06 · Checklist
Checklist: WordPress security
Close the most common ways in, and have a plan for if something goes wrong anyway.
yourweb.se/en/tools/checklists/wordpress-security/
20 items in 5 groups
Your ticks are only saved in this browser. Nothing is sent to us.
Updates
3 items
-
Why: Most intrusions exploit weaknesses that there is already an update for. Check under Updates that they have not been switched off.
-
Why: Plugins are the most common way in. Take a backup first and check the site afterwards, or switch on automatic updates for plugins you trust.
We handle updates, backup and monitoring -
Why: PHP 8.1 and older no longer get security updates, and more versions will follow over time. Switch in the web host’s control panel and check the site afterwards.
Login and permissions
7 items
-
Why: Leaked passwords from other services are tried automatically against WordPress logins. A password manager makes it easy to have unique ones.
Create and test a password -
Why: Even if the password leaks, nobody gets in without the code. WordPress has no built-in function, so use a plugin, and switch it on at the web host as well.
We set up two-step verification and a password manager -
Why: It is the first username that is tried in attacks. Create a new administrator with another name, move the content and delete admin.
-
Why: Someone who only writes posts does not need to be an administrator. A hijacked account with low permission does much less damage.
-
Why: Robots guess passwords around the clock. A block after a few wrong attempts makes the guesses pointless. Security plugins and many web hosts have the function.
-
Why: Without https, login details can be read by others on the same open wifi.
Check the certificate and https in the website test -
Why: If someone gets in as an administrator, they can otherwise write their own code directly in the theme. Put the line
define('DISALLOW_FILE_EDIT', true);in wp-config.php.
Plugins and themes
3 items
-
Why: A deactivated plugin can still have a weakness that can be reached. Keep a standard theme as a fallback and delete the rest.
-
Why: Free copies of paid plugins often contain backdoors. Buy a licence or choose a free alternative.
-
Why: A plugin that nobody updates stays vulnerable when a weakness is found. Look at “Last updated” and the number of active installations.
Backup and restore
2 items
-
Why: If the backups are on the same server, they often disappear together with the site. Take both files and database and keep at least two weeks back.
Backup that works: plan and cloud backup -
Why: A backup that has never been tested is a guess. Do a restore at least once and note how long it takes.
Monitoring and operation
5 items
-
Why: Unknown administrators are a common sign that someone has already got in. They are also a backdoor that survives a password change.
-
Why: A firewall stops known attack patterns before they reach the site, and a plugin warns about changed files. Choose one: several security plugins at the same time can clash.
-
Why: A hacked or down site is otherwise only noticed when a customer gets in touch. There are free services that check every few minutes.
-
Why: WordPress itself lists critical problems, such as an old PHP version, inactive plugins and missing updates, and shows how to fix them.
-
Why: During an intrusion every hour counts. Note who contacts the web host, where the latest clean backup is and which passwords are to be changed, in a place that is not on the site.
Hacked site? We clean it and strengthen the protection
All done
You have ticked off all items. Print the list or copy it as text if you want to keep it as a record.
Remove all ticks in this list? This cannot be undone.
- No sign-up, no account
- The ticks are only saved in your browser
- Can be printed or copied as text
How to use the list
Three steps through the list
-
Tick off what is already done
Tap a row to tick it off, or use Tab and Space. Start with updates and login: that is where most intrusions happen.
-
Read why and follow the link
Under each item it says why it is there. Where a tool, a guide or a fixed package can help, there is a link.
-
Carry on when you have time
What you have ticked off is saved in your browser. Go through the list again after every major change, and print it or copy it as text if you want to share it.
Good to know
- Your ticks are only saved in this browser, on this device. Nothing is sent to us.
- They are not synced between phone and computer, and disappear if you clear the browser’s data or browse in private mode.
- The list applies to your own WordPress installation (WordPress.org). On wordpress.com the provider takes care of large parts for you.
Why do WordPress sites get hacked?
Usually not because someone has targeted you in particular, but because robots search the internet for known weaknesses in old plugins and themes, and for passwords that have leaked from other services. That is why the emphasis is on updates, login and removing what you do not use.
The most underrated is the backup. A backup that sits on the same server as the site often disappears together with it, and one that has never been tested may not be possible to restore. Do a real restore to a test copy at least once.
The third is accounts: a username called admin, shared passwords and administrators who really only write posts. Switch on two-step verification and give everyone the lowest possible permission.
Read more under cybersecurity. If you would rather not handle it yourself, there is WordPress care with updates, backup and monitoring, and troubleshooting when something has broken. If it has already happened, we help with cleaning a hacked WordPress site.
Fixed packages
Do you want to avoid doing it yourself?
There are packages for most of what is on the list. Prices include VAT, and the scope is confirmed in writing before we start.
- WordPress care: updates, backup and monitoringFrom SEK 995/month incl. VAT
- Hacked WordPress site? We remove malware and tighten securityFrom SEK 2,995 incl. VAT
- Two-step verification and password managerFrom SEK 1,995 incl. VAT
- Backup that worksFrom SEK 2,995 incl. VAT
- WordPress troubleshooting, one error in a theme or pluginFrom SEK 1,995 incl. VAT
Frequently asked questions
Questions about WordPress security
Is a security plugin enough?
No. A plugin or a firewall helps, but does not replace updates, unique passwords, two-step verification and a backup that can be restored. It is the combination that protects.
How often should I update WordPress and the plugins?
Security updates of WordPress are often installed automatically. You should go through plugins and themes at least once a week, and a serious weakness may need fixing the same day. Take a backup before every major update.
What do I do if my WordPress site has already been hacked?
Put the site in maintenance mode and contact the web host. Change all passwords, restore from a backup that is older than the intrusion and update everything before you open the site again. If you cannot get it in order, we help with cleaning and stronger protection.
Do you want a more secure WordPress site?
Tell us what worries you, and we say what needs to be done first. You get a written price before we start.