In part 2 of our Comprehensive Step-by-Step Guide to WordPress Security, we cover user permissions and how to change them, and also what can be changed on and through the Admin dashboard. Depending on your hosting provider and what access you have to your server, some of this will need to be completed by your hosting company, or by your site developer.
At Weble, we will happily handle any of these requests on your behalf if you have any of our hosting packages.
Changing User Permissions in WordPress
A crucial step towards securing your WordPress website is managing user permissions effectively.
WordPress User Roles and Responsibilities
If you’re the sole user of your site, you’ll have full administrative access, so user roles may not require much thought. However, as your user base grows, it becomes vital to consider who is granted administrative access. WordPress offers six standard user roles, each with varying levels of authority and capabilities:
- Administrator: Has full access to all settings and features. It’s best to limit this role to one user, typically the site owner.
- Editor: Responsible for overseeing site content and managing posts.
- Author: Can create and manage their own posts.
- Contributor: Can read, edit, and delete only their own posts.
- Subscriber: Can read posts but not contribute.
- Super Admin: Manages a network of sites and has the ability to delete them if necessary.
The more users with full Administrator access, the greater the risk of cyber attacks on your WordPress site.
It’s advisable to assign one user as the Administrator and then create a limited number of Editor roles for users familiar with the site’s functionality.
How to Change Permissions in WordPress
User roles aren’t set in stone; they can evolve over time. If you want to adjust user permissions, consider using the Capability Manager Enhanced plugin. This plugin allows ongoing management of user roles.
Once installed, navigate to your dashboard, select Users, then Capabilities. From there, you can choose a specific user role and modify its permissions as needed. The plugin also enables you to create custom roles should the need arise.
By carefully managing user permissions, you can significantly enhance the security of your WordPress site.
What You Can Change in the WordPress Admin Menu
There are several actions you can take to protect your WordPress website from potential security vulnerabilities.
Latest WordPress Version
Keeping your WordPress site updated to the latest version is just as crucial as updating to the latest PHP version. The reasons are the same: security, speed, new features, and bug fixes.
You can check which version of WordPress your website is currently using by visiting the Updates page on your main dashboard.
Minor updates generally occur automatically, but it’s important to monitor this page for major updates. When an update is available, simply click the Update Now button to apply it.
Update Plugins
Many sites are compromised due to a failure to update plugins. With thousands of plugins available, they create a significant ‘attack surface’ for potential hackers, making it essential to stay vigilant.
Don’t overlook the Updates page in the WordPress Admin. When plugins require updating, you’ll receive a notification at the top of the page. Clicking on this notification will direct you to the Updates page, where you’ll see the Update Now button next to each plugin and theme that needs attention.
On the Plugins page, you can also opt to enable automatic updates, which is particularly useful if you don’t log in to WordPress Admin frequently.
Remove Unused Plugins
It’s best practice to limit the number of plugins installed on your website. Only keep those that you actively use, and remove any that are no longer necessary.
This approach will reduce the ‘attack surface’ for malicious hackers: fewer plugins mean fewer vulnerabilities. Additionally, removing unused plugins may help speed up your site, which is always beneficial!
WordPress efficiently provides email notifications to site owners when new updates are available. However, hackers can find version numbers in a website’s source code, targeting sites that still operate on older, unsupported versions. Therefore, make sure to install new versions as soon as possible.
Disable XML-RPC in WordPress
If you use the WordPress app to update and add content remotely to your website, then the XML-RPC remote procedure call feature is useful and should remain enabled.
However, if you don’t use this feature, we recommend disabling it to close off another potential attack vector for cybercriminals.
The easiest way to disable XML-RPC is to install the Disable XML-RPC plugin. Once activated, XML-RPC will be disabled. If your circumstances change and you need to re-enable it, simply reverse the process by deactivating the plugin.
At Weble, we block all attempts by default on all of our hosting packages. However, the Data Centre whitelists reputable applications that require access, such as Jetpack. With Weble, you’re protected as standard and do not need to use the above plugin.
What Your Hosting Company Or Web Site Developer Can Change
We will happily handle any of these requests on your behalf if you have any of our hosting packages.
Ensure Your Site Uses the Latest PHP Version
WordPress is built on the PHP programming language, and all PHP files within your WordPress installation have a .php extension.
While you don’t need to know how to code in PHP to create a WordPress website, it’s essential to perform periodic updates to ensure your site is running on the latest PHP version.
Each new PHP release includes features designed to enhance the stability, speed, and security of your website. These updates also address bugs that may have arisen in previous versions.
Just like operating systems, PHP does not provide security support for all its versions. Running an older version not only means missing out on new features but also increases your exposure to security vulnerabilities and system bugs. Additionally, your site may experience slower performance.
PHP typically releases new versions regularly while phasing out older ones. Each version is expected to receive full security support for at least two years after a new version is introduced. The latest PHP version, released in November 2020, is PHP 8.
The process for changing your PHP version will vary depending on your hosting provider, so check their support for specific instructions.
Security Keys
A website uses cookies to identify a user when they log in with their username and password. However, hackers may attempt to find these cookies in your database to decipher passwords and gain unauthorised access.
To enhance security, WordPress employs security keys and salts to protect these cookies. This process encrypts all passwords stored in your site’s database, making them significantly harder to crack.
For instance, an encrypted password might look like this: ‘36g489bd34hg72ed98s0rf’. This is far more difficult to decipher than a simple password like ‘123456’. There are four security keys: AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY, and NONCE_KEY, each accompanied by its own salt.
You don’t need to create these keys yourself; WordPress provides a random generator to do this for you.
Once generated, simply paste each security key into the wp-config.php file, which can be found in your website’s root folder (usually starting from line 45). We recommend changing your security keys and salts regularly to maintain optimal security.
Disabling the Built-in Code Editors
WordPress includes a built-in code editor that enables you to edit your theme and plugin files directly from the Admin dashboard. To access these files, click on the Appearance tab and select Theme Editor. For plugins, navigate to Plugins and then Plugin Editor.
However, it is advisable to remove both of these code editors from your site. If a hacker gains access to your dashboard, they could exploit these editors to launch malware or DDoS attacks, or even steal your data.
To disable the code editors, simply add the following line of code to your wp-config.php file, placing it above the line that says: ‘That’s all, stop editing! Happy publishing’:
define( ‘DISALLOW_FILE_EDIT’, true );
Once you’ve saved these changes, both file editors will be disabled and will no longer appear on your Admin dashboard.
Disable PHP File Execution
WordPress keeps several directories open on your website to allow easy uploads of new themes, plugins, and other content, such as videos and images. However, if these directories are compromised, they can pose a security risk, as they may be used to upload malicious files disguised as standard core files.
If you’re using 20i, you can rest assured that PHP scripts are blocked at the platform level.
For other hosting providers, you can prevent this risk by disabling PHP file execution in directories where it is unnecessary. To do this, create a .htaccess file using a text editor such as Notepad, Wordpad or Notepad++ and add the following line of code:
<Files *.php>
deny from all
</Files>
Save the file and upload it to the /wp-content/uploads/ directory on your website, using your web host’s FTP client or File Manager.
Disable Directory Indexing and Browsing
Disabling directory indexing and browsing prevents unauthorised users from viewing your website’s files, thereby reducing the risk of malicious access.
This is a quick and straightforward fix. Remember the .htaccess file mentioned earlier? Open it again in your text editor and simply add the following line to the document:
Options -Indexes
Save the file and upload it back to your server, and you’ll have a more secure WordPress website.
Directory indexing is disabled by default with any of our hosting packages


