WordPress security checklist: 15 steps to protect your site in 2026
A practical WordPress and WooCommerce security checklist: updates, plugins, logins, file permissions, WAF, backups and monitoring.
A practical WordPress and WooCommerce security checklist: updates, plugins, logins, file permissions, WAF, backups and monitoring.
Why WordPress sites get hacked
WordPress core is well maintained; most compromises come from vulnerable plugins and themes, weak passwords and poor hosting. Attackers use automated scanners, so small sites are targeted as often as big ones.
RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud →The checklist
- Keep WordPress core, themes and plugins updated (test on staging first)
- Delete unused, abandoned and nulled plugins and themes
- Enforce strong passwords and two-factor authentication for all admins
- Limit login attempts and consider moving /wp-login.php
- Disable XML-RPC if you don’t need it
- Disable file editing in the dashboard (DISALLOW_FILE_EDIT)
- Set correct file permissions (644 files, 755 folders, 600/640 wp-config.php)
- Use unique salts and a non-default database prefix
- Put the site behind a cloud WAF such as Cloudflare or Sucuri
- Force HTTPS everywhere
- Run daily off-site backups and test restores
- Use PHP 8.2+ and a host that isolates sites
- Give users the lowest role they need
- Monitor file changes and uptime
- Scan regularly for malware and blocklisting
Extra steps for WooCommerce
Online stores are a bigger target. Protect checkout from card testing with reCAPTCHA and gateway fraud tools, block fake account registrations, and keep payment plugins updated immediately when security releases appear.
What to do if you are hacked
Put the site into maintenance mode, change all passwords, restore a clean backup or have the infection professionally removed, then patch whatever let the attacker in. Request a review in Google Search Console if you were flagged.
Common mistakes to avoid
How we help with security
Frequently asked questions
Is a security plugin enough?
It helps, but updates, hardening, backups and a cloud WAF stop far more attacks than a plugin alone.
How often should I update WordPress?
Apply security updates as soon as possible; test feature updates on staging weekly or fortnightly.
Is WordPress secure for ecommerce?
Yes, when properly hardened, hosted and maintained.