SECURITY

How to protect WordPress from 99% of attacks

WordPress is the most popular CMS in the world, and that's exactly why it's the most attacked. The good news is that the vast majority of attacks are automated and are repelled by basic measures.

Main attack vectors

  • Brute-force — guessing passwords for wp-login.php.
  • xmlrpc.php — an outdated interface often used to amplify attacks.
  • SQL injections and XSS — through vulnerable plugins.

A checklist of 12 actions

  1. A strong admin password and two-factor authentication.
  2. Limiting login attempts.
  3. Disabling or protecting xmlrpc.php.
  4. Regular updates of the core, themes and plugins.
  5. A web firewall (WAF) — on WPHost this is Imunify360.
  6. Protection from 0-day vulnerabilities via Patchstack.
  7. Forbidding PHP execution in the uploads folder.
  8. Hiding the WordPress version.
  9. Regular automatic backups.
  10. An SSL certificate across the whole site.
  11. A minimum of plugins from trusted sources.
  12. Monitoring and antivirus scanning of files.
The combination of WAF + auto-updates + backups closes 99% of typical hacking scenarios.
← All articles

Ready to migrate your site to WPHOST?

15-day money-back, no questions. Free migration from your current host. Start right now.