL certificates — auto-issued and auto-renewed.

You don't configure any of this; it's running.

What you handle

  • WordPress core, plugins, themes — keeping updated.
  • Strong admin passwords.
  • Two-factor on admin accounts.
  • Audit user list periodically.
  • Vetting plugins before installing (don't install random ones).

If your site is compromised

You suspect a hack — strange admin users, unfamiliar redirects, malware warnings, defaced content:

  1. Don't panic — a hack can be cleaned up.
  2. Take a snapshot — even compromised, having a backup helps forensics.
  3. Restore from a known-clean backup — if the compromise is recent, restoring to before the breach fixes it.
  4. Change all passwords — admin accounts, FTP, hosting, database.
  5. Update everything — WordPress core, all plugins, all themes.
  6. Run a malware scan — Wordfence's deep scan catches infected files most attackers leave behind.
  7. Audit — check for added admin users, modified files, scheduled cron jobs you don't recognize.

For serious cases, open a ticket with our team. We can help with cleanup, especially if you don't have a clean backup to restore from.

For more on incident response, see What to do if my website is hacked.

Power-user note

For maximum security, host WordPress in a "least privilege" pattern:

  • Database user with only the privileges WordPress needs (no DROP, no FILE, no GRANT).
  • WordPress files owned by a non-web-server user; web server has read-only access except for /wp-content/uploads/.
  • Critical config files (wp-config.php) outside the web root.

These are heavyweight changes, beyond the scope of typical hosted setups. Worth the work for high-stakes sites.

Common questions

How do I stop brute-force login attacks on my WordPress site?

Use a unique admin username instead of "admin", enable two-factor authentication, and set a security plugin like Wordfence to lock IPs after 5 to 10 failed login attempts. Moving your login page off /wp-admin with a plugin like WPS Hide Login also cuts down probing traffic.

What's the single biggest thing that gets WordPress sites hacked?

Outdated WordPress core, plugins, and themes are the number one attack vector. Most exploits target known vulnerabilities that were already patched months or years earlier, so staying current closes that door.

Do I need a security plugin if Flashcloud already protects my site?

Yes. Flashcloud runs server-level firewall, DDoS protection, Imunify360, and malware scanning automatically, but WordPress-level protections like login rate-limiting, two-factor authentication, and file editing restrictions are still on you. Wordfence or iThemes Security cover those.

What do I do if my WordPress site gets hacked?

Don't panic, take a snapshot for forensics, then restore from a known-clean backup if the compromise is recent. Change all passwords, update everything, run a malware scan, and audit for added admin users or unfamiliar files; open a ticket with Flashcloud if you need help with cleanup.

Should I delete unused plugins or just deactivate them?

Delete them. Even deactivated plugins and themes stay on disk and remain exploitable, so removing unused ones entirely closes that risk.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.