In part 3 of our Comprehensive Step-by-Step Guide to WordPress Security, we discuss securing your database and how to back it, and other important site files, up, as well as malware and methods for scanning for it. Finally, we’ll cover the use of security plugins, whether you truly need them, and the best plugins available at the time of writing.
Much of what we will discuss here depends on your hosting company and/or web developer, as well as the services they provide.
If you have any of our hosting packages, alongside our Maintenance & Support Services, all of these points are are already managed by us. The only thing we don’t automatically cover, is additional security plugins, although we are happy to talk to you about this, make suggestions, and manage those plugins for you.
Secure Your Database
Database Prefix
If you’re familiar with the file configuration of WordPress sites, you’ll know that the database file typically begins with the prefix ‘wp_’, followed by your site name—‘wp_yourwebsite’.
When you first set up a WordPress site, it’s advisable to rename the database table prefix. It doesn’t have to be overly complex; using your initials—such as ‘yourinitialswp_’ or ‘wpyourwebsiteinitials_’—is perfectly acceptable.
Backups
Regularly backing up your WordPress site data is something we all know we should do, yet it’s surprising how many site owners allow this important task to be neglected. While it may not be the most exciting job, it is essential and must be done.
There are a number of plugins that we can recommend if your hosts don’t already provide this service. Or if you just prefer to be in full control of your own backup solution. We often hold agency licences for the most popular WordPress plugins, which means we are able to licence these products cheaper than you can buy them for, direct from the development company. Contact Us for more details.
Monitor Audit Logs
Monitoring your WordPress website’s audit log is an effective way to track user activity and ensure that they are not engaging in actions outside the permissions you’ve set. If you have many users or manage multiple websites, this can become a cumbersome task.
The WP Activity Log plugin simplifies this by creating a convenient reference log of all activity on your site. It captures everything from users who have forgotten their passwords to more malicious login attempts.
With 20i, you can view your site’s audit log directly in your My20i account control panel.
Strong Passwords
It’s important to set a strong password for your database as a good security practice. When creating the database password, apply the same principles as for your main login—the more complex your password, the harder it is to hack.
Remember, you can always use an online strong password generator to create one for you.
Scan for Malware
All the measures mentioned so far in this guide will significantly enhance the security of your WordPress website. However, if you want to be even more proactive, you can regularly scan for any malware that may have infiltrated your site.
Weble’s free on-demand automatic scanner
If you’re using our hosting services combined with our Maintenance & Support Services, we include free malware scanning as part of the package. This software automatically scans your site for malware on a daily basis. It can also conduct a scan ‘on-demand’, should you identify any suspicious activity on your site.
Once each scan is complete, a report is compile with the results. If any malware is spotted we proactively take recommended steps. Once complete, we’ll run another scan to make sure everything has now been fixed.
We’ve also a WordPress Checksum tool works in a similar way. It checks that your installation matches the official WordPress repository, and can often find core files that have been changed by malware and auto-replace them for you.
Other malware scanning options
Many other WordPress hosts offer similar malware scanning facilities, so if you’re not with us you should check with your provider to find out what their package includes and whether there’s a charge to use it.
If you’d prefer to adopt a more ‘hands-on’ approach, there are a number of online providers that will be able to perform this service for you, such as Google, Sucuri SiteCheck and WPScans.
WordPress security plugins
Do I need a security plugin?
The quick answer is: no, not in every case.
Whether you need a security plugin depends on what you’re using WordPress for. If it’s just a small blog, you likely don’t need one, especially if you follow the tips outlined in this guide. There are other factors to consider as well.
More plugins can lead to longer loading times, which may discourage visitors from reading your posts, purchasing your products, or browsing your services. Google takes loading speed into account when ranking sites, so faster-performing websites tend to achieve higher positions in search results. Performance can directly impact your bottom line, and security plugins can sometimes slow down loading times or conflict with other functions.
This might suggest that a security plugin isn’t necessary. Hosting with us, you’ll benefit from a range of secure hosting features, such as the Web Application Firewall (WAF) and brute force login protection, meaning you may not need an additional security plugin.
What Are the Best WordPress Security Plugins?
You may not receive the same level of protection at other hosts, so in this section, we will take a closer look at some of the best WordPress security plugins currently available.
The first piece of advice when selecting a security plugin is to ensure that you choose one from a reputable source. Avoid downloading a paid plugin from a site that offers it for free!
With that in mind, here’s a list of the ten best security plugins that provide various features to help keep your WordPress website safe from malicious attacks:
- Wordfence Security
- iThemes Security
- Sucuri Security
- All In One WP Security & Firewall
- Defender Security
- WP Hide & Security Enhancer
- VaultPress
- MalCare Security
- SecuPress
- BulletProof Security
What Do They Offer and How Do They Differ?
Wordfence Security is arguably the most comprehensive all-in-one WordPress security and firewall plugin available today. It offers both a free and a premium package, both providing a significant level of protection for your website. Wordfence features a robust web application firewall (WAF) and malware scanning, as well as two-factor authentication (2FA) to defend against brute force attacks—a feature not commonly found in free plugins.
Unlike other plugins, Wordfence not only tracks attempted hacks on your website but also identifies the source of this traffic (whether from Google crawlers, humans, or bots).
iThemes Security offers both free and premium versions. However, unlike Wordfence, it does not include a firewall, although it does provide a malware scanner. This plugin delves deeply into a variety of security measures, such as hiding the login page, removing ‘admin’ as a username, and changing the database prefix.
Sucuri is another popular choice, available in both free and premium versions. While its free version is considered to have a more basic malware scanning feature than both Wordfence and iThemes, the paid version does include a powerful firewall feature.
All In One WP Security & Firewall is a free plugin that is regarded as extremely user-friendly. It provides basic firewall protection and secures your site against spam comments on your blog. It caters to beginners while allowing users to select from three levels of protection—basic, intermediate, or advanced—based on their experience.
Defender Security is a straightforward plugin available in both free and premium versions. The premium version includes cloud backups with 10GB of storage and audit logs to monitor user activity. In the event of a hack, it offers access to expert advice to help you restore your site as quickly as possible.
WP Hide & Security Enhancer does exactly what its says on the tin: it conceals the fact that you’re using WordPress as your content management system from potential hackers. It also hides the names of the themes and plugins used on your site, making it harder for attackers to identify vulnerabilities. This plugin is available as a free option and is very easy to use.
VaultPress, part of the JetPack suite, is a premium-only plugin that offers malware scanning using its own servers, ensuring that your site’s performance isn’t affected. It also features premium plans that can automatically resolve security issues it detects.
MalCare, as its name implies, places significant emphasis on malware scanning and detection. Like VaultPress, it utilises its own servers for scanning and provides a ‘one-click removal’ feature for any malicious files found. This plugin is available as a premium option only.
SecuPress is available in both free and premium versions. It boasts many features, including an impressive firewall. What distinguishes it from other security plugins is its protection of your website’s security keys, along with a ‘one-click solution’ for issues identified during malware scans.
BulletProof Security can also be found in free and premium versions. It is generally seen as better suited to more advanced users but includes an easy-to-use setup wizard to assist beginners. This plugin offers idle session logouts and email notifications for any failed login attempts.
Which WordPress Security Plugin Should I Choose?
All the security plugins outlined above will effectively help protect your website from unwanted visitors.
Choosing the right one may require some trial and testing. However, before doing so, it is advisable to check what your web host provides as part of their hosting package.
Once you understand your host’s offerings, you can eliminate any plugins that duplicate existing protections and select one that complements the security measures you already have in place.


