10 Simple WordPress Security Measures

Well … it eventually had to happen!

When you are the world’s most popular content management system and the preferred online publishing platform for over 60 million websites around the world, used by millions of businesses and loved by thousands of  web developers and web designers, it’s inevitable that, at some point, WordPress will come under attack from hackers wanting to score a “big win”.

In early April 2013 a global “brute-force” attack began hitting WordPress installations across virtually every web host in existence around the world using botnets.

A “Botnet” is a network of private computers that has been infected with malicious software, which is then controlled remotely as a group, typically without the computer owners’ knowledge. Botnets are often used to send mass spam emails.

Below is a screenshot taken from an Internet Security monitoring site showing the locations of the command centers of ZeuS – a botnet that has been actively infecting computer networks all around the globe since 2009 …

How To Prevent Your WordPress Site From Being Attacked

The ongoing botnet attacks on WordPress are well-organized and highly-distributed. Over 90,000 IP addresses were identified by a number of webhosting companies just in the initial attack, when the web was flooded with millions of attempts to force their way into WordPress users administration areas. At the height of the attack, over 30,000 WordPress sites were being hacked per day.

News of the April mass brute-force botnet attack was reported by all of the major webhosting companies, as well as the leading technology publications, such as Forbes, TechNews Daily, PC Magazine, Tech Crunch, BBC News, and even on the official website of the US Department of Homeland Security …

How To Prevent Your WordPress Site From Being Attacked

10 Simple Steps to Prevent Hacking

If your website is powered by WordPress and you’re not taking steps to harden your site, it’s practically guaranteed that your site will be hacked, or at least targeted by bots, because these attacks are systematically targeting WordPress sites around the world!

Typically, whenever a site is hacked, website owners will discover much to their dismay that they have been “locked out” of their own site, or that their content has been vandalized or even entirely wiped out. Often, sites will be infected with malicious software without the owner’s knowledge.

To help avoid the heartache of having your site being hacked into, we have gathered 10 simple, yet essential steps that will help to protect your WordPress site from brute force attacks.


Note: Some of the steps listed below require some technical understanding of how to modify core WordPress and server files. If you are not technical, or don’t want to mess around with code on your site, then please contact us.

1 – Contact Your Web Host

Contact your webhosting provider and ask them exactly what they have put into place to help prevent your site from being attacked, and what they are doing to ensure that your WordPress sites are being regularly backed up. Check that your host is backing up your sites and that, if anything happens, you can easily get your site back.

2 – BackUp Your WordPress Data And Files And Keep Your Site Regularly Maintained

You should never rely only on your webhost for your site backups. Instead, learn how to maintain and manage your WordPress site and develop a habit of performing a complete WordPress site maintenance routine on a regular basis (e.g. weekly, monthly, etc …). See the list of routines we recommend, or purchase a quarterly maintenance package. We also recommend the plugin WP Database (for database backups).

3 – Make Sure That Your User Name Is Not “Admin”

The mass brute-force botnet attack on WordPress is mostly attempting to compromise websites’ administrator panels by exploiting hosts with “admin” as their account name. If your site’s username is “admin” you need to change this immediately.

The simplest way to fix this issue is to create a new User account with administrator privileges. Make sure your new username is not obvious and choose a very strong password (see next section below).

1. Under Users tab, create a new user with an uncommon username. Assign administrator privileges.

2. Select a strong password.

3. Log out.

4. Log in as the new administrator.

5. Under Users tab, delete the “admin” user.

4 – Change Your Password

A “brute force” attack occurs when malicious software hits a password field with different strings of characters in an attempt to guess the right combination.

Unless some measure is put into place to block the brute force attack (see further below for a simple and effective way to do this), the “bot” will just keep attacking your site until it eventually “cracks” the code.

Weak passwords are very easy targets for brute force attack methods. Make sure, therefore, that you change your password to something that is at least eight characters long, and that includes upper and lowercase letters, and “special” characters (^%$#&@*).

If you have trouble coming up with strong passwords or feel reluctant to set up different passwords for all of your online logins, then use a password management tool like LastPass.

5 – Prevent the wp-config.php file from being accessed

If a hacker breaks into your site, they will look for the wp-config.php file, because this is the file that contains your WordPress database details.

To prevent the wp-config.php file from being accessed, insert the following code into your .htaccess file:

How To Prevent Your WordPress Site From Being Attacked

Note: Editing your .htaccess file can seriously mess up your site. Make sure that your site is fully backed up before you modify any system files. If you don’t know what you’re doing please contact us.

6 – Rename or delete your install.php, upgrade.php and readme.html files

These files are completely unnecessary after installation and can be removed. If you don’t want to delete these files, then just rename them.

7 – Upgrade your WordPress installation, plugins and themes to their latest version

Hackers look for vulnerabilities they can exploit in older versions of WordPress, including outdated versions of WordPress plugins and themes. Ensure that all of your WordPress files, plugins, themes etc. are always up to date.

8 – Disable Your WordPress Theme Editor

When you log into WordPress, you can access your WordPress Theme Editor (by selecting Appearance > Editor) from the dashboard menu. This means that anyone who logs into your site can see all of your WordPress files and make changes or cause havoc on your site.

The WordPress Theme Editor can be easily disabled by adding the line of code below to your wp-config.php file:

How To Prevent Your WordPress Site From Being Attacked

Once again, please don’t modify any files on your site if you don’t know what you are doing and always backup your data before making changes. See our recommended solution further down the page if you need help with this step.

9 – Remove Access To Your WordPress Uploads Folder

The “uploads” folder stores all the media that gets uploaded to your WordPress site. By default, this folder is visible to anyone online.

Adding the line below to your .htaccess file will prevent online users from viewing your Uploads folder:

How To Prevent Your WordPress Site From Being Attacked

It’s worth repeating this warning once again: back up your site before making changes to core files and don’t edit files if you don’t know what you are doing.

Useful Tip

Tip: You can add a blank “index.php” file into any directory that you don’t want people to look into. This will display a blank page to visitors. (The downside to this method is that you have to add a blank “index.php” file into every folder that has content or files you don’t want people to access.)

10 – Use WordPress Security Plugins

Currently, a number of WordPress security plugins are available that address many of the common security issues that most WordPress website owners face (e.g. preventing hackers from accessing your site, protecting your site from malicious software, etc …)

We provide detailed WordPress step-by-step tutorials to our clients on all aspects of using WordPress, and these also include tutorials on WordPress security.

Many WordPress plugins address some but not all areas of WordPress security. One WordPress security plugin that seems to do a comprehensive job of scanning, fixing and preventing issues that could lead to hackers accessing your site files and damaging your site is Better WP Security.

Better WP Security is easy to install and easy to use, and does a great job of addressing most of the security areas and fixing the issues that WordPress users need to address.

For more details, visit this website: Better WP Security.

What Doesn’t Kill You Makes You Stronger

As cybercrime grows worldwide and cybercriminals develop more sophisticated mass methods to identify and exploit vulnerabilities online, WordPress security is becoming increasingly more important. Hackers range from individuals who carry out attacks on sites out of curiosity, for entertainment, or to earn “bragging rights” with their peers, all the way to sophisticated, co-ordinated and highly organized criminal networks and cyberterrorists.

As stated earlier, WordPress is a target for hackers because it is the most widely used platform for publishing websites and managing content online. We have covered some of the steps you can take to protect your WordPress site, now let’s take a quick look at why you should still consider using WordPress if you are currently looking to start your own website.

There are some people who argue that WordPress is not the most secure platform for running a website or blog because it is “open source” (i.e. free), which means that hackers can easily access the software to find and exploit holes and weaknesses in its coding and security.

While it’s true that WordPress is free and hackers can easily access it and study the code for weaknesses and vulnerabilities (hackers can do the same with any program), the fact that WordPress is a free, open platform makes it actually more secure in many ways.

The reason for this is that WordPress has the support of a huge community of thousands of people such as software programmers, plugin developers and theme designers who are constantly working to help improve the program.

WordPress evolves through the effort of a huge community and benefits from thousands of minds who are dedicated to improving the software and making it safer for every user. As soon as an issue, weakness, vulnerability or problem is discovered, therefore, it is almost immediately reported to the software creators and addressed by the WordPress development team. This is why WordPress releases new security updates so often, and why you need to keep your WordPress site constantly updated and maintained.

Contrast the above with other proprietary web development platforms and technologies which are developed by one company with a limited number of employees, and whose updates are therefore much less frequent, and you will quickly realize the value and advantages of using WordPress to power your website or blog.

Like many modern software packages, WordPress is updated regularly to address new security issues that may arise. Improving software security is always an ongoing concern, and to that end – and as we have been stressing throughout this article – you should always keep up to date with the latest version of WordPress. Older versions of WordPress are not maintained with security updates.

And just one last thing …

It’s important to note that in the case of this recent mass brute-force botnet attack there is actually no WordPress vulnerability being exploited (the same script is also attacking Joomla sites).

In a recent interview, Mike Little – the co-founder of WordPress with Matt Mullenweg, said the following about the attacks:

It is a “simple” script that attempts to login using the admin login and a generated password. So if your password is too short or based on dictionary words it will be guessed and then the script can login legitimately and do whatever it wants including installing scripts (as plugins) or editing files. The attack tries to guess your password, if it succeeds, the most secure site in the world is wide open because they have your password.

Hopefully this information will help to keep your site protected. Please contact us if you need any further help or assistance with WordPress security issues.



  1. says

    Hello Cathy,
    I must say attack has increased, even my site got hacked on April 2013, and i must say most of the site get hack because of the admin mistake, like what i had done.

    I got so lazy that i never clicked the update button, and finally one day i started working when my site got hacked,

    You got really very nice and in depth post but i would like to suggest to our readers that keep the password between 15 to 17 character, containing upper and lowercase, Symbol and Number.
    even by keeping a 15 character password of just number and character chances of getting hack is very high.

    Even Plugins are one way for hackers to gain access, so it is good only for newbie and some one if have even a small knowledge must secure manually,

    As well connecting site with webmaster tool, it will notify when any malware is detected,

    Finally never be lazy when it comes to your website security *link removed*.


Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>