Most hacked WordPress sites aren’t compromised through some sophisticated attack — they’re compromised through an outdated plugin, a weak password, or no backup to recover from once something goes wrong. These basics cover the large majority of real-world risk.

Not sure your WordPress site is actually protected? We audit, lock down, and maintain sites for small businesses in Manhattan. Get Human Help →

1. Keep WordPress core, themes, and plugins updated

Nearly every major WordPress compromise traces back to a known, already-patched vulnerability in an outdated plugin or theme. Check the Updates screen in wp-admin regularly, and remove plugins you’re not actually using — an inactive plugin can still be a security hole if it’s not updated, and every unnecessary plugin is one more thing that can break or be exploited.

2. Use strong, unique admin credentials

Never use “admin” as a username — it’s the first guess in every automated attack. Use a long, unique password (a password manager makes this painless), and enable two-factor authentication for wp-admin login through a security plugin or your host’s built-in option. Automated bots scan for weak WordPress logins constantly; this alone stops the vast majority of attacks.

3. Have a real, working backup

A backup should cover both the database (your posts, pages, settings) and the files (theme, plugins, uploads/media), stored somewhere other than the same server the site lives on. Many hosts include automatic backups — confirm yours actually does, how far back it goes, and that you know how to trigger a restore before you need one in an emergency, not during one.

4. Limit login attempts

By default, WordPress allows unlimited login attempts, which is exactly what automated brute-force bots rely on. A security plugin or host-level setting that locks out an IP after a handful of failed attempts closes this off almost entirely.

5. Keep an eye on file changes

A security plugin that alerts on unexpected file changes (new files appearing in your theme folder, core files being modified) catches a compromise early, before it spreads or gets noticed by visitors — often well before Google flags the site for malware, which can hurt search rankings.

6. Use HTTPS everywhere, and keep your SSL certificate current

Most hosts now provide free, auto-renewing SSL certificates (Let’s Encrypt), so there’s rarely a reason to run a WordPress site without HTTPS. Beyond the padlock icon, this also protects login credentials in transit and is a baseline requirement for good SEO.

If a site does get compromised

Restore from a known-clean backup rather than trying to manually hunt down every injected file — it’s faster and far more reliable. Then change every password associated with the site (WordPress admin, hosting account, database, FTP) before bringing it back online, since the entry point is often a leaked or weak credential rather than the vulnerability itself.

Backups must live somewhere else

A backup stored on the same server as the site is not a backup. If the server is compromised, encrypted, or suspended by the host, both go together. Whatever plugin you use, send copies offsite — a separate cloud account is fine — and confirm they are actually arriving. A backup plugin reporting success while writing to a full or disconnected destination is a common and quiet failure.

Restore one to a staging site once a year. Same principle as any other backup: untested means unproven. Our guide to backing up properly covers the same logic for the machines in your office.

What actually causes incidents

Nearly every compromised small-business WordPress site we see comes down to the same short list:

  • Out-of-date plugins. Most attacks target known vulnerabilities in old versions, automatically, at scale. Updating promptly prevents the large majority.
  • Abandoned plugins. Anything not updated by its developer in over a year is a liability; replace it.
  • Weak or reused admin passwords, with no two-factor authentication.
  • Too many administrators. A contractor from three years ago probably still has an account. Audit your user list and demote anyone who does not need full access.
  • Stacked security plugins. Running two or three at once does not multiply protection — it creates conflicts, slows the site, and makes it hard to tell what is blocking what. Pick one, configure it properly, leave it.

If a compromise started with a phishing email rather than a plugin, our guide to spotting phishing before it costs you anything covers that side. We maintain WordPress sites for small businesses across Manhattan — updates, backups, and the monitoring that catches problems before they become outages.

TECH SUPPORT NYC
Technology for a better tomorrow · Proudly serving Manhattan
Need hands-on help?

On-site and remote tech support for homes and small businesses across the Upper West Side and Manhattan.

Book a consultation (844) 915-4004

We value your opinion. If we have helped you, a quick review means a lot — leave one on Google. Thank you.

382 Central Park West, New York, NY 10025 · Mon–Fri 8am–5pm · Local. Reliable. Here to help. — techsupportnyc.com