WordPress security: 7 things to do today
90% of hacked WordPress sites are compromised through the same 7 issues. All fixable for free in one afternoon.
WordPress is the world's most-used CMS (43% of sites) — and therefore the most attacked. Good news: 90% of hacks happen through the same 7 trivial issues, all fixable for free in one afternoon.
How much being hacked costs (why prevention is worth it)
- Site offline 1-7 days during recovery
- Cleanup costs: €300-2,000 (depending on severity)
- Google penalty ("This site may be hacked") for 2-4 weeks
- Potential client data breach (GDPR risk)
- Trust + traffic loss for months
All avoidable with 2 hours of preventive work.
1. Update core, plugins and theme NOW
60% of hacks exploit unpatched plugin/theme vulnerabilities. WordPress > 6.x, plugins always on latest stable versions, theme updated.
How: WP-Admin → Updates. Setup auto-update for plugin minor + WP minor.
2. Uninstall ALL unused plugins/themes
Deactivated plugin isn't safe. Even disabled, they can be exploited. Uninstall.
How: Plugins → sort by "last updated". Those not updated in > 12 months are dangerous (even if active).
3. Change "admin" username + strong password
99% of brute force attempts try "admin"/"admin", "wp-admin"/"123456", etc. "admin" username + weak password = compromise in 24-48 hours.
How:
- Create new admin user with random username (e.g. "gamer_owner_2026")
- Password generated by password manager (16+ chars, symbols, numbers)
- Delete the old "admin" user and reassign their posts to the new
4. Enable 2FA (two-factor authentication)
Even if password is stolen, without the second factor they can't access. Reduces risk by 99%.
Free plugins: Wordfence Login Security, miniOrange, Two Factor.
Setup via Google Authenticator / Authy on phone. 5 minutes.
5. Limit Login Attempts
Without limits, scripts try thousands of passwords per minute. With limit, after 3 failed attempts the IP is banned.
Plugin: Limit Login Attempts Reloaded (free). Basic setup: 3 attempts, 30-minute lockout.
6. Change default DB prefix
WordPress default: tables prefixed wp_. Every attacker knows it. Change to a random prefix like wp_g8h2_.
How: on new installs, during setup. On existing sites, plugin Brozzme DB Prefix & Tools (with backup first).
7. Setup automatic external backup
Backup on the server itself = useless if the attack erases it. Backup on external cloud = recovery in 1 hour instead of 1 week.
Solutions:
- UpdraftPlus + Google Drive/Dropbox (free, weekly manual)
- Hosting with automatic off-site backup (SiteGround, Kinsta, etc.)
- Dedicated service: BlogVault, Jetpack Backup (€5-30/month)
Bonus — "all-in-one" security plugin
For those who want one plugin that does everything:
- Wordfence (free): firewall + malware scanner + 2FA + login security
- Sucuri Security (free base): scanner + file integrity + alerts
- iThemes Security (now SolidWP): comprehensive security
Wordfence is the most popular and complete choice for SMEs.
Advanced hardening (for the keen)
- Disable XML-RPC if you don't use it (historic vulnerability)
- Hide WordPress version (info useful to attackers)
- Disable file editor from WP-Admin (
DISALLOW_FILE_EDITin wp-config.php) - SSL/HTTPS mandatory (today practically standard)
- Geo-blocking of countries that aren't your target
- Free Cloudflare as WAF (Web Application Firewall)
What to do if already hacked
- Don't panic. Backup EVERYTHING immediately.
- Change all passwords (WordPress, hosting, FTP, DB).
- Malware scanner: Wordfence + Sucuri SiteCheck (free online).
- If you don't know how to clean: call an expert. Average cost: €200-800 for cleanup.
- Search Console: request review if flagged as "hacked site".
- Notify clients if their data was exposed (GDPR obligation within 72 hours).
2-hour checklist
- ☐ Update WordPress core, plugins, theme
- ☐ Uninstall unused plugins/themes
- ☐ Change admin username + strong password
- ☐ Setup 2FA
- ☐ Install Limit Login Attempts
- ☐ Change DB prefix
- ☐ Setup automatic external backup
- ☐ Install Wordfence (free)
No time or skills? WordPress security is included in the Digital Presence Management package from €89/month: automatic off-site backup, 24/7 monitoring, managed updates, fast intervention if hacked. Free audit to understand your site's current risks.
Want to apply this to your SME?
If you'd like a concrete analysis of your situation, request the free audit from Gamerbit. In 48 hours we tell you exactly where you're losing leads, time or budget — no sales pitch.
If you already know what you need and want a steady system, the Conversion Website package is the most direct starting point.
Want more clients from your website?
Get the free 48h Check-up: we show you where you are losing enquiries.
Free 48h Check-up