Why does security matter?
WordPress is very popular, so attackers target it often. A hacked site can show spam, lose data or be blocked by search engines. The good news is that basic steps stop most attacks.
1. Keep everything updated
Old software has known holes. Update WordPress, plugins and themes. A plugin is an add-on with extra features. A theme is the design of your site.
- Log in to your WordPress dashboard.
- Go to Dashboard, then Updates.
- Update everything that has a new version.
2. Use strong passwords
- Go to Users, then Profile.
- Click Set New Password.
- Use a long password with letters, numbers and symbols.
- Never reuse a password from another site.
3. Avoid the username "admin"
Attackers try "admin" first. Make a new administrator with another name. Then delete the old one.
4. Add two-factor login
Two-factor login needs a second proof, like a code from your phone. A security plugin can add it.
5. Limit login attempts
Install a plugin that blocks someone who fails to log in many times. This stops password guessing.
6. Remove what you do not use
- Go to Plugins, then Installed Plugins.
- Deactivate and delete any plugin you do not need.
- Do the same for unused themes under Appearance, then Themes.
7. Use only trusted plugins and themes
Download from the official WordPress library or from known makers. "Free" copies of paid items often hide harmful code.
8. Use HTTPS
HTTPS encrypts the data between your visitor and your site. It uses an SSL certificate, a digital ID for your site. Ask Hostvento support about SSL for your plan.
9. Make regular backups
A backup is a saved copy of your site. If something goes wrong, you can restore it. Keep a copy off the server too.
10. Set safe file permissions
Folders should usually be 755 and files 644. Never set 777. It lets anyone write to your files.
11. Turn off the file editor
This stops anyone who gets into your dashboard from editing code there.
- In File Manager, edit
wp-config.php. - Add this line above the "stop editing" comment:
define( 'DISALLOW_FILE_EDIT', true );
This hides the theme and plugin editors in the dashboard.
12. Install a security plugin
A good security plugin scans for malware and adds a firewall. A firewall blocks bad visitors.
Quick recap
- Update WordPress, plugins and themes.
- Use strong passwords, two-factor login and limited login attempts.
- Delete unused plugins and themes.
- Use HTTPS and take regular backups.