Your Comprehensive Step-by-Step Guide to WordPress Security – Part 1

Table of Contents

Reading Time: 4 minutes

Secure Your WordPress Site: Protection Strategies and Recovery Steps

Ensuring the security of your WordPress website should be a top priority for every site owner. That’s why we’ve decided to create a series of blogs to help you and your business stay secure.

With over 40% of all websites powered by WordPress, it stands out as the most widely used content management system (CMS).

This popularity also attracts a significant amount of unwanted attention. Every day, Google blacklists more than 10,000 websites for malware and around 50,000 for phishing each week.

In our detailed guide to WordPress security, we’ll provide you with essential strategies to safeguard your site, including:

  • Password settings and brute force attacks
  • Admin access and user permissions
  • Version control and updating plugins
  • Choosing the right secure plugin
  • Malware scanning
  • Secure web hosting
  • Distributed denial of service attacks (DDoS)

 

We’ll guide you through a series of straightforward preventive measures step-by-step. We’ll also show you how to recover a hacked WordPress site and outline the actions to take in the event of a worst-case scenario.

Weble Design & Hosting

Of course if you have one of our hosting packages, alongside our Maintenance & Support Services, then much of what we are about to cover in the detailed guide is automatically done for you, freeing up your businesses precious time and resources. And, giving you peace of mind that your site is as secure as it can be.

1. Securing Your WordPress Admin Login

The Admin login of any WordPress site is often the first target for hackers, as it’s easily accessible. Simply enter your domain followed by either /wp-admin or /wp-login.php, and you’re there.

Cybercriminals are also aware that the default username for WordPress is “admin,” allowing them to launch brute force attacks on your site in no time.

So, what steps can you take to enhance the security of your WordPress login page?

How to Change the wp-admin URL in WordPress

Changing your wp-admin URL is a simple yet effective way to enhance security, making it harder for unauthorized users to access your site.

While hackers are familiar with the default route to a WordPress login page at domain.com/wp-admin, they won’t easily guess your unique URL, such as yoursite.com/ilovemyfavouritefood or yoursite.com/onlyiwillknowthis.

This customization is easily achieved with a plugin called WPS Hide Login. It’s free, user-friendly, and instead of altering existing files, it intercepts page requests and redirects them to a URL of your choosing once the plugin is installed.

Be sure to document your new URL in case you forget it later, especially if you opt for something creative!

However, keep in mind that this measure may only deter less experienced hackers. Additional steps will be necessary to fully secure your site.

Changing the WordPress Admin URL can bypass many of the hosting provider’s rules concerning /wp-admin and /wp-login.php, including their built-in brute force protection. While this can be a helpful measure, it should be implemented in conjunction with other security techniques discussed in these series of posts, rather than as a standalone solution.

Change Your Admin Username / Create a New Administrator Profile

Since every hacker is aware that the default username for the primary WordPress user is “admin,” one of the first steps you should take is to change it.

This process is straightforward. From the main dashboard, you can create a new user with a unique username. Once that’s done, you can delete the original “admin” user.

Consider using a unique email address associated with the new profile as your username, as this adds an extra layer of security against brute force attacks.

If the original profile was assigned the administrator role (which is typically the case for the first user), be sure to reassign this role to your newly created user.

When deleting the old profile, select the option to “attribute all content to” the new administrator to ensure that any historical site content is preserved.

Strong Password Generators

Selecting a strong password is a crucial step in safeguarding your WordPress site from potential cyber threats.

Given the multitude of passwords we need for various websites, it’s tempting to avoid complex combinations of uppercase letters, lowercase letters, numbers, and symbols, as they can be difficult to remember.

However, passwords that are easy to remember are often easy to guess.

To solve this, we recommend using an online tool that generates random passwords for you. These tools handle the complexity, creating secure passwords tailored to your specifications.

Additionally, consider using a password manager like Bitwarden, which is totally free . This tool securely stores all your passwords, so you don’t have to memorise them.

Two-Factor Authentication

Two-factor authentication (2FA) is becoming increasingly common across a range of websites, with mainstream sites like Google, Facebook, and Twitter now implementing it. As the name suggests, this involves a two-step process.

First, a user provides their usual login details for a website. Second, they are prompted to enter a passcode, which is sent via another method—usually by text, a phone app, or email.

2FA has proven to be a highly effective layer of security, as it is nearly impossible for criminals to access both components required for this process. Therefore, it is definitely something you should consider implementing for your WordPress site.

Limit Login Attempts

There are various plugins and online tools available that can limit the number of incorrect login attempts made on your site.

Weble Design & Hosting

If you use our hosting services with our Maintenance & Support Services instead of using a plugin, we employ an automated security tool. This monitors all requests to common login pages and blocks any attempts that match known malicious activity. This powerful software has the capability to block millions of attempts each day.

Automatically Log Out Idle Users

It’s all too easy for a user to become distracted when working on a website, such as leaving a page open while stepping away from their desk.

This could provide an opportunistic hacker with the equivalent of an open goal to make unauthorised changes, posing an unexpected security risk.

You’ll notice that nearly all financial websites automatically suspend any session after a few minutes of inactivity.

For a WordPress site, there are several security plugins—specifically Inactive Logout and BulletProof Security—that offer similar functionality.

Both plugins are free and provide a range of options, allowing you to set a specific timescale for logging users out of a session, along with customisable message settings.

Security Questions on Login

For added peace of mind, you can also incorporate one or more security questions during the wp-admin login process by installing the WP Security Questions plugin.

Once installed, simply visit your settings page and activate the plugin to configure the specific security questions you wish to set for users.

Check out our latest news & blogs

Let's Talk

We’d love to hear from you, so just pop a few details in our form below, hit send, and we’ll get back in touch.