Start with maintained software, individual accounts, and recoverable backups. Security plugins can provide useful controls, but you still need to review who can sign in and what software runs on your site.
Use WordPress administration to manage WordPress users. The Control Center's Hosting login controls the shared hosting owner, while its WordPress tab only lists tracked applications. Replacing a hosting password does not automatically replace WordPress administrator passwords.
Protect administrator access #
- Give each person their own WordPress account and the lowest role that fits their work. Reserve administrator access for people who manage the installation.
- Use unique generated passwords. Enable multifactor authentication through a maintained, compatible solution if your setup supports it.
- Confirm that administrator recovery email addresses belong to the right people and remain accessible.
- Review users after staff or contractor changes, and remove unnecessary access after deciding how to handle their content.
- Keep hosting and file-transfer credentials separate from routine editing accounts.
WordPress roles determine application capabilities. Someone who can manage hosting files or the database may still have broader practical control than their WordPress role suggests. WordPress roles and capabilities
Maintain software and files #
Obtain WordPress and extensions from official sources or the software publisher. Keep core, themes, and plugins updated, and remove abandoned components. Keep backups outside the public website directory and store a verified copy away from the hosting account.
Use the file ownership and permissions your host requires. Do not grant public write access to solve an update problem. Review unexpected PHP files in upload directories with your developer, and avoid editing core WordPress files as part of ordinary customization. WordPress hardening guide
Verify your protections #
Test recovery access before an emergency. Check that a normal editor cannot administer plugins and that an old contractor's account no longer works. Confirm the public website uses HTTPS without certificate warnings.
If you suspect a compromise #
Record the first observed time, affected URLs, and unexpected accounts or changes. Contact support and preserve relevant logs and a private copy for investigation before mass deletion. From a trusted device, review and rotate affected credentials as part of the recovery plan.
Restoring a backup without fixing the entry point can leave the site vulnerable again. Have your developer or security specialist identify affected components, repair the site, and verify it before restoring public access.
Related: updates and maintenance, website logs.


Leave a Reply