Most hacked WordPress sites aren’t compromised through some sophisticated attack — they’re compromised through an outdated plugin, a weak password, or no backup to recover from once something goes wrong. These basics cover the large majority of real-world risk.
1. Keep WordPress core, themes, and plugins updated
Nearly every major WordPress compromise traces back to a known, already-patched vulnerability in an outdated plugin or theme. Check the Updates screen in wp-admin regularly, and remove plugins you’re not actually using — an inactive plugin can still be a security hole if it’s not updated, and every unnecessary plugin is one more thing that can break or be exploited.
2. Use strong, unique admin credentials
Never use “admin” as a username — it’s the first guess in every automated attack. Use a long, unique password (a password manager makes this painless), and enable two-factor authentication for wp-admin login through a security plugin or your host’s built-in option. Automated bots scan for weak WordPress logins constantly; this alone stops the vast majority of attacks.
3. Have a real, working backup
A backup should cover both the database (your posts, pages, settings) and the files (theme, plugins, uploads/media), stored somewhere other than the same server the site lives on. Many hosts include automatic backups — confirm yours actually does, how far back it goes, and that you know how to trigger a restore before you need one in an emergency, not during one.
4. Limit login attempts
By default, WordPress allows unlimited login attempts, which is exactly what automated brute-force bots rely on. A security plugin or host-level setting that locks out an IP after a handful of failed attempts closes this off almost entirely.
5. Keep an eye on file changes
A security plugin that alerts on unexpected file changes (new files appearing in your theme folder, core files being modified) catches a compromise early, before it spreads or gets noticed by visitors — often well before Google flags the site for malware, which can hurt search rankings.
6. Use HTTPS everywhere, and keep your SSL certificate current
Most hosts now provide free, auto-renewing SSL certificates (Let’s Encrypt), so there’s rarely a reason to run a WordPress site without HTTPS. Beyond the padlock icon, this also protects login credentials in transit and is a baseline requirement for good SEO.
If a site does get compromised
Restore from a known-clean backup rather than trying to manually hunt down every injected file — it’s faster and far more reliable. Then change every password associated with the site (WordPress admin, hosting account, database, FTP) before bringing it back online, since the entry point is often a leaked or weak credential rather than the vulnerability itself.
Backups must live somewhere else
A backup stored on the same server as the site is not a backup. If the server is compromised, encrypted, or suspended by the host, both go together. Whatever plugin you use, send copies offsite — a separate cloud account is fine — and confirm they are actually arriving. A backup plugin reporting success while writing to a full or disconnected destination is a common and quiet failure.
Restore one to a staging site once a year. Same principle as any other backup: untested means unproven. Our guide to backing up properly covers the same logic for the machines in your office.
What actually causes incidents
Nearly every compromised small-business WordPress site we see comes down to the same short list:
- Out-of-date plugins. Most attacks target known vulnerabilities in old versions, automatically, at scale. Updating promptly prevents the large majority.
- Abandoned plugins. Anything not updated by its developer in over a year is a liability; replace it.
- Weak or reused admin passwords, with no two-factor authentication.
- Too many administrators. A contractor from three years ago probably still has an account. Audit your user list and demote anyone who does not need full access.
- Stacked security plugins. Running two or three at once does not multiply protection — it creates conflicts, slows the site, and makes it hard to tell what is blocking what. Pick one, configure it properly, leave it.
If a compromise started with a phishing email rather than a plugin, our guide to spotting phishing before it costs you anything covers that side. We maintain WordPress sites for small businesses across Manhattan — updates, backups, and the monitoring that catches problems before they become outages.
On-site and remote tech support for homes and small businesses across the Upper West Side and Manhattan.
Book a consultation (844) 915-4004
We value your opinion. If we have helped you, a quick review means a lot — leave one on Google. Thank you.
