Why is WordPress Security More Important Than Ever?
WordPress, as the world's most popular content management system, is the primary target of automated and human attacks. Every day, thousands of scanner bots search WordPress sites for known vulnerabilities. If you think your small site isn't worth attacking, you're sorely mistaken; most automated attacks look for undefended sites, not large ones. In this article, we provide a practical roadmap for WordPress security that starts with the most important and effective measures and progresses to technical details.
The key point is that security is a process, not a product. No plugin alone can secure your site. A combination of good habits, precise settings, and continuous monitoring significantly raises your site's security level. In what follows, we cover four main areas: updates, login restrictions, file permissions, and hiding the WordPress version.
Updates; The First and Most Important Line of Defense
Most successful attacks on WordPress sites exploit known vulnerabilities for which a new version has been released, but the sites haven't updated. Regularly updating the WordPress core, plugins, and themes is the simplest and most effective measure for WordPress security.
Enabling Automatic Updates
From version 5.6 onward, WordPress has enabled automatic updates for minor versions by default. But for major versions and plugins, you need to decide yourself. You can enable automatic updates for everything by adding the following code to the wp-config.php file:
// Enable automatic updates for everything
add_filter( 'auto_update_core', '__return_true' );
add_filter( 'auto_update_plugin', '__return_true' );
add_filter( 'auto_update_theme', '__return_true' );
If you prefer more control, at least enable security updates and set a regular weekly or monthly schedule for major versions. Perform updates during low-traffic hours and always back up your site before doing so.
Removing Unnecessary Plugins and Themes
Every plugin you install increases your site's attack surface. Delete plugins you don't use, don't just deactivate them. Inactive files remain on the server and may have vulnerabilities. The same rule applies to themes; keep only the active theme and one default theme (like Twenty Twenty-Four).
Restricting Access to the WordPress Admin
The login page (wp-login.php) is one of the most attacked points of any WordPress site. Brute-force attacks (password guessing) are carried out automatically with thousands of attempts per minute. Restricting login is one of the pillars of WordPress security.
Using Strong Passwords and Two-Factor Authentication
The site admin password should be at least 16 characters and a combination of uppercase, lowercase letters, numbers, and symbols. Avoid reusing passwords across other sites. For an extra security layer, install a plugin like WP 2FA or Wordfence to enable two-factor authentication (2FA). With 2FA, even if the password is leaked, an attacker cannot log in without the second-factor code.
Limiting Login Attempts
Plugins like Limit Login Attempts Reloaded limit the number of failed attempts. Recommended setting: a maximum of 3 failed attempts every 10 minutes, with a 30-minute lockout. This effectively neutralizes brute-force attacks.
Changing the Login Page URL
By changing the default login URL, you confuse bots. The WPS Hide Login plugin allows you to change the login URL to a custom path like /my-secret-login. Note that this doesn't provide absolute security, but it drastically reduces automated attacks.
Restricting Login by IP
If you use a static IP, you can restrict access to wp-login.php to only your IP. You can do this in the .htaccess file (for Apache):
<Files wp-login.php>
Require ip YOUR_IP_ADDRESS
</Files>
If you use Nginx, add the following code to the server block:
location = /wp-login.php {
allow YOUR_IP_ADDRESS;
deny all;
}
Setting File and Folder Permissions
Incorrect file permissions are one of the main reasons for WordPress site breaches. If files are writable by everyone, an attacker can inject malicious code. Correctly setting permissions is a critical part of WordPress security.
Standard and Secure Permissions
The following permissions are considered the golden standard:
- Files:
644(owner can read and write, others can only read) - Folders:
755(owner can read, write, and execute; others can only read and execute) wp-config.phpfile:600(only the owner can read and write)
To apply these permissions via SSH, use the following commands:
# Set all files to 644
find /path/to/wordpress -type f -exec chmod 644 {} \;
# Set all folders to 755
find /path/to/wordpress -type d -exec chmod 755 {} \;
# Set special permissions for wp-config.php
chmod 600 /path/to/wordpress/wp-config.php
Protecting the wp-config.php File
The wp-config.php file contains sensitive information like the database username and password. In addition to 600 permissions, you can move it to a directory above the site root. WordPress automatically looks for this file in the higher directory. This makes the file inaccessible via the web.
Disabling PHP Execution in Upload Folders
The wp-content/uploads folder is where user files are uploaded. If an attacker can upload a malicious PHP file to this folder and execute it, your site is in serious danger. By adding the following code to the .htaccess file in the upload folder, you can disable PHP execution:
<FilesMatch "\.(php|php5|phtml)$">
Require all denied
</FilesMatch>
For Nginx, add the following code to the location block:
location ~* /wp-content/uploads/.*\.(php|php5|phtml)$ {
deny all;
}
777 to solve upload issues. This is very dangerous and allows an attacker to write any file to the server. Always use standard permissions.Hiding the WordPress Version
By knowing the exact version of WordPress, plugins, and themes, attackers can target known vulnerabilities of that version. Hiding the version conceals valuable information from attackers and is part of WordPress security.
Removing the Version Meta Tag from the Header
WordPress by default places a meta tag with the version content in the site header. To remove it, add the following code to the functions.php file of your child theme:
remove_action( 'wp_head', 'wp_generator' );
Removing the Version from Static File URLs
WordPress adds the version to the end of CSS and JS file URLs (like style.css?ver=6.4.2). To remove this parameter, add the following code:
function remove_wp_version_from_assets( $src ) {
if ( strpos( $src, 'ver=' ) ) {
$src = remove_query_arg( 'ver', $src );
}
return $src;
}
add_filter( 'style_loader_src', 'remove_wp_version_from_assets', 9999 );
add_filter( 'script_loader_src', 'remove_wp_version_from_assets', 9999 );
Restricting Access to Informational Files
Files like readme.html and license.txt contain version information. Delete these files or block access to them via .htaccess:
<FilesMatch "^(readme\.html|license\.txt|wp-config\.php)$">
Require all denied
</FilesMatch>
Restricting Access to XML-RPC Files
The xmlrpc.php file is known as an entry point for brute-force and DDoS attacks. If you don't use it (e.g., for connecting to mobile apps), disable it. By adding the following code to .htaccess:
<Files xmlrpc.php>
Require all denied
</Files>
readme.html file. An attacker can see the exact WordPress version by directly visiting /readme.html. Cover all sources of version information.Summary and Next Steps
WordPress security is an ongoing process. By implementing the following steps, you significantly increase your site's security level:
- Regularly update the core, plugins, and themes
- Restrict login with strong passwords, 2FA, and attempt limits
- Set file permissions to
644and folder permissions to755 - Hide the WordPress version from all sources
- Take regular backups and test restoration
For high-traffic or critical sites, using hosting services that provide security at the infrastructure level is recommended. ServerNet, as a hosting and cloud infrastructure provider, offers environments with optimized security configurations for WordPress that can be part of your security strategy. But remember, no service replaces following security principles at the application level. By implementing this guide, your site will be resilient against most common attacks.