Over 40% of the web runs on WordPress – which is exactly why bots probe it for weaknesses around the clock. With the right measures your login becomes a hard target. Here's the concrete checklist, plus hands-off hardening by us if you want it.
You make a WordPress site secure with strong passwords plus 2FA, prompt updates of core, themes and plugins, a hardened login, tested backups, plus HTTPS and monitoring. Forge12 provides WordPress hardening and ongoing maintenance – updates, backups, monitoring and security from €59/month – plus emergency clean-up after a hack.
Most hacked WordPress sites aren't targeted deliberately – they're caught by automated bots that hammer known vulnerabilities, weak passwords and outdated plugins day and night.
The good news: that's exactly why basic hardening pays off disproportionately. Get login, updates, backups and monitoring right and you drop out of the mass-attack pattern – no expensive niche product required.
The eight levers with the best effort-to-impact ratio – in this order.
A unique random password per account (use our password generator) and two-factor authentication on every admin login. Never use "admin" as the username.
Update WordPress core, themes and plugins promptly – outdated extensions are the single most common way in.
Fully remove unused plugins and themes (not just deactivate them). Every extension is extra attack surface.
Limit login attempts, protect /wp-admin and wp-login.php, restrict XML-RPC – so brute-force and bot attacks run into a wall.
Automated backups to an off-site location – and test the restore regularly. A backup you've never restored isn't a backup.
End-to-end HTTPS, sensible security headers and a Web Application Firewall (WAF) filter out most malicious traffic before it reaches WordPress.
Watch file integrity, malware and uptime – so you learn about a problem before your visitors (or Google) do.
A current PHP version, reputable hosting and correct file permissions (least privilege). Even the best hardening means little on a shaky foundation.
Already hacked?
If your site is already compromised, the priority is fast clean-up – not hardening.
If you'd rather not handle it yourself: we take over updates, backups, monitoring, malware protection and hardening as ongoing WordPress maintenance – with a dedicated contact and fast help when it counts.
Almost all attacks run automatically through known weaknesses. Knowing the attack surfaces lets you close them deliberately — which is exactly what the checklist above does.
Bots try thousands of passwords against wp-login.php around the clock. Without a login limit and 2FA a weak password is cracked in minutes.
By far the most common gap: known weaknesses in un-updated extensions — publicly documented and exploited en masse.
Known from data leaks or easy to guess. Without a second factor, a single leaked password is enough for takeover.
Rarely used, often active interfaces get abused for brute-force amplification and DDoS. Whatever isn't needed should be switched off.
Outdated server software or infected neighbour sites in the same account. Weak hosting undermines any WordPress hardening.
No safety net when it breaks — and every open gap stays open. The quietest mistake, with the biggest damage in an emergency.
The terms that keep coming up with WordPress security — explained in one sentence.
A second factor at login in addition to the password (app code, hardware key). Makes leaked passwords practically worthless.
Filters malicious requests before they reach WordPress — blocks automated attacks, brute force and known exploits.
Automated trying of thousands of passwords until one fits. Countermeasures: login limit, strong passwords, 2FA.
HTTP headers (e.g. HSTS, CSP, X-Frame-Options) that instruct the browser to block attacks like clickjacking and XSS.
Encrypts the transfer between browser and server. Protects logins and data in transit — mandatory, but not a hack shield on its own.
Random values in wp-config.php that secure login cookies. Regenerate them regularly, especially after a suspected breach.
The most effective steps: strong, unique passwords plus 2FA, keep core/themes/plugins updated, remove unused extensions, harden the login (login limit, protect wp-admin), keep regular tested backups, and enable HTTPS, security headers and monitoring. The full order is in the checklist above.
A security plugin helps but doesn't replace clean baseline hardening. Current updates, strong passwords, tested backups and secure hosting matter more than any single plugin. Best is to combine both.
Security is not a one-off project but ongoing operations: updates and backups should run at least weekly, monitoring continuously. That's exactly what our WordPress maintenance is for.
Typical signs: unknown admin accounts, strange redirects, spam content, Google/browser warnings, a sudden performance drop. If in doubt, our WordPress emergency help handles fast clean-up.
Yes. As part of WordPress maintenance we harden the site, keep it updated, monitor it and stay reachable when it matters – senior-led, with a dedicated contact.
The WordPress core itself is solid and actively maintained. Almost all hacks run not through the core but through outdated plugins/themes, weak passwords and missing updates. In short: WordPress is as secure as it is maintained — with the measures from the checklist above it becomes a hard target.
A web application firewall filters malicious requests before they reach WordPress — it blocks a large share of automated attacks and brute-force attempts. Worth it, yes, but not a replacement for updates, strong passwords and backups. The combination is most effective.
2FA requires a second factor at login in addition to the password (e.g. a code from an app). Even if your password is leaked, the attacker can't get in. 2FA is the single most effective protection against login attacks — strongly recommended for every admin account.
Only partly. HTTPS encrypts the transfer between browser and server (important for logins and data), but it doesn't prevent a hack via a plugin gap or a weak password. HTTPS is mandatory — but one building block, not all-round protection.
Builders take updates off your hands but restrict you heavily and you hand over control of your data. A maintained WordPress is just as secure — with full flexibility. The difference isn't »secure vs. insecure«, it's »maintained vs. not maintained«.
The one-off professional hardening (security setup) starts at €490 — incl. login protection, 2FA, firewall, backup strategy and a security report. Ongoing protection (updates, monitoring, tested backups) runs via WordPress maintenance from €59/month. Details in the pricing section below.
A one-off, thorough hardening of your installation. The basics are secure afterwards — for ongoing protection, add a Care plan on top.
Over 90% of hacks run automatically through outdated plugins. For lasting protection we recommend an ongoing Care plan after the setup (updates, monitoring, tested backups).
Work beyond the fixed price is agreed in advance — never a surprise invoice. External costs (hosting, paid plugin/theme licenses) are borne by the client.
Site already compromised? Manual emergency cleanup at a fixed price — malware out, entry point closed.
Checked updates, monitoring and tested backups in one package — security as continuous operation, not a one-off.
White screen, login trouble, a broken update? We get your site running again fast.