WordPress is the most popular CMS of all time. However, it’s WordPress’ open source nature that is often the cause of most security issues. When so many websites are sharing the same open source framework, once identified, these flaws can then turn into a rather tempting gold mine for hackers and those with too much time on their hands. Finding one vulnerability essentially gives them a far more efficient way to execute automated large scale attacks.
Just because WordPress is Open Source doesn’t necessarily make it ‘vulnerable’, but there are coordinated steps one can take to prevent attacks on your WordPress CMS website.
These are in a very rough order of importance, but that is really an arbitrary statement since a vulnerability in one area is all it takes to end up with a compromised website. Put simply, follow all the steps or none at all.
1. Update, Update, UPDATE!
You must keep all plugins and themes up to date. The biggest target for wordpress websites is outdated vulnerable plugins or themes. New vulnerabilities are discovered everyday.
If a vulnerability is discovered in a WordPress plugin or theme, then a new version is typically released to solve the problem. Given that it’s open source, the information required to exploit a weakness is now available to the public. if you don’t update, you’re just an easy target.
This includes deleting anything you’re not using. Keeping track of updating plugins and themes you’re not using is a pain and often overlooked.
The best solution is to have automatic updates.
2. Prevent Database Vulnerabilities
This is key and is a popular target for hackers trying to execute remote SQL database injection attacks. Each one of your WordPress databases begins with the prefix “wp_”. If you’ve yet to install WordPress, then change the prefix before you install and make sure you add the “_” so you can easily navigate the database names if you need to in the future.
Some webhosts will do this for you automatically, such as Siteground, some don’t.
The easiest way to do this is to use a plugin that will change database prefixes for you, both bulletproof security and ithemes can change the database strings without any issues.
If you don’t want to use a plugin, then you’ll have to do it manually. It sounds more complicated than it is, but you’ll have to open the wp-config file and change the prefix, then you’ll have to change all the entries from the database.
Most hosts will use C-panel, so you can access the ‘phpmyadmin’ wizard easily from there and simply change the prefixes manually.
3. Harden Your .htaccess File
Your .htaccess file is a hidden plain text file located on the server to that is responsible for how visitors interact with your website, among other things. For example, the htaccess file can be used to block specific traffic from being able to view your site.
By default, you’ll find this in each and every WordPress .htaccess file:
# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress
You’ll need to make sure that any protection code you add comes after this existing code.
To protect your WordPress configuration file (wp-config) from being read, add the following code to the .htaccess:
<files wp-config.php> order allow,deny deny from all </files>
To protect the htaccess file itself, add the following:
<files ~ "^.*\.([Hh][Tt][Aa])"> order allow,deny deny from all satisfy all </files>
This will prevent the htaccess file from being open to attacks as well.
4. Use WordPress Security Plugins
I’ll write a post on the best security plugins soon, but for now, here’s what I recommend if you want added protection.
For comment spam:
For Impressive database and .htaccess hardening:
To prevent brute force attempts:
For malware protection, firewall and scanning:
There is also Ithemes security which is a great all-in-one security plugin for those that like to click and forget. However, it tries to do too much in my opinion and consequently does everything a little less than more specific plugins on offer.
Depending on your hosting provider, some of these could slow down your website. I’ve yet to have this issue, but it is well documented. Make sure you monitor and pay close attention to site speed after installing to keep on top of performance.
5. Remove ‘admin’ user and create strong passwords.
All WordPress installations come with a user that has the default name “admin”. Using admin gives away 50% of what’s need to access your control panel.
Here’s how to create a new user and delete you admin username:
- In the admin panel, navigate to Users and then Add New.
- Add a new user with administrative rights.
- Sign out and in again with the new user
- Go back to Users and delete the old admin.
As for passwords, make sure you use a password over 10 characters and with numbers, capitals, characters and importantly, keep it random.
6. Backup your site on a regular basis.
I host this website using Siteground, so luckily they include daily backups as part of their platform. If you’re host doesn’t provide them, then look at plugins such as:
Sometimes the easiest way to restore issues with a website, depending on the infection, is to simply revert to an older version prior to the compromise.

Awesome article on how to harden wordpress, thanks. wHERE should I add the code to the htaccess file? Cheers matt.
Awesome shout on the DB strings! People (me included) have no idea how to do that in wordpress, just proves you have to really KNOW what you’re doing still to use wordpress effectively!
Was awesome to meet you btw Matt – thanks for your advice, you just saved us a ton of $$
Thanks for your kind words!