Skip to content
Will your site survive Black Friday? Free peak-readiness audit →
SECURITY

WordPress security checklist: 15 steps to protect your site in 2026

A practical WordPress and WooCommerce security checklist: updates, plugins, logins, file permissions, WAF, backups and monitoring.

By VISIBI Security team·Reviewed by Saeed Ak, Co-founder & CTO·Updated 29 September 2026·9 min read
QUICK ANSWER

A practical WordPress and WooCommerce security checklist: updates, plugins, logins, file permissions, WAF, backups and monitoring.

KEY TAKEAWAYS
✓Most WordPress hacks come from outdated or abandoned plugins.
✓Two-factor authentication and login limits stop most brute-force attacks.
✓A cloud WAF blocks attacks before they reach WordPress.
✓Tested off-site backups turn a disaster into a minor inconvenience.

Why WordPress sites get hacked

WordPress core is well maintained; most compromises come from vulnerable plugins and themes, weak passwords and poor hosting. Attackers use automated scanners, so small sites are targeted as often as big ones.

RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud →

The checklist

  • Keep WordPress core, themes and plugins updated (test on staging first)
  • Delete unused, abandoned and nulled plugins and themes
  • Enforce strong passwords and two-factor authentication for all admins
  • Limit login attempts and consider moving /wp-login.php
  • Disable XML-RPC if you don’t need it
  • Disable file editing in the dashboard (DISALLOW_FILE_EDIT)
  • Set correct file permissions (644 files, 755 folders, 600/640 wp-config.php)
  • Use unique salts and a non-default database prefix
  • Put the site behind a cloud WAF such as Cloudflare or Sucuri
  • Force HTTPS everywhere
  • Run daily off-site backups and test restores
  • Use PHP 8.2+ and a host that isolates sites
  • Give users the lowest role they need
  • Monitor file changes and uptime
  • Scan regularly for malware and blocklisting
Want this done for you?We harden WordPress and WooCommerce and keep them patched every month.Get a free WordPress security scan →

Extra steps for WooCommerce

Online stores are a bigger target. Protect checkout from card testing with reCAPTCHA and gateway fraud tools, block fake account registrations, and keep payment plugins updated immediately when security releases appear.

What to do if you are hacked

Put the site into maintenance mode, change all passwords, restore a clean backup or have the infection professionally removed, then patch whatever let the attacker in. Request a review in Google Search Console if you were flagged.

Common mistakes to avoid

✕Waiting until after a breach to act
✕Restoring a backup without fixing the entry point
✕Leaving old plugins, extensions and admin users in place
✕Relying on a single tool instead of layered defences
HOW VISIBI CAN HELP

How we help with security

01ScanFree scan for malware, vulnerabilities and blocklisting.
02Clean & patchEngineers remove threats and close the entry point.
03HardenWAF, 2FA, least privilege and platform hardening.
04MonitorContinuous scanning with unlimited cleanups on our plans.
Get a free WordPress security scan →Free · No obligation · Reply within 24 hours

Frequently asked questions

Is a security plugin enough?

It helps, but updates, hardening, backups and a cloud WAF stop far more attacks than a plugin alone.

How often should I update WordPress?

Apply security updates as soon as possible; test feature updates on staging weekly or fortnightly.

Is WordPress secure for ecommerce?

Yes, when properly hardened, hosted and maintained.

SA
Reviewed by Saeed Ak · Co-founder & CTO25 years engineering high-traffic ecommerce, cloud and security platforms. Written by the VISIBI Security team.Meet the team →
Was this guide helpful?
Share:LinkedInXEmail
RELATED SERVICES

Keep reading

SECURITY · 9 MINHow to stop spam and bot attacks on Adobe Commerce CloudRead →SECURITY · 8 MINMagecart and card skimming: how to protect your checkoutRead →SECURITY · 7 MINMy website has been hacked — what should I do?Read →
FREE · NO OBLIGATION

Want this done for you?

We harden WordPress and WooCommerce and keep them patched every month.

Get a free WordPress security scan →Talk to a specialist
✓ Senior specialist, not a bot✓ Reply within 24 hours✓ Clients in 18 countries
SECURITY SCAN PREVIEWEXAMPLE
What attackers can see right now
Unpatched vulnerabilities6
Unknown checkout scripts2
Blocklist statusClean
Your free review shows your real numbers.