22 Tips to keep your WordPress site secure

Here are some useful tips to help keep your WordPress site from being hacked. Plugins can help you with many of the tips I mention.

  1. Keep your themes and plugins up to date.
  2. Use strong passwords.
  3. Enable 2FA (two factor authentication).
  4. Use secure FTP.
  5. Disable comments if not needed.
  6. Disable registration if not needed.
  7. Use https (SSL) on your site.
  8. Check file permissions. Default should be 640.
  9. Check folder permissions. Default should be 750.
  10. Move wp-config outside of public_html. This prevents the file from being accessible from the internet.
  11. Disable file editing.
  12. Remove the default admin account with an id of 1. Or change the default ID of the admin account.
  13. Change the default database prefix.
  14. Don’t have any users with the name admin, administrator, or webmaster.
  15. Create secret keys.
  16. Add blank index.php files where needed.
  17. Delete readme.html and install.php.
  18. Keep your computer antivirus program up to date.
  19. Never use the same password for multiple websites.
  20. Backup everything in case something happens.
  21. Disable XML-RPC
  22. Avoid installing WordPress and not doing anything else to secure it. Your site will get hacked if you do this.

