How to Secure WordPress


WordPress is so widespread that more and more developers are creating ready-made themes and plugins for it. While most of these make your site easier to use and expand its functionality, some can harbor viruses or open the door to hackers. This article will help you minimize the risk of your site being hacked and teach you how to be prepared for any situation.

 

Rule 1: The web server, not WordPress, should be running.
Currently, I prefer to configure Nginx + PHP-FPM for WordPress, without a hosting control panel. Therefore, this article will provide the code for configuring Nginx; you can find similar code for Apache and LiteSpeed ​​online. If you have managed WordPress hosting and don't have access to your web server settings, please contact your hosting provider's technical support.

What do I mean by the statement: the web server should be running, not the WordPress engine? All user requests that the web server can handle should be handled by it, not WordPress. Every request to your site puts a load on it. The greater the load, the worse your site performs. In general, my recommendation will help relieve the load on caching and security plugins, meaning not only speeding up your site but also making it more secure. So, the web server should be optimized for WordPress, not the other way around. WordPress is a powerful platform, but it can be resource-intensive. If your web server isn't optimized for WordPress, it can lead to performance and availability issues.

Let's look at my recommendation using a simple example to understand how your WordPress or other CMS site can become more secure and faster. The readme.html and license.txt files are located in the root folder of any WordPress installation. These are simply text files that don't affect WordPress in any way, and it's recommended to delete them immediately after installation. You don't need these files, but they help hackers determine your current WordPress version and much more, which can be useful for hacking your website.

As we can see, the recommendation is correct and seemingly simple to implement. However, the same .txt files are also found in plugin directories, so they need to be deleted there as well. They will reappear after a plugin update. Furthermore, the load of hacker requests on your site can significantly slow it down. This problem can be elegantly solved in any web server, for example in Nginx, the code prohibits access to files with the extensions log, txt, sql in any directory of your site.

location ~ \.(log|txt|sql)$ { deny all; access_log off; log_not_found off;}

We've secured your site with this line of code. The next line of code will also speed up your site by disabling access to the xmlrpc.php file, which is used for remote access to your site:

location = /xmlrpc.php { deny all; access_log off; log_not_found off;}

Rule 2: Enable automatic updates for your engine, plugins, and themes
Vulnerabilities in previous versions of software are publicly available, so the latest version is the most secure for any software.
If you don't want to update WordPress because you've made changes to files, it's best to create a child theme, migrate your changes to it, and then enable updates anyway.

Starting with version 5.5, WordPress has a built-in automatic update feature for themes and plugins.

To enable automatic theme updates: Go to "Appearance" -> "Themes," hover over the desired theme, and click "Theme Info" -> Enable automatic updates.
To enable automatic plugin updates: Go to the "Plugins" section and enable automatic updates next to the desired plugin.
If you have software on your site that is incompatible with new versions of WordPress, a plugin, or a theme, you can enable selective automatic updates.

Rule 3: Don't use nulled templates for WordPress
Nulled products are pirated copies of paid themes and plugins distributed illegally online.

In short, you'll end up paying the developer more to clean your site of malicious code than you'll save by installing a nulled template or plugin.

Rule 4: Back up your data as often as possible
Even the largest websites get hacked every day, despite their owners spending thousands of dollars improving their security.

Not all attacks can be prevented, but just one successful attack can destroy all the work you've put into building your website. We recommend making regular website backups.

Attention
Many hosting companies offer server backups for FREE, and that seems like a good idea! However, I currently don't know of a single hosting provider whose backup service works correctly, especially for FREE! Perhaps I'm being overly demanding, but if you've had any experience restoring a website from your provider's backups, let me know in the comments. TIP: Don't trust the marketing hype of your chosen hosting provider; instead, test your website recovery yourself!

There are several ways to create backups. You can manually download your website files and export the database, or, as I mentioned above, use the tools offered by your hosting plan (I used the word "plan" for a reason—hello, marketers). Another option is to use WordPress plugins, for example:

BulletProof Security is a very interesting plugin for both website protection and backups.
WordPress Database Backup—the plugin settings allow you to set up a daily database backup sent to your contact email.
There are a large number of dedicated security plugins developed for WordPress.

WordPress Website Security Recommendations
Delete all unnecessary plugins, themes, and files
Feel free to delete all unused plugins, themes, and files. Hackers often use disabled and outdated templates and plugins (even official WordPress plugins) to gain access to your dashboard or upload malicious content to your server. By deleting plugins and templates you no longer use, you reduce the risks and make your WordPress site more secure.

For example, you installed plugins to test and choose the one you want to use. After choosing, be sure to delete all unnecessary ones.

Delete unused plugins.
Delete unused themes. You should have a maximum of three themes: the first one you use on your site, its child theme, and the Twenty-One theme (the latest official WordPress theme as of 2021). You should leave Twenty-One installed so that if your main theme crashes (white screens often appear due to PHP errors, especially if you have a custom theme or plugins), you can switch to Twenty-One and fix the problem.
How to Hide WordPress Versions, Scripts, and Styles
By default, WordPress adds the current version number to the source code of its files and pages.

<meta name="generator" content="WordPress 5.7.1" />
<meta name="generator" content="WooCommerce 5.2.2" />

It's quite common to fail to keep your WordPress version up to date, which can become a weakness in your website. Knowing your WordPress version can be a huge source of damage for a hacker. To prevent WordPress version information from being displayed, add the following line to your functions.php file:

remove_action('wp_head', 'wp_generator');

I use the Clearfy Pro plugin, which has settings for:

Removes the meta tag from the head section. This allows attackers to find out the WordPress version installed on the site. This meta tag doesn't provide any useful functionality.
Removes style versions. WordPress, themes, and plugins often include styles that specify the file, plugin, or engine version, which looks like this: ?ver=4.7.5. This allows attackers to find out the plugin or engine version. Also, not all proxy servers and CDN services can cache files with the "ver" parameter at the end of the URL, which increases page load time on your site.
Removes script versions. As with styles, scripts are included with the file, plugin, or engine version specified, which looks like this: ?ver=4.7.5.
How to enable two-step authentication in WordPress
Two-step authentication is an account security method based on two factors: login information known only to you (password) and your physical device (mobile device or key).

After you enter your password on the site, you are sent a request for a new one-time password, which you receive via your phone number or email (or by clicking a link in the email). Therefore, even if your primary password is compromised, a hacker will not be able to access your account without access to your phone or email.

Popular two-factor verification plugins for WordPress:

Keyy Two-Factor Authentication allows you to log in by scanning a QR code instead of remembering your password.

Google Authenticator provides two-factor authentication using the Google Authenticator app for Android, iPhone, and Blackberry.

Use non-default login credentials
Avoid using a username like admin. It is strongly recommended to change the administrator username to something else.

The easiest way to set a username is when installing WordPress. However, if you already have it installed, create a new administrator account with different credentials.

Log in to your WordPress dashboard
Find the Users section and click the Add New button.
Create a new user and assign them Administrator privileges.
Log back into WordPress with your new credentials.
Return to the Users section and delete the default Admin account.
Tip
A good password is key to WordPress security. A password consisting of numbers, lowercase and uppercase letters, and special characters is much harder to crack.
I recommend using specialized tools for creating and securely storing passwords, such as the free KeePass Password Safe.

Additionally, you can disable the error message about the entered username and password in the functions.php file, located in your website's current theme folder (wp-content/themes/current_theme_WordPress). However, I removed the code because it varies for different WordPress versions. To disable the error message, use the Clearfy Pro plugin or the WP Cerber Security plugin.

Disable WP JSON and other features
WP JSON is short for WordPress JSON REST API. WP JSON is used to write applications on various platforms and in various languages ​​that can manage your site: add, edit, and delete content, customize themes, menus, widgets, and more. As you might have guessed, it allows you to do unsafe things!

Search engines often index /wp-json/ as a subsection of a website. From an SEO perspective, the index should only include pages that drive traffic, not technical (junk) /wp-json/ pages.

When disabling the WordPress REST API, keep in mind that some popular plugins use it, such as Contact Form 7. Therefore, if your contact form suddenly stops working, check to see if the REST API is disabled.

There are at least two reasons to disable wp-json: security and SEO. I use the Clearfy Pro plugin to disable wp-json.

Using .htaccess in Apache to improve WordPress security
Properly and securely setting up .htaccess is a very broad topic and requires specific professional expertise. I strongly advise against copying .htaccess settings from unknown websites, especially forums, and using them without understanding them.

.htaccess is a file required for WordPress links to function correctly when using the Apache or LiteSpeed ​​web server (Nginx does not use the .htaccess file). Without the correct entries in the .htaccess file, you will receive many 404 errors.

All .htaccess settings are correct immediately after installing WordPress! You may only need to configure redirects from www and http to https. The classic way to configure these redirects is by editing the .htaccess file, but before doing so, consult your hosting provider's documentation; hosting providers often offer their own solutions for setting up redirects.
Use the code below to repair a damaged .htaccess file (for example, caused by a malfunctioning plugin). The code is copied from the official Wordpess documentation.

# BEGIN WordPress

RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]

# END WordPress

List of WordPress Security Plugins
Hackers often exploit vulnerabilities in WordPress templates or plugins. Therefore, it's important to scan your blog frequently. There are many well-written plugins for this purpose, for example: WP Cerber Security – very good and easy to use, with clear settings. I use it. By the way, you won't find it among the official WordPress plugins because it's considered unreliable. :)

I caution against using security plugins thoughtlessly! Be sure to test them on your website. They can ruin your website's layout (and I'm not confusing this with caching plugins) or block visitor access.
List of other security plugins for WordPress:

Wordfence Security – antivirus, firewall, and malware scanner. Wordfence offers a user guide and automatic scanning options, along with a bunch of other settings.
Sucuri Security – a plugin that protects against DDOS attacks, contains a blacklist, scans your website for malware, and manages your firewall. Google, Norton, and McAfee—this plugin includes all blacklists from these programs. If a problem is detected, you will be notified via email.
BulletProof Security (DIFFICULT to understand and configure)—malware scanner, firewall, login form protection, database backups, and anti-spam. Database comparison feature. Database backups: full and partial database backups, manual backups, scheduled backups, emailing archived backups, and scheduled automatic deletion of outdated backups.
All-In-One Security (AIOS) – Security and Firewall
Defender Security – Malware Scanner, Login Security & Firewall
There are many specialized security plugins developed for WordPress.

Changing Default WordPress Database Prefixes to Prevent SQL Injection
SQL injection is a common method of hacking websites and database-based programs, based on injecting arbitrary SQL code into queries. Depending on the type of DBMS used and the conditions under which it is injected, SQL injection can allow an attacker to execute arbitrary database queries (for example, read the contents of any tables, delete, modify, or add data), read and/or write local files, and execute arbitrary commands on the target server.

Key Point: A SQL injection attack can be possible due to improper handling of input data used in SQL queries. Simply put, a plugin or theme incorrectly (insecurely) handles data entered by visitors to your site.
I am skeptical of advice about changing the WordPress database prefix on a live site. If you are a beginner webmaster, change the prefix only during the initial WordPress installation.

If you're a seasoned experimenter, find a guide to changing the prefix on another website. Good luck!


Go back
18-09-2025, 04:53