Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

WordPress Security Best Practices

Clear, practical guidance for securing a WordPress site from the first five minutes to advanced operational hardening.

Start Here

If you are new, do this in order:

  1. Read the 5-minute quickstart.
  2. Use the role-based guide to find your path.
  3. Check terms you do not know in the glossary.
  4. Use the checklists for ongoing maintenance.
  5. If you suspect compromise, open hacked-site triage immediately.

Fastest Wins

These are the highest-value actions for most sites:

Action Impact Effort Who should do it first
Update WordPress core, plugins, themes, and PHP High Low Every site owner
Remove unused plugins, themes, and accounts High Low Every site owner
Enable MFA for privileged users High Medium Admins
Enforce HTTPS everywhere High Medium Admins or hosts
Verify backups and test restores High Medium Owners and admins
Stop editing production directly High Medium Developers and agencies

Choose Your Path

Main Guides

How To Read This Repo

Most recommendations use the same pattern:

  • Minimum: the basic version most sites should do
  • Better: the stronger setup for sites with moderate effort available
  • Advanced: the more mature control for higher-risk or more complex environments
  • How to verify: a simple way to confirm the change is real

This structure is meant to help basic users take action quickly without blocking advanced users from going deeper.

Contributing

To improve the repo, read CONTRIBUTING.md and AGENTS.md. Keep changes practical, source-backed, and easy to understand for a non-expert reader.

License

MIT

About

Guideline to securing your WordPress site

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Used by

Contributors