Skip to main content
UNPWNED
WordPress Security Guide
Q&AWordPress

How to secure a WordPress site?

Keep WordPress core, all plugins, and themes updated to the latest versions. Use strong, unique passwords and enable two-factor authentication for all admin accounts. Install a security plugin that provides firewall, malware scanning, and login protection. Disable XML-RPC if not needed. Restrict the REST API to authenticated users. Change the default wp-admin URL. Set proper file permissions (644 for files, 755 for directories). Add security headers through your hosting configuration or a plugin. Remove unused themes and plugins. Configure regular backups. UNPWNED reports completed outside-in findings for the submitted WordPress site. Paid reports add prioritized remediation guidance.

Check your WordPress app now

Run free security scan

Last reviewed: 2026-04-07. Based on publicly available security research and UNPWNED scan telemetry.