WordPress security

Secure your WordPress

Over 40% of the web runs on WordPress – which is exactly why bots probe it for weaknesses around the clock. With the right measures your login becomes a hard target. Here's the concrete checklist, plus hands-off hardening by us if you want it.

In short

You make a WordPress site secure with strong passwords plus 2FA, prompt updates of core, themes and plugins, a hardened login, tested backups, plus HTTPS and monitoring. Forge12 provides WordPress hardening and ongoing maintenance – updates, backups, monitoring and security from €59/month – plus emergency clean-up after a hack.

0%
of all websites worldwide run on WordPress – a popular target
0%
of WordPress hacks run automatically through outdated plugins
0
hardening steps take your WordPress out of the mass-attack pattern

Why WordPress security can't be left to chance

Most hacked WordPress sites aren't targeted deliberately – they're caught by automated bots that hammer known vulnerabilities, weak passwords and outdated plugins day and night.

The good news: that's exactly why basic hardening pays off disproportionately. Get login, updates, backups and monitoring right and you drop out of the mass-attack pattern – no expensive niche product required.

Checklist: how to secure WordPress

The eight levers with the best effort-to-impact ratio – in this order.

01

Strong, unique passwords + 2FA

A unique random password per account (use our password generator) and two-factor authentication on every admin login. Never use "admin" as the username.

02

Keep everything up to date

Update WordPress core, themes and plugins promptly – outdated extensions are the single most common way in.

03

Less is more

Fully remove unused plugins and themes (not just deactivate them). Every extension is extra attack surface.

04

Harden the login

Limit login attempts, protect /wp-admin and wp-login.php, restrict XML-RPC – so brute-force and bot attacks run into a wall.

05

Regular, tested backups

Automated backups to an off-site location – and test the restore regularly. A backup you've never restored isn't a backup.

06

HTTPS, security headers & firewall

End-to-end HTTPS, sensible security headers and a Web Application Firewall (WAF) filter out most malicious traffic before it reaches WordPress.

07

Monitoring & malware scanning

Watch file integrity, malware and uptime – so you learn about a problem before your visitors (or Google) do.

08

A secure base: hosting, PHP & permissions

A current PHP version, reputable hosting and correct file permissions (least privilege). Even the best hardening means little on a shaky foundation.

Already hacked?

If your site is already compromised, the priority is fast clean-up – not hardening.

Go to WordPress emergency help →

WordPress security as a service

If you'd rather not handle it yourself: we take over updates, backups, monitoring, malware protection and hardening as ongoing WordPress maintenance – with a dedicated contact and fast help when it counts.

See maintenance & securityPassword generator
Threats

How WordPress gets attacked

Almost all attacks run automatically through known weaknesses. Knowing the attack surfaces lets you close them deliberately — which is exactly what the checklist above does.

Brute-force login

Bots try thousands of passwords against wp-login.php around the clock. Without a login limit and 2FA a weak password is cracked in minutes.

Outdated plugins & themes

By far the most common gap: known weaknesses in un-updated extensions — publicly documented and exploited en masse.

Weak & reused passwords

Known from data leaks or easy to guess. Without a second factor, a single leaked password is enough for takeover.

XML-RPC & open interfaces

Rarely used, often active interfaces get abused for brute-force amplification and DDoS. Whatever isn't needed should be switched off.

Insecure / shared hosting

Outdated server software or infected neighbour sites in the same account. Weak hosting undermines any WordPress hardening.

Missing backups & updates

No safety net when it breaks — and every open gap stays open. The quietest mistake, with the biggest damage in an emergency.

Glossary

Security — in brief

The terms that keep coming up with WordPress security — explained in one sentence.

2FA (two-factor authentication)

A second factor at login in addition to the password (app code, hardware key). Makes leaked passwords practically worthless.

WAF (web application firewall)

Filters malicious requests before they reach WordPress — blocks automated attacks, brute force and known exploits.

Brute force

Automated trying of thousands of passwords until one fits. Countermeasures: login limit, strong passwords, 2FA.

Security headers

HTTP headers (e.g. HSTS, CSP, X-Frame-Options) that instruct the browser to block attacks like clickjacking and XSS.

SSL / TLS (HTTPS)

Encrypts the transfer between browser and server. Protects logins and data in transit — mandatory, but not a hack shield on its own.

Salts / security keys

Random values in wp-config.php that secure login cookies. Regenerate them regularly, especially after a suspected breach.

FAQ

Frequently asked questions about WordPress security

01How do I make my WordPress website secure?

The most effective steps: strong, unique passwords plus 2FA, keep core/themes/plugins updated, remove unused extensions, harden the login (login limit, protect wp-admin), keep regular tested backups, and enable HTTPS, security headers and monitoring. The full order is in the checklist above.

02Is a security plugin enough?

A security plugin helps but doesn't replace clean baseline hardening. Current updates, strong passwords, tested backups and secure hosting matter more than any single plugin. Best is to combine both.

03How often do I need to deal with security?

Security is not a one-off project but ongoing operations: updates and backups should run at least weekly, monitoring continuously. That's exactly what our WordPress maintenance is for.

04How can I tell my site was hacked?

Typical signs: unknown admin accounts, strange redirects, spam content, Google/browser warnings, a sudden performance drop. If in doubt, our WordPress emergency help handles fast clean-up.

05Can you handle securing it entirely?

Yes. As part of WordPress maintenance we harden the site, keep it updated, monitor it and stay reachable when it matters – senior-led, with a dedicated contact.

06Is WordPress even secure?

The WordPress core itself is solid and actively maintained. Almost all hacks run not through the core but through outdated plugins/themes, weak passwords and missing updates. In short: WordPress is as secure as it is maintained — with the measures from the checklist above it becomes a hard target.

07Do I need a firewall (WAF) for WordPress?

A web application firewall filters malicious requests before they reach WordPress — it blocks a large share of automated attacks and brute-force attempts. Worth it, yes, but not a replacement for updates, strong passwords and backups. The combination is most effective.

08What is two-factor authentication (2FA) — and do I need it?

2FA requires a second factor at login in addition to the password (e.g. a code from an app). Even if your password is leaked, the attacker can't get in. 2FA is the single most effective protection against login attacks — strongly recommended for every admin account.

09Does SSL/HTTPS protect me from hackers?

Only partly. HTTPS encrypts the transfer between browser and server (important for logins and data), but it doesn't prevent a hack via a plugin gap or a weak password. HTTPS is mandatory — but one building block, not all-round protection.

10Is a website builder (Wix, Jimdo) more secure than WordPress?

Builders take updates off your hands but restrict you heavily and you hand over control of your data. A maintained WordPress is just as secure — with full flexibility. The difference isn't »secure vs. insecure«, it's »maintained vs. not maintained«.

11What does it cost to have WordPress secured?

The one-off professional hardening (security setup) starts at €490 — incl. login protection, 2FA, firewall, backup strategy and a security report. Ongoing protection (updates, monitoring, tested backups) runs via WordPress maintenance from €59/month. Details in the pricing section below.

Offer

Secure WordPress — at a fixed price.

A one-off, thorough hardening of your installation. The basics are secure afterwards — for ongoing protection, add a Care plan on top.

Security setup
from €490one-off
Included
  • Hardening of the installation
  • Login protection & two-factor authentication
  • Firewall set up
  • Backup strategy set up
  • Security report with concrete recommendations
Not included
  • Ongoing protection / monitoring (→ Care plan)
  • Cleanup of an already-hacked site (→ Hack recovery)
A one-off hardening isn't ongoing protection.

Over 90% of hacks run automatically through outdated plugins. For lasting protection we recommend an ongoing Care plan after the setup (updates, monitoring, tested backups).

Work beyond the fixed price is agreed in advance — never a surprise invoice. External costs (hosting, paid plugin/theme licenses) are borne by the client.

Request a security setupAll prices net, plus VAT.
WORDPRESS SECURITY

Let's secure your WordPress.