WordPress and security: the paradox of popularity
WordPress powers more than 43% of the world’s websites. That is its strength, and its weakness too. Its popularity makes it the favorite target of the malicious bots that scan the web without pause in search of vulnerable sites. The good news is that almost all of these attacks are automated, and a few simple WordPress security measures are enough to block them.
What a hacked WordPress site really costs
The stakes are underestimated for as long as nothing has happened. Yet a compromised site is not merely “down”. The damage is concrete, and it adds up:
- Lost revenue. Every hour offline is visitors and quote requests going elsewhere.
- A Google demotion. An infected site is quickly flagged, sometimes labeled “dangerous site” in the results. Climbing back takes weeks.
- Lost trust. A customer whose browser throws up a warning on your site will not be back any time soon.
- Clean-up costs. Having a site disinfected by hand often costs more than a full year of preventive maintenance.
- A data leak. If your site collects customer information, a breach can make you liable under the GDPR.
Security, then, is not an expense: it is insurance, and the premium is trifling next to the loss it averts.
The 8 essential measures to secure your WordPress site
These eight measures cover the vast majority of the risks. None of them requires advanced technical skill.
Each measure is walked through step by step, with screenshots of the settings to back it up, in our guide to how to secure a WordPress site.
Measure 1: Systematic updates
WordPress, themes and plugins must be updated as soon as a new version is available. Every update closes documented vulnerabilities. Not updating is leaving the door open to attacks that are already known.
Measure 2: Strong, unique passwords
Use a password manager and generate random passwords of 16 characters or more for your WordPress admin. Turn on two-factor authentication (2FA) for your back office.
Measure 3: Change the admin login URL
By default, every WordPress site can be reached at “/wp-admin”. The bots know it, and that is where they aim their brute-force attacks. Change that URL with a plugin such as WPS Hide Login.
Measure 4: Install a security plugin
Wordfence and Sucuri Security are the two established names. They provide a web application firewall, malware scanning, blocking of suspicious IP addresses and real-time alerts.
Measure 5: Automatic daily backups
A backup is only worth anything if it is stored away from the main server. Use UpdraftPlus to send your backups automatically to Google Drive, Dropbox or S3 storage. And test the restore regularly: a backup that has never been tested is not a backup.
Measure 6: An SSL certificate and mandatory HTTPS
A site still on HTTP in 2026 is a site that does not inspire confidence. HTTPS encrypts the exchanges between your site and your visitors, protects the data entered in forms, and counts as a ranking signal for Google.
Measure 7: Limit login attempts
Automatically block IP addresses that try to log in several times with the wrong credentials. A simple plugin such as “Limit Login Attempts Reloaded” (free) wipes out almost every brute-force attack.
Measure 8: Delete unused plugins and themes
Every inactive plugin left in place remains a potential attack surface. Delete, rather than merely deactivate, everything you do not use. A pared-down site is a safer and faster site.
The most common security mistakes
Beyond the good practices to adopt, certain habits weaken a site without anyone noticing:
- Keeping the default “admin” account. It is the first username the bots try. Create an administrator account under a name of your own and delete “admin”.
- Installing pirated plugins. A premium plugin downloaded free from a dubious site almost always carries malicious code.
- Never looking at the updates. A site nobody has logged into for six months accumulates known vulnerabilities.
- Piling on plugins. Every plugin adds code, and therefore attack surface. Five dependable plugins beat twenty installed “just in case”.
- Confusing deactivating with deleting. A deactivated plugin is still sitting on the server, and can still be exploited.
How often should you check your site’s security?
Security is not a one-off action; it is a rhythm. Here is a simple benchmark:
If you have neither the time nor the inclination to keep that rhythm, leave the monitoring of your site to us: we will tell you first what is missing, before proposing anything at all.
- Every week: apply the updates to WordPress, the theme and the plugins, and check that a recent backup really does exist.
- Every month: run a full malware scan and go through the user accounts.
- Every quarter: delete unused plugins and themes, check performance and test a backup restore.
That rhythm looks demanding to anyone running a site alone. Which is exactly why a website subscription with maintenance built in exists: you hand the routine over and never have to think about it again.
What to do if your site has already been hacked
Do not panic. Put the site into maintenance mode so that no visitor sees the compromised page, contact your host, and if you have a recent, clean backup, restore it. Without a backup, the site will have to be cleaned by hand: identify the infected files, replace them, change every password and check the user accounts. When in doubt, call in a professional: an incomplete clean-up often leaves a back door behind it.
If the incident is beyond your skills or time is short, you can open an urgent WordPress support ticket: one dedicated hour of work, booked and paid for online, to take back control of the site before Google flags it as dangerous.
Several of these measures belong to the server rather than the site: they come included in our managed cloud hosting.
These eight measures only hold if someone keeps them up. That is the point of regular WordPress maintenance.
Frequently asked questions about WordPress security
Is WordPress a secure CMS? Yes. The WordPress core is developed and audited by a vast community. Most hacks do not come from WordPress itself but from outdated plugins, weak passwords or neglected hosting.
Does a small site really need securing? Yes. The attacks are automated: the bots do not choose their targets, they scan the whole web. A three-page brochure site gets probed as much as a large one.
Is a security plugin enough on its own? No, but it is a solid foundation. A plugin such as Wordfence covers the firewall and detection, but it replaces neither updates, nor backups, nor serious hosting.
Do you have to pay to secure a site properly? Not necessarily. Most of the 8 measures rely on free tools. The real cost is time and regularity, and that time is what a maintenance subscription gives you back.
Conclusion
WordPress security is not reserved for experts. These 8 measures are within reach of any website owner, and most of them rely on free tools. What matters is not the technique: it is the regularity.
If you are short of time to put them in place, an all-inclusive maintenance subscription builds them in automatically. You can also look at our WordPress and SEO training, run from Pau in south west France, if you would rather manage your site yourself.



