WordPress security
an out-of-date wordpress
site is a sitting target.
WordPress is the most-attacked platform on the web — not because it is weak, but because it is everywhere. The good news: the fix is almost entirely in your hands, and it is mostly just one habit — keeping everything updated.
Keep WordPress, its plugins and its themes updated.
WordPress runs a huge share of the web, which makes it the most probed platform online — and an out-of-date plugin is how the overwhelming majority of hacked WordPress sites are broken into. Updates are not optional housekeeping; they are the single most important thing you can do to stay safe. We give you the tools to make it painless, but applying them is your part.
See the essentials belowhow sites actually get hacked.
Almost nobody is targeted by name. The reality is duller and more relentless: automated bots crawl the entire internet around the clock, checking each WordPress site against a list of known, published vulnerabilities — the kind that already have a fix.
When a bot finds a site running an old version of a plugin with a known hole, it walks straight in. No skill required, no reason you were chosen. The single thing standing between your site and that bot is whether you have applied the update that closes the hole.
Where the break-ins come from
- 1.Out-of-date plugins and themes — the overwhelming majority. A published flaw plus an un-applied update is the whole story.
- 2.Weak or reused passwords — guessed by bots hammering the login page, or leaked from another site you used the same password on.
- 3.Nulled or pirated plugins — free copies of paid plugins, very often shipped with malware baked in on purpose.
the essentials, in order of impact.
You do not need to be a security expert. Do these six things and you have shut out almost every automated attack that will ever come your way.
Update core, plugins and themes — promptly
Most WordPress hacks exploit a known flaw in an out-of-date plugin that already had a fix available. Applying updates quickly closes the door before an automated scanner finds it open. Turn on automatic updates where you can.
Delete plugins and themes you do not use
Every plugin is code that can be attacked, even when it is deactivated. If you are not using it, remove it — the smaller the surface, the fewer the ways in. This alone removes a surprising number of risks.
Strong, unique passwords and two-factor
Bots guess passwords against wp-login all day. A long, unique admin password and two-factor authentication defeat that entirely — it is the cheapest, highest-impact step you can take.
Do not use the username “admin”
Half of every brute-force attempt tries “admin” first. Use a different administrator username so an attacker has to guess the name as well as the password.
Install plugins from reputable sources only
Nulled or pirated “premium” plugins are a classic way malware gets in deliberately. Stick to the WordPress directory and known vendors, and check a plugin is still maintained before you rely on it.
Keep backups you can actually restore
When something does slip through, a recent backup turns a crisis into a five-minute rollback. Every plan here is backed up daily with 30 days of history, restorable by you — but test that you know how before you need it.
we make the hard part easy.
Staying updated is only a chore if you have to remember it. On every WordPress plan here, most of it is handled for you.
The WordPress Toolkit
Turn on automatic updates, and let the toolkit scan your plugins and themes against known-vulnerability data and flag the risky ones. It takes a restore point automatically before every update, and one-click staging lets you test a change before it ever touches the live site.
Imunify360 and daily backups
An Imunify360 web application firewall filters attacks before they reach your site, and malware is scanned for and removed automatically. Behind that, every site is backed up daily with 30 days of history you can restore yourself — so a bad day is a rollback, not a rebuild.
The honest limit: these tools protect the platform and catch known malware, but no host can force your plugins to update or choose your password for you. A firewall cannot patch a hole — it can only make it harder to reach — so an out-of-date plugin will be reinfected even after a clean-up. Cleaning and updating have to go together, which is why the six essentials above are still yours to do. See how we protect the platform.
wordpress security questions
Why is WordPress attacked so much?
Not because it is insecure — because it is everywhere. WordPress powers a huge share of the world's websites, so it is the most worthwhile target for automated attacks, which scan the whole internet looking for sites running a plugin or theme version with a known, published vulnerability. The core software is well maintained; the weak point is almost always a third-party plugin or theme that has not been updated.
Do your security tools mean I do not have to update?
No — and any host that tells you otherwise is overselling. Our Imunify360 firewall blocks a great deal and removes known malware automatically, but a web application firewall cannot patch a hole in your plugin; it can only make it harder to reach. If an out-of-date plugin is the way in, a cleaned site simply gets reinfected. Cleaning and patching have to happen together, which is why updates are still your most important job.
What does the WordPress Toolkit do to help?
On every WordPress plan, the WordPress Toolkit in Plesk lets you turn on automatic updates, scans your installed plugins and themes against known-vulnerability data and flags the risky ones, takes a restore point automatically before an update runs, and clones your site to a staging copy so you can test an update before it touches the live site. It turns “stay updated” from a chore you forget into something the platform mostly handles for you.
I think my WordPress site has been hacked — what now?
Do four things, in order: restore from a clean backup from before the compromise; update WordPress core, every plugin and every theme, and delete any you do not recognise or use; change all passwords (WordPress admin, hosting, database, FTP) and turn on two-factor; then run a full malware scan. If you are hosted with us, our malware scanning will already have flagged and cleaned known threats — but closing the hole that let it in is the step that stops it happening again. Call us if you want a hand.
wordpress hosting with the tools built in.
The WordPress Toolkit, automatic updates, vulnerability scanning, staging, a firewall and daily backups — on every plan, so staying safe is mostly already handled.
