Customer Impact

Website & Development

WordPress Security: 12 Measures Against Hacks (B2B Checklist)

Copy for AI

Securing WordPress does not start with expensive tools, but with getting a few basics right and doing them consistently: keeping everything up to date, strong logins with two-factor authentication, a firewall and the right user permissions. WordPress powers roughly 42% of all websites, and that popularity makes it a favourite target for automated attacks. In this article we walk through 12 concrete measures to harden a business WordPress site (not a webshop) against hacks, grouped from logins to infrastructure, with a checklist at the bottom you can tick off.

Why is WordPress attacked so often?

Not because WordPress is insecure, but because it is everywhere. With a share of around 42% of all websites it is simply the biggest target, and attackers work automatically: bots scan the entire web for known vulnerabilities and weak logins.

More important still is where those vulnerabilities sit. Patchstack’s 2025 security research shows that the vast majority of WordPress vulnerabilities are in plugins, a small share in themes, and almost nothing in the WordPress core itself. In other words: the core is generally well maintained, but every plugin and every theme you add is another door that can be left open. Many of those vulnerabilities can also be exploited without logging in, which makes them ideal for automated attacks.

The practical conclusion for a B2B site: you do not need to be a security expert, but you do need your basic hygiene in order. A hacked business site costs you not just remediation work, but also trust with exactly the visitors you want to convert into leads. How to build that trust is covered in building trust on your B2B website.

How do you secure the logins?

The login page is the most attacked spot on your site, so that is where you get the quickest wins. Four measures:

  • Strong, unique passwords for every account. Use a password manager so nobody falls back on “CompanyName2025”. Reused passwords are the number one cause of hijacked accounts.
  • Two-factor authentication (2FA) on all accounts. This is the single most important measure you can take. Even if a password leaks, an attacker does not get in without the second factor (a code on your phone). Make it mandatory for every user with admin rights.
  • Limit the number of login attempts. By default you can try a password an unlimited number of times, which invites brute-force attacks. A plugin or your firewall that blocks after a few failed attempts closes that door.
  • Least-privilege user roles. Give nobody more rights than they need. An editor who only writes blog posts does not need an administrator account. The fewer admin accounts, the smaller the risk if one of them is compromised.

Also consider moving or shielding the default login URL. It will not stop a targeted attack, but it keeps the bulk of automated bots away from your login page.

How do you keep plugins and updates under control?

Updating is not maintenance you get around to “some day”, it is your most important defence. Because most vulnerabilities sit in plugins and themes, updating is literally closing known holes before a bot finds them.

  • Keep core, plugins and themes up to date. Set security updates for the core to automatic. For plugins, a fixed weekly or fortnightly moment is often wiser than blindly auto-updating everything, so you can first test an update on a staging environment and do not wake up to a broken site.
  • Delete what you do not use. Every deactivated but still installed plugin or unused theme remains a risk. Remove them completely. Less code on your server means less attack surface and a faster site at the same time.
  • Only install from trusted sources. Use plugins from the official directory or from well-known makers, with recent updates and an active maintenance team. Avoid “nulled” (illegally copied) premium plugins entirely: they are a classic delivery channel for malware.

A site with fifteen half-maintained plugins is by definition more vulnerable than a tightly built site with five good ones. With a new website or redesign, a critical look at your plugin stack is therefore a free security win.

Which measures belong at server and infrastructure level?

The final layer sits underneath WordPress itself: hosting, connection and file permissions. This is where you prevent an attack that does get through from doing a lot of damage.

  • Put a Web Application Firewall (WAF) in front of it. A WAF filters malicious traffic (such as known exploit attempts and brute-force bots) before it reaches your site. This can be done through a security plugin or, often more effectively, at network level with your host or CDN.
  • Enforce HTTPS across the entire site. A valid SSL certificate encrypts traffic between visitor and server, protects submitted data and is by now a baseline expectation for any business site. Make sure everything redirects to https automatically.
  • Set file permissions correctly and disable the built-in file editor. With the right file permissions an attacker cannot overwrite files. By switching off the code editor in the dashboard, you prevent anyone who does get in from injecting malicious code straight away.
  • Choose hosting with security built in. Good (managed) WordPress hosting adds server security, isolation between sites, automatic updates and malware scans. That saves you a lot of manual work and covers a layer you cannot reach with plugins alone.

How do you make sure you recover quickly after an incident?

No security is a hundred percent watertight, so the question is not only whether you stop an attack, but also how quickly you recover. Two measures make the difference between an annoying hour and a week of downtime:

  • Automatic, offsite backups. Make a daily or weekly backup and store it separately from your server. A backup sitting on the same hacked server is just as lost in an attack. Test now and then whether you can actually restore a backup.
  • Monitoring and malware scanning. Have a tool scan your site for suspicious files and unusual changes, and send an alert as soon as something deviates. The sooner you spot a breach, the less damage. Many hacks in fact go unnoticed for a long time.

This safety-net layer is also what keeps disruption short when you make technical changes, such as during a website migration without losing rankings.

The 12-point WordPress security checklist

Work through this list from top to bottom. The first points deliver the most security per minute of work.

  1. Keep core, plugins and themes up to date and switch on automatic security updates for the core.
  2. Remove unused plugins and themes completely, do not just deactivate them.
  3. Only install plugins from trusted sources and avoid illegally copied premium plugins.
  4. Use strong, unique passwords with a password manager.
  5. Enable two-factor authentication for every account with admin rights.
  6. Limit the number of login attempts to stop brute-force attacks.
  7. Apply least privilege: give every user only the role they need.
  8. Shield your login page or move the default login URL.
  9. Put a Web Application Firewall in front of your site, preferably at network level.
  10. Enforce HTTPS across the entire site with a valid SSL certificate.
  11. Set file permissions correctly and disable the built-in file editor.
  12. Arrange automatic offsite backups and monitoring, and test your restore.

If you want to place this within a broader picture, read the overarching guide to B2B website development. And because a fast, clean site also performs better, this approach ties in seamlessly with your WordPress SEO.

The short summary

Securing WordPress is not a matter of one magic plugin, but of consistently sticking to a handful of basics. Keep everything up to date, limit your plugin stack to what you actually use, set up strong logins with two-factor authentication, put a firewall in front of it and arrange backups as a safety net. Most attacks are automated and go for the low-hanging fruit, so anyone with the basics in order already falls outside the reach of the bulk of the bots. We build B2B sites that not only convert but also stay maintainable and secure, with honest advice on what is and is not worth the effort. Not webshop-grade security, but a solid business site that brings you leads instead of problems.

Book your free intake call

Free website scan

Enter your website and get an automatic scan within minutes, with concrete technical and SEO improvements. No sales pitch.

Where should we send your report?

We only use your details for your scan. No spam, unsubscribe anytime.