How WordPress Sites Actually Get Hacked
Popular belief holds that hackers target sites with a grudge, a political angle or valuable data. The reality is duller. Most attacks are automated. Bots scan millions of sites looking for known weaknesses, and they take the easiest target they can find. A site with an outdated plugin, a weak admin password and no login limits is simply an easier target than the one next door.
Understanding the common entry points makes protection much simpler, because you can defend against categories rather than individual threats.
- Outdated plugins and themes. The single most common cause by a wide margin.
- Weak or reused passwords. Especially on administrator and hosting accounts.
- Stolen credentials. Malware on a computer, phishing emails, or a data breach at a service you reuse a password on.
- Nulled or pirated plugins and themes. Often contain deliberately hidden malicious code.
- Misconfigured file permissions. Usually after a bad migration or a helpful tutorial followed too literally.
- Server-level weaknesses. An outdated PHP version or an unpatched hosting stack.
- Cron and XML-RPC abuse. The latter is rarely needed and frequently attacked.
Step 1: Start With the Accounts
Most site compromises begin with a login, so accounts come first.
- Use a unique password for every service. Your hosting, WordPress, email, domain registrar and payment accounts should never share a password. Use a password manager to keep track.
- Never use “admin” as a username. It is the first guess in every automated attack. Create a new administrator with a distinctive name, then delete or demote the old one.
- Limit accounts. Every administrator is a potential door. Editors and authors rarely need full administrative rights.
- Delete dormant users. Old guest authors and ex-employees are forgotten access points.
- Protect your email. The admin email address is where password resets arrive. Secure it with two-factor authentication and never publish it in plain text on the site.
Step 2: Turn On Two-Factor Authentication
Passwords can be guessed, phished or leaked. A second factor, usually a code from an authenticator app, means a stolen password alone is useless.
Enable 2FA in two places at minimum: your WordPress administrator logins and your hosting or control panel account. If the host does not support 2FA on the control panel, that is a strong argument for changing hosts.
Save the backup or recovery codes somewhere offline. If you lose your phone without them, you will be locked out of your own site, which is a self-inflicted outage that support teams cannot always resolve quickly.
Step 3: Fix Updates and Version Hygiene
Updates exist because something was found to be unsafe or broken. Delaying them is like leaving a door unlocked in a neighbourhood where thieves test handles.
- Take a backup first. Always, before core, theme or plugin updates.
- Update plugins and themes weekly. Delete anything you are not using rather than deactivating it, because inactive code can still be exploited.
- Update WordPress core promptly. Minor security releases should be applied within days.
- Update PHP. Ask your host which version they recommend and switch. Old PHP versions are a common server-side weakness.
- Avoid abandoned software. If a plugin has not been updated in years, find an alternative with a maintenance history.
- Never use nulled plugins or themes. The “savings” cost is a backdoor you cannot see.
Step 4: Harden the Login
A few settings remove the majority of automated login attacks.
- Limit login attempts. Lock out or slow down an IP after a small number of failed tries.
- Change the login URL if your security plugin supports it. It is not real security on its own, but it removes endless background noise from bots hitting the default address.
- Rename or protect the admin area with an additional authentication layer where your host supports it.
- Require strong passwords for all users through a plugin or a policy you enforce manually.
- Log out idle sessions. A forgotten session on a shared computer is an easy way in.
- Disable XML-RPC if you do not use apps that depend on it. It is a frequent target for password-guessing attacks.
Step 5: Add a Firewall and Malware Scanning
Login protection stops attackers at the door. A firewall stops the traffic before it reaches WordPress at all, and malware scanning gives you an early warning if something slipped through.
What a decent security setup provides:
- Web application firewall rules for common attacks.
- Regular file-integrity checks that flag modified core or plugin files.
- Malware and backdoor scanning with alerts.
- Monitoring for unexpected file changes and login activity.
- Blocking of suspicious IPs and user-agent patterns.
Do not install three security plugins at once. They conflict, duplicate work, and slow the site. Choose one well-reviewed option and configure it properly. If your host already provides server-level protection, use that as the foundation and keep plugin-level security light.
Step 6: Get File Permissions and Configuration Right
Correct permissions prevent a small problem from becoming a big one.
| Item | Recommended | Why |
|---|---|---|
| Folders | 755 | Allows reading and execution, blocks writing by others |
| Files | 644 | Standard safe default |
| wp-config.php | 600 where supported | Contains database credentials |
| Directory listings | Disabled | Prevents visitors browsing your file structure |
| Public write access anywhere | Never | A writable public folder invites injected scripts |
Also confirm that debug display is off on your live site. Error messages on the front end reveal file paths and plugin versions to anyone who triggers them.
Step 7: Protect Against the Everyday Risks
Not every incident is an attack. Some are accidents that look like one.
- Back up automatically and store copies off the server. This is also your recovery plan when a hack succeeds.
- Do not give administrator access casually. Contractors and guest writers can work with lower roles.
- Watch the email inbox. Unexpected password reset messages, login alerts or admin notifications should always be investigated.
- Keep your own computer clean. A keylogger on your laptop defeats every protection on the site.
- Be careful with “security scan” emails. Fake warnings are a classic phishing route to your hosting login.
- Review plugins each quarter. Remove the ones used once and forgotten.
How to Tell If You Have Already Been Hacked
Common signs, roughly in order of how often they appear:
- Search results show unexpected pages, often about unrelated products or pharmaceuticals.
- Visitors report warnings in their browsers or being redirected elsewhere.
- Your host sends an abuse notice or suspends the account.
- New administrators or users appear that you did not create.
- Files changed that you did not edit, especially in plugin folders.
- The site slows dramatically, usually because it is sending spam or mining in the background.
- Emails from your domain are blocked or land in spam folders.
If any of these happen, work fast and work carefully.
Recovery Steps After a Compromise
- Change all passwords immediately: WordPress, hosting, database, email, and anything connected.
- Enable 2FA everywhere it is available.
- Take a forensic backup of the current state before cleaning, in case you need to investigate later.
- Identify the entry point with your host, using access logs, so you do not simply get reinfected.
- Clean or rebuild. Cleaning is often faster than people expect, but if the compromise is deep, restoring a known-good backup and re-applying recent content is more reliable.
- Update everything the moment the site is clean.
- Check Google Search Console for manual actions or security issues and request a review if needed.
- Tell your users if personal data may have been exposed, as required by applicable privacy rules.
Hosting-Level Security Worth Asking For
Plugin security covers the parts of the site you control. Your host covers everything underneath, and it is fair to ask what is included.
- ModSecurity or an equivalent web application firewall. Blocks many common attack patterns before they reach PHP.
- Malware scanning at server level, with alerts rather than silent deletion.
- Automated patch management for the hosting stack and current PHP versions.
- Brute-force protection on the control panel login as well as WordPress itself.
- Isolated accounts, so one compromised site on the server cannot read another’s files.
- Backups with a tested restore path and a clear retention policy.
If your host charges extra for basic isolation or leaves accounts on a PHP version that stopped receiving security updates years ago, that is a real, measurable risk and a reasonable reason to move.
A Quarterly Security Review
Spending twenty minutes every three months keeps a small site in good shape. Work through this list and note the date when you finish.
- List all users and roles; remove anyone who no longer needs access.
- List all plugins; delete the ones you do not use.
- Confirm two-factor authentication is still active on WordPress, hosting and the admin email account.
- Check the activity log for unexpected logins, file changes or new users.
- Confirm backups are running and that at least one recent archive exists off the server.
- Update everything, including PHP if a newer supported version is available.
- Review file permissions if you have migrated or restored anything since the last check.
- Check Search Console for security issues and manual actions.
Write the date of the review at the top of the page. A security routine that has not been touched in eight months is not really a routine.
Frequently Asked Questions
Is a small blog really a target?
Yes, but not personally. Automated tools scan everything. Small sites are often chosen precisely because they are less monitored and easier to exploit.
Do I need a paid security plugin?
Not necessarily. A well-configured free plugin plus good hosting, updates and 2FA removes the majority of risk. Paid tools mainly add faster malware signatures and cleaner incident support.
Will a firewall slow my site?
Modern firewalls add very little overhead, especially server-level ones. Poorly configured plugin firewalls can slow things down, which is another reason to use one rather than three.
How often should I change my passwords?
Changing passwords on a schedule is less important than using unique passwords, never reusing them, and rotating them immediately after any suspected breach or staff change.
What is the single most effective thing I can do today?
Turn on two-factor authentication for your WordPress and hosting accounts, and update every plugin. Together, those two steps prevent the vast majority of successful attacks.
Security Checklist
- Unique passwords for everything, stored in a manager.
- Two-factor authentication on WordPress, hosting and email.
- No “admin” username; minimal administrator accounts.
- Weekly updates; nothing unused installed.
- Login attempt limits and XML-RPC disabled if unused.
- One well-configured firewall and malware scanner.
- Correct file permissions and directory listing disabled.
- Automatic backups stored off the server.
- Regular reviews of users, plugins and access.
- A written plan for what to do if something goes wrong.
Security Questions and Real Scenarios
My site is small and has no traffic. Why would anyone attack it?
Because attacks are automated and indiscriminate. Bots look for a known vulnerability, not for a valuable target. A small site is often easier to break into precisely because nobody monitors it, and attackers can use the server for spam, phishing pages or resources without the owner noticing for weeks.
A plugin I rely on has not been updated in two years. What should I do?
Look for an actively maintained alternative and plan a migration. If there is no alternative and the plugin is essential, isolate the risk: keep it updated manually if patches are released, restrict its use to pages where it is needed, monitor file changes in its folder, and put a firewall in front of the site. Abandoned software is a permanent risk, not a temporary one.
I inherited a site from a previous developer. What do I check first?
Get full ownership of the hosting, domain and DNS accounts, then list every administrator user and every plugin and theme. Remove anything unknown, replace all credentials, check for scheduled tasks you did not create, and review the file permissions. Inherited sites frequently contain forgotten access points left by former contractors.
Do I need to tell anyone if my site is hacked?
Yes, in most cases. Your host should be informed because the server may be abused. If user data was exposed, privacy rules in many countries require you to notify affected people. And if search results were affected, use Search Console to request a review once the site is clean.
How do I know whether my security plugin is actually doing anything?
Check its logs and alerts once a month. A well-configured firewall records blocked attempts, and a malware scanner reports clean or flagged files. Silence is not proof of safety; it may indicate that logging is switched off.
Final Thoughts
WordPress security is not about becoming an expert. It is about removing the easy options an attacker looks for first. Strong accounts with two-factor authentication, current software, a firewall, working backups and fewer plugins than you think you need will keep the overwhelming majority of automated attacks away from your site.