Home / Blog / Website

WordPress security: 7 things to do today

90% of hacked WordPress sites are compromised through the same 7 issues. All fixable for free in one afternoon.

WordPress security: 7 things to do today

WordPress is the world's most-used CMS (43% of sites) — and therefore the most attacked. Good news: 90% of hacks happen through the same 7 trivial issues, all fixable for free in one afternoon.

How much being hacked costs (why prevention is worth it)

  • Site offline 1-7 days during recovery
  • Cleanup costs: €300-2,000 (depending on severity)
  • Google penalty ("This site may be hacked") for 2-4 weeks
  • Potential client data breach (GDPR risk)
  • Trust + traffic loss for months

All avoidable with 2 hours of preventive work.

1. Update core, plugins and theme NOW

60% of hacks exploit unpatched plugin/theme vulnerabilities. WordPress > 6.x, plugins always on latest stable versions, theme updated.

How: WP-Admin → Updates. Setup auto-update for plugin minor + WP minor.

2. Uninstall ALL unused plugins/themes

Deactivated plugin isn't safe. Even disabled, they can be exploited. Uninstall.

How: Plugins → sort by "last updated". Those not updated in > 12 months are dangerous (even if active).

3. Change "admin" username + strong password

99% of brute force attempts try "admin"/"admin", "wp-admin"/"123456", etc. "admin" username + weak password = compromise in 24-48 hours.

How:

  1. Create new admin user with random username (e.g. "gamer_owner_2026")
  2. Password generated by password manager (16+ chars, symbols, numbers)
  3. Delete the old "admin" user and reassign their posts to the new

4. Enable 2FA (two-factor authentication)

Even if password is stolen, without the second factor they can't access. Reduces risk by 99%.

Free plugins: Wordfence Login Security, miniOrange, Two Factor.

Setup via Google Authenticator / Authy on phone. 5 minutes.

5. Limit Login Attempts

Without limits, scripts try thousands of passwords per minute. With limit, after 3 failed attempts the IP is banned.

Plugin: Limit Login Attempts Reloaded (free). Basic setup: 3 attempts, 30-minute lockout.

6. Change default DB prefix

WordPress default: tables prefixed wp_. Every attacker knows it. Change to a random prefix like wp_g8h2_.

How: on new installs, during setup. On existing sites, plugin Brozzme DB Prefix & Tools (with backup first).

7. Setup automatic external backup

Backup on the server itself = useless if the attack erases it. Backup on external cloud = recovery in 1 hour instead of 1 week.

Solutions:

  • UpdraftPlus + Google Drive/Dropbox (free, weekly manual)
  • Hosting with automatic off-site backup (SiteGround, Kinsta, etc.)
  • Dedicated service: BlogVault, Jetpack Backup (€5-30/month)

Bonus — "all-in-one" security plugin

For those who want one plugin that does everything:

  • Wordfence (free): firewall + malware scanner + 2FA + login security
  • Sucuri Security (free base): scanner + file integrity + alerts
  • iThemes Security (now SolidWP): comprehensive security

Wordfence is the most popular and complete choice for SMEs.

Advanced hardening (for the keen)

  • Disable XML-RPC if you don't use it (historic vulnerability)
  • Hide WordPress version (info useful to attackers)
  • Disable file editor from WP-Admin (DISALLOW_FILE_EDIT in wp-config.php)
  • SSL/HTTPS mandatory (today practically standard)
  • Geo-blocking of countries that aren't your target
  • Free Cloudflare as WAF (Web Application Firewall)

What to do if already hacked

  1. Don't panic. Backup EVERYTHING immediately.
  2. Change all passwords (WordPress, hosting, FTP, DB).
  3. Malware scanner: Wordfence + Sucuri SiteCheck (free online).
  4. If you don't know how to clean: call an expert. Average cost: €200-800 for cleanup.
  5. Search Console: request review if flagged as "hacked site".
  6. Notify clients if their data was exposed (GDPR obligation within 72 hours).

2-hour checklist

  • ☐ Update WordPress core, plugins, theme
  • ☐ Uninstall unused plugins/themes
  • ☐ Change admin username + strong password
  • ☐ Setup 2FA
  • ☐ Install Limit Login Attempts
  • ☐ Change DB prefix
  • ☐ Setup automatic external backup
  • ☐ Install Wordfence (free)

No time or skills? WordPress security is included in the Digital Presence Management package from €89/month: automatic off-site backup, 24/7 monitoring, managed updates, fast intervention if hacked. Free audit to understand your site's current risks.

Want to apply this to your SME?

If you'd like a concrete analysis of your situation, request the free audit from Gamerbit. In 48 hours we tell you exactly where you're losing leads, time or budget — no sales pitch.

If you already know what you need and want a steady system, the Conversion Website package is the most direct starting point.

Want more clients from your website?

Get the free 48h Check-up: we show you where you are losing enquiries.

Free 48h Check-up