WordPress security is still a popular conversation even after all these years. And the email usually starts the same way: someone has read something alarming, or heard a rumour, or gotten a quote for a $200/month security solution. There’s a lot of noise out there. Let’s discuss!
First: is WordPress actually insecure?
No – but it is a target. Here’s how that matters to you.
WordPress powers over 43% of the entire internet, which makes it the most attractive platform for anyone looking to cause trouble. The logic is simple: if you’re going to exploit something, you exploit the thing that’s everywhere. That’s just what happens if you create something this successful. Kind of like influencers – once you get to a certain popularity, be prepared for the barrage of hate comments! Awful, but only a result of your success.
The flip side of that same popularity is that WordPress has a massive, active developer community constantly reviewing, patching, and improving the software. Open source means thousands of eyes on the code at all times. It’s the opposite of proprietary (where the software is all obfuscated. Open source isn’t perfect, but it does allow for on-the-fly fixes to be delivered constantly.
Here’s the more important number: 96% of WordPress vulnerabilities are found in plugins and themes, not in WordPress core itself. Data from thousands of installations confirms that 92% of all successful WordPress breaches originate from plugins and themes. WordPress core, on its own, is remarkably solid. The problems come when we start adding bits and bobs to it.
Which brings me to the three things that actually keep a site safe. These haven’t changed in 17 years, and I don’t expect they will.
How to Secure Your WordPress Website
1. Keep everything updated.
This is the unglamorous one, but it is the most important one!
When a vulnerability is found in a plugin or theme, a patch is usually issued quickly – but the first automated attacks can appear within five hours of publication. The window between “vulnerability announced” and “bots are taking advantage” is measured in hours, not weeks.
Keeping WordPress, your plugins, and your theme updated closes that window. But updating only covers what you’re actively using. Plugins you installed and forgot about, themes you switched away from, widgets with old ad code sitting in the inactive area – all of that still runs, still has access, and still needs to be updated. If you’re not using it, remove it. If you are using it, update it.
Also worth knowing: in 2024, more than half of plugin developers failed to patch a reported vulnerability before it was publicly disclosed. Reputable developers respond quickly; less reputable ones don’t. Which leads directly to the next point.
2. Be selective about your plugins.
Every plugin you add is a point of entry. Think of your website like a piece of fabric – tight and strong on its own. Every plugin you install cuts a small hole and patches something in. The more patches, the weaker the overall structure. That doesn’t mean plugins are bad; it means they deserve some scrutiny.
A few things I look for:
- Is the plugin actively maintained?
- Has it been updated in the last few months?
- Does it have a meaningful install base?
- Do I recognize and trust the developer?
If the answer to any of these is ‘no’, I keep looking.
I generally recommend keeping your plugin count under 15. Not because it’s some perfect number, but because it forces us to be intentional. Every plugin should be earning its place.
3. Use a strong password.
This one sounds too simple to be worth saying, but brute force attacks- the ones by robots that scan websites- remain one of the most common ways sites get compromised. In 2025, brute force attacks increased by 45%, driven by AI-powered botnets. The bots aren’t guessing cleverly; they’re just fast and relentless.
Here’s how to set the strongest password possible:
Avoid:
- person, place, thing that is mentioned in your wallet or phone – avoid any / all of them
- avoid any word you can find in the English dictionary
- avoid any date that is personal to you.
A strong password is random, long, and uses a mix of letters, numbers, and special characters. Now you can see why we recommend using a password keeper. For example, the passwords for my personal devices and accounts, look like this:
ybfRVl9cw3@VdP@p
There is zero possibility of me remembering that. Ask my kids – I get their names confused. So I use LastPass – there are lots of programs like this – just pick one and use it! Their security is better than most banks. It is safe to store anything you like in a password keeper.
A word about your host.
All of the above assumes you’re on a solid hosting provider. A reputable host keeps its server environment secure and properly isolates accounts from one another. A cut-rate or overcrowded shared host can mean that a breach on someone else’s account becomes your problem too. That’s why we recommend any website that is part of a business, avoid any of the following hosts:
You don’t need to be on an expensive dedicated server, but you do need a host with a real commitment to security. It’s the foundation everything else sits on. (Note: we offer a reputable plan for managed WP Hosting)
The three principles: update everything, choose plugins carefully, use strong passwords, have held up through every shift in the WordPress landscape. The specific threats evolve; the fundamentals don’t. If you’re doing those three things consistently, you’re ahead of the vast majority of sites out there.
New! Welcome-Email AI Agent
Looking at email marketing? Don’t forget a welcome series – folks are 4x more likely to open the first email than any other email that you send! Enter your email and we’ll send you to our custom AI Agent that will help you craft five highly converting emails in a welcome series! Then see this post for the tutorial.

Cathy Mitchell
Single Mom, Volunteer, Lifelong Learner, Jesus Follower, Founder and CEO at WPBarista.
