All posts

How to Secure a WordPress Website: 10 Steps to Protect Against Hacks and Malware

WordPress core had only 6 reported vulnerabilities in 2025. Its plugins had over 10,000. Here's why almost every WordPress hack is actually preventable, and the 10 steps that stop the vast majority of them.

10 min read
websites & growthwordpresswebsite securitycybersecuritysmall business websitesweb designwordpress maintenance

Around 13,000 WordPress sites get hacked every day. That number sounds like an indictment of WordPress itself, until you look at where the actual weaknesses are: WordPress core accounted for roughly 6 of the 11,334 new vulnerabilities discovered across the ecosystem in 2025. The other 99.9% came from plugins and themes. This isn't a WordPress problem so much as a maintenance problem, and it's one that basic security hygiene stops in roughly 90% of cases.


The Real Numbers Behind WordPress Security

WordPress runs about 43.5% of all websites, making it the largest single target on the internet purely by volume. Patchstack's 2026 whitepaper found 11,334 new vulnerabilities disclosed across the WordPress ecosystem in 2025, and 91-96% of those originated in plugins rather than core software.

The speed of exploitation is critical: the median time from a vulnerability's public disclosure to its first real-world exploitation is about 5 hours. Automated bots scan the internet constantly for newly disclosed flaws, so manual updates can be too slow. Furthermore, 46% of vulnerabilities have no available patch at the moment they're disclosed, and 43% can be exploited without any login credentials at all.


What a Hack Actually Costs

Estimates put the average recovery cost for a small business after a WordPress hack around $14,500, factoring in cleanup, downtime, reputational damage, and potential compliance issues. Compare that to the cost of prevention: a solid WordPress security plugin runs somewhere between free and roughly $150-230/year.

Most hacked sites aren't defaced with an obvious message. The more common outcome is quieter: injected scripts, spam redirects, or SEO spam served invisibly to search engines while the site looks completely normal to a human visitor (read why poor migrations drop traffic).


The 10 Steps That Actually Matter

  1. Keep WordPress core, themes, and plugins updated automatically where possible. Given the 5-hour median exploitation window, enable automatic updates for minor releases at minimum.
  2. Audit your plugin list and remove anything inactive or unnecessary. The average production site runs 30+ plugins. If you haven't used a plugin in months, deactivate and delete it — deactivated plugin code can still be exploited.
  3. Install a dedicated WordPress security plugin. Wordfence's free tier includes a firewall, malware scanner, and two-factor authentication; Sucuri is another strong alternative.
  4. Turn on two-factor authentication (2FA) for every admin account. With 81% of hacked sites involving weak or stolen passwords, 2FA is a top-leverage defense.
  5. Change the default login URL. Automated attacks overwhelmingly target `/wp-login.php` and `/wp-admin`. Moving your login page filters out automated bots.
  6. Enforce strong, unique passwords and limit login attempts. Rate-limiting login attempts closes off brute-force attack vectors.
  7. Set up automated, offsite backups. If a security tool ever misses something, a recent offsite backup turns a disaster into a quick restore.
  8. Use a Web Application Firewall (WAF). A WAF filters malicious traffic before it reaches WordPress, protecting against pre-authentication exploits.
  9. Only install plugins and themes from reputable sources. Avoid nulled (pirated) premium plugins, which are a primary vector for malware.
  10. Monitor file integrity and get alerted to changes. Receive instant alerts whenever core, theme, or plugin files are modified unexpectedly.

Security Plugin Comparison

PluginFree tier includesPaid tierBest for
WordfenceFirewall, malware scanner, 2FA, login security~$149/yearMost small business sites; strongest free tier
SucuriHardening checklist, remote scanner~$199-229/yearCloud WAF + CDN, hack cleanup services
All In One Security (AIOS)Firewall, hardening, brute-force protectionFreeBudget-conscious, beginner-friendly setups
MalCareUptime monitoring, basic scanningPaid plans add 1-click cleanupFast malware cleanup

Reality Check: Is Your Maintenance Sustainable?

If your site was compromised recently, the issue usually isn't bad luck — it's that your setup doesn't match the ongoing attention WordPress requires.

Brandywebs builds and hardens WordPress sites properly from the start, and can audit existing security gaps — custom builds start from $999 (read custom website cost breakdown).

Get a free quote from Brandywebs →


FAQs

Why do WordPress sites get hacked so often? Mostly because of outdated or vulnerable plugins, not WordPress core itself. Roughly 91-96% of disclosed vulnerabilities originate in plugins and themes.

Is WordPress actually less secure than other website platforms? Not inherently. Its massive market share (43.5%) makes it the largest target in raw volume, but a well-maintained WordPress site with minimal plugins is secure.

How do I know if my WordPress site has been hacked? Common signs include unexpected redirects, unfamiliar admin users, changed files flagged by a security scanner, sudden drops in search rankings, or host notifications.

What's the best free WordPress security plugin? Wordfence's free tier is widely regarded as the strongest, offering a firewall, malware scanner, and two-factor authentication at no cost.

How much does it cost to fix a hacked WordPress site? Average small business recovery costs land around $14,500 once downtime, cleanup, and reputational impact are calculated — far more than prevention costs ($0-$230/year).

Does changing my login URL actually stop hackers? It stops the vast majority of automated bot attacks targeting the default `/wp-login.php` path.

Do I need both a firewall plugin and my host's built-in security? Yes. Generic hosting defenses block only 12-26% of WordPress-specific exploit attempts, so a dedicated WordPress firewall adds necessary protection.

How often should I update WordPress plugins and themes? As soon as security patches are released. Enabling automatic updates for minor releases and inspecting major updates weekly is a recommended baseline.

Ready when you are

Want us to help you ship this in your business?