{"id":20763,"date":"2021-08-17T10:43:35","date_gmt":"2021-08-17T02:43:35","guid":{"rendered":"https:\/\/www.exabytes.sg\/blog\/?p=20763"},"modified":"2024-01-19T08:37:31","modified_gmt":"2024-01-19T00:37:31","slug":"wordpress-website-security-tips","status":"publish","type":"post","link":"https:\/\/www.exabytes.sg\/blog\/wordpress-website-security-tips\/","title":{"rendered":"WordPress Website Security Tips (Updated for 2024)"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone size-full wp-image-28244\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?resize=696%2C364&#038;ssl=1\" alt=\"Essential WordPress Security: How to Protect Your Site\" width=\"696\" height=\"364\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?resize=300%2C157&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?resize=1024%2C536&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?resize=768%2C402&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?resize=696%2C364&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?resize=1068%2C559&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?resize=218%2C114&amp;ssl=1 218w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?resize=803%2C420&amp;ssl=1 803w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">With <\/span><a href=\"https:\/\/www.businessdit.com\/website-hacking-statistics\/\" target=\"_blank\" rel=\"noopener\" data-schema-attribute=\"\"><b>30,000<\/b> <b>new websites hacked<\/b><\/a><span style=\"font-weight: 400;\"> every day on average, the chances of our website being hacked are high if we <\/span><span style=\"font-weight: 400;\">are not following all the <a href=\"https:\/\/www.exabytes.sg\/web-security\/sucuri-website-security\">website security<\/a> practices provided by industry experts.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this article, we have compiled all the <a href=\"https:\/\/www.exabytes.sg\/web-hosting\/wordpress-hosting\">WordPress<\/a> website security tips that you should be implementing to keep your website protected from vulnerabilities.\u00a0<\/span><\/p>\n<h3><strong>Latest WordPress Website Security Tips in 2024<\/strong><\/h3>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Do not install null themes or plugins<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use an unique username and password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use the latest WordPress version<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">Update your plugin and themes regularly<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use the latest and most stable PHP version<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Install SSL certificate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove unused plugins and themes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weekly\/daily website backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use a reliable hosting provider<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable domain lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable brute force protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable file editing on the WordPress dashboard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Setup WAF Protection<\/span><\/li>\n<\/ol>\n<h2><b>Do not install null themes or plugins<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">This is listed as number 1 for a reason, most of the websites that were infected by malware are mainly because of the installation of null themes or plugins. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Yes, it may be tempting for you to take the risk to buy null themes or plugins so that you can save a lot of money. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">By installing null themes or plugins into your website, you will not be able to receive any updates and there is a high chance that the plugin\/theme is corrupted with malware.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you can\u2019t afford the premium plugin, <\/span><b>there is always a free alternative<\/b><span style=\"font-weight: 400;\"> for the tool you are looking for.<\/span><\/p>\n<p>You can check whether your current theme meets WordPress requirements, just copy your website URL (or the URL of the WordPress theme\u2019s live demo) into any W3C Markup Validation Service.<\/p>\n<p>If you find your theme isn\u2019t compliant, search for a new theme in the official\u00a0<a href=\"https:\/\/wordpress.org\/themes\/\" target=\"_blank\" rel=\"noopener\">WordPress theme directory<\/a>.<\/p>\n<h2><b>Use an unique username and password<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">By default, your WordPress username is most likely to be \u201c<\/span><b>admin<\/b><span style=\"font-weight: 400;\">\u201d. You need to use a more unique username such as \u201c<\/span><b>kelvin-mycoolbrand<\/b><span style=\"font-weight: 400;\">\u201d. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">By doing so, it makes it harder for hackers to brute force your website as now, they have to guess your username too. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">As for your password, try to have a strong password that fulfills all the following criteria:-<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">At least 12 characters long<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">At least 1 uppercase and 1 lowercase<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">At least 1 special character such as @, &amp;, (<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">You\u2019re not using this password on other websites<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Having these 2 in place, it will be reasonably hard for a hacker to brute force into your WordPress dashboard.<\/span><\/p>\n<p>You also can use one of the simplest and most effective tools to secure your WordPress by enabling two-factor authentication. Two-factor authentication (2FA) requires users to verify their sign-on with a second device in just a few simple steps.<\/p>\n<p><span style=\"font-weight: 400;\">If you\u2019re interested in knowing how long it will take for a hacker to crack your password, you can use tools like <\/span><a href=\"https:\/\/howsecureismypassword.net\/\" target=\"_blank\" rel=\"noopener\" data-schema-attribute=\"\"><span style=\"font-weight: 400;\">How Secure Is My Password<\/span><\/a><span style=\"font-weight: 400;\"> to find out more.<\/span><\/p>\n<h2><b>Use the latest WordPress version\u00a0<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Keeping your WordPress version up to date is a good practice to keep your WordPress website protected from vulnerabilities. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Most of the time when there is a WordPress update, the updates are related to website security. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">After each WordPress update announcement, it also gives hackers a better understanding of all the vulnerabilities in their previous version, then using the knowledge to target websites that are still using the outdated WordPress version.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Therefore, it is important to ensure your WordPress version is up to date.<\/span><\/p>\n<h2><b>Update your plugin and themes regularly<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The reason to make sure your <a href=\"https:\/\/www.exabytes.sg\/blog\/basic-free-wordpress-plugins\/\" target=\"_blank\" rel=\"noopener\">WordPress plugins<\/a> and themes are up to date is the same as updating your WordPress version. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Updates from plugins and themes are much more frequent compared with WordPress versions, some plugins even have new updates once a week.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Therefore, it is recommended that you at least check all your websites once a week to ensure all your plugins and themes are up to date. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you have a lot of websites and do not have the time to do it one by one every week, you can enable auto-updates so that your plugins can be automatically updated when there is a new update.<\/span><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-20765 size-full\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/WordPress-Security-Auto-Updates.jpg?resize=696%2C360&#038;ssl=1\" alt=\"\" width=\"696\" height=\"360\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/WordPress-Security-Auto-Updates.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/WordPress-Security-Auto-Updates.jpg?resize=300%2C155&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/WordPress-Security-Auto-Updates.jpg?resize=1024%2C529&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/WordPress-Security-Auto-Updates.jpg?resize=768%2C397&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/WordPress-Security-Auto-Updates.jpg?resize=696%2C360&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/WordPress-Security-Auto-Updates.jpg?resize=1068%2C552&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/WordPress-Security-Auto-Updates.jpg?resize=813%2C420&amp;ssl=1 813w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/WordPress-Security-Auto-Updates.jpg?resize=218%2C114&amp;ssl=1 218w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<p><b>Note:<\/b><span style=\"font-weight: 400;\"> For plugins such as <a href=\"https:\/\/www.exabytes.sg\/web-hosting\/woocommerce-hosting\" target=\"_blank\" rel=\"noopener\">WooCommerce WordPress<\/a> and Elementor, I do not recommend enabling auto-updates as there is always a small chance that the updates will cause your website to crash. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">So, before updating plugins with major updates, you should perform a full website backup first.<\/span><\/p>\n<h2><b>Use the latest and most stable PHP version<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The concept is the same as keeping your WordPress version, themes, and plugins up to date. If your PHP version is set as <\/span><b>PHP 7.4<\/b><span style=\"font-weight: 400;\">, you\u2019re all good. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">While there is a newer PHP version released on 26 November 2020, PHP 8.0, it\u2019s still not as stable as compared with PHP 7.4.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition, if you are using plugins such as Oxygen Builder, using PHP 8.0 would cause your website to have issues as Oxygen Builder is still incompatible with PHP 8.0 at the moment.<\/span><\/p>\n<h2><b>Install SSL certificate<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Installing an <a href=\"https:\/\/www.exabytes.sg\/web-security\/ssl\" target=\"_blank\" rel=\"noopener\">SSL certificate<\/a> on your website, can help to ensure that all the data on your website is encrypted. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Making it hard for hackers to get access to all the sensitive information on your website, such as customers\u2019 shipping addresses, contact numbers, and most importantly credit card details.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you are using <\/span><a href=\"https:\/\/www.exabytes.sg\/web-hosting\/wordpress-hosting?utm_source=website&amp;utm_medium=blog&amp;utm_campaign=wph\"><span style=\"font-weight: 400;\">Exabytes WordPress Hosting<\/span><\/a><span style=\"font-weight: 400;\">, this would not be an issue for you as we are providing <a href=\"https:\/\/www.exabytes.sg\/blog\/free-ssl-certificate\/\" target=\"_blank\" rel=\"noopener\">free SSL for websites<\/a> hosted with us.<\/span><\/p>\n<h2><b>Remove unused plugins and themes<\/b><\/h2>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-20766 size-full\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Remove-Unsued-Plugins.jpg?resize=696%2C360&#038;ssl=1\" alt=\"\" width=\"696\" height=\"360\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Remove-Unsued-Plugins.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Remove-Unsued-Plugins.jpg?resize=300%2C155&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Remove-Unsued-Plugins.jpg?resize=1024%2C529&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Remove-Unsued-Plugins.jpg?resize=768%2C397&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Remove-Unsued-Plugins.jpg?resize=696%2C360&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Remove-Unsued-Plugins.jpg?resize=1068%2C552&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Remove-Unsued-Plugins.jpg?resize=813%2C420&amp;ssl=1 813w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Remove-Unsued-Plugins.jpg?resize=218%2C114&amp;ssl=1 218w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Another important thing to do to keep your WordPress website protected is to <\/span><b>delete ALL <\/b><span style=\"font-weight: 400;\">the plugins that you are not using. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">There is no point for us to keep the plugin there, making our website more bloated, slowing down your website speed, and also giving hackers a<\/span><b>nother vulnerability opportunity<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h2><b>Weekly\/daily website backup<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">It is extremely important to backup your website on a weekly or daily basis. If something did go wrong on our website, say being infected by malware and losing control of our website, at least we have a backup version for us to recover our website.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With <\/span><a href=\"https:\/\/www.exabytes.sg\/web-hosting\/wordpress-hosting?utm_source=website&amp;utm_medium=blog&amp;utm_campaign=wph\"><span style=\"font-weight: 400;\">Exabytes WordPress Hosting<\/span><\/a><span style=\"font-weight: 400;\">, we provide free daily auto backups for our users so that they can be well protected from unfortunate events.<\/span><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-20767 size-full\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Daily-Backup-wth-Plesk.jpg?resize=696%2C360&#038;ssl=1\" alt=\"\" width=\"696\" height=\"360\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Daily-Backup-wth-Plesk.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Daily-Backup-wth-Plesk.jpg?resize=300%2C155&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Daily-Backup-wth-Plesk.jpg?resize=1024%2C529&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Daily-Backup-wth-Plesk.jpg?resize=768%2C397&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Daily-Backup-wth-Plesk.jpg?resize=696%2C360&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Daily-Backup-wth-Plesk.jpg?resize=1068%2C552&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Daily-Backup-wth-Plesk.jpg?resize=813%2C420&amp;ssl=1 813w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Daily-Backup-wth-Plesk.jpg?resize=218%2C114&amp;ssl=1 218w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<h2><b>Use a reliable hosting provider<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">One of the important WordPress website security tips is to choose to use a reliable <a href=\"https:\/\/www.exabytes.sg\/hosting\" target=\"_blank\" rel=\"noopener\">hosting provider<\/a> such as Exabytes comes with additional security benefits. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">With Exabytes, you\u2019ll have additional tools &#8211; <\/span><b>Imunify 360 and Patchman<\/b><span style=\"font-weight: 400;\"> to protect your websites from malware, fixing website vulnerabilities, and bad bots.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition, if you\u2019re facing any issues with your website, our team is always ready to assist 24\/7\/355.<\/span><\/p>\n<h2><b>Enable domain lock<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Another thing you should do to keep your website secure is to enable domain lock. With domain lock enabled, it can prevent others from transferring your domain name to another registrar by protecting your name servers.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you are using Exabytes as your domain registrar, you can easily lock your domain by going to your <\/span><b>Client Area<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Domains<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>My Domains<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Manage Domain<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Registrar Lock<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-20768 size-full\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Domain-Lock.jpg?resize=696%2C360&#038;ssl=1\" alt=\"\" width=\"696\" height=\"360\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Domain-Lock.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Domain-Lock.jpg?resize=300%2C155&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Domain-Lock.jpg?resize=1024%2C529&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Domain-Lock.jpg?resize=768%2C397&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Domain-Lock.jpg?resize=696%2C360&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Domain-Lock.jpg?resize=1068%2C552&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Domain-Lock.jpg?resize=813%2C420&amp;ssl=1 813w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Domain-Lock.jpg?resize=218%2C114&amp;ssl=1 218w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<h2><b>Enable brute force protection<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Enabling <a href=\"https:\/\/www.exabytes.sg\/blog\/wordpress-security-vulnerabilities\/\">brute force protection<\/a> is another good tips of WordPress website security to make it harder for hackers to get access to your WordPress account. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Whenever you log in to your WordPress dashboard, this will appear requesting you to fill up the characters shown in the picture.\u00a0<\/span><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-20769 size-full\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Brute-Force-Protection.jpg?resize=696%2C360&#038;ssl=1\" alt=\"\" width=\"696\" height=\"360\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Brute-Force-Protection.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Brute-Force-Protection.jpg?resize=300%2C155&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Brute-Force-Protection.jpg?resize=1024%2C529&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Brute-Force-Protection.jpg?resize=768%2C397&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Brute-Force-Protection.jpg?resize=696%2C360&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Brute-Force-Protection.jpg?resize=1068%2C552&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Brute-Force-Protection.jpg?resize=813%2C420&amp;ssl=1 813w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Brute-Force-Protection.jpg?resize=218%2C114&amp;ssl=1 218w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">With this in place, your website will be protected from brute force attacks. To enable brute-force protection, you can install a free plugin &#8211; NinjaFirewall.<\/span><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-20770 size-full\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall.jpg?resize=696%2C360&#038;ssl=1\" alt=\"\" width=\"696\" height=\"360\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall.jpg?resize=300%2C155&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall.jpg?resize=1024%2C529&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall.jpg?resize=768%2C397&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall.jpg?resize=696%2C360&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall.jpg?resize=1068%2C552&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall.jpg?resize=813%2C420&amp;ssl=1 813w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall.jpg?resize=218%2C114&amp;ssl=1 218w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Once you\u2019ve activated the plugin, go to <\/span><b>NinjaFirewall<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Login Protection<\/b><span style=\"font-weight: 400;\"> and select the same settings as shown below, then click save.<\/span><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-20771 size-full\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall-Configuration.jpg?resize=696%2C360&#038;ssl=1\" alt=\"\" width=\"696\" height=\"360\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall-Configuration.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall-Configuration.jpg?resize=300%2C155&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall-Configuration.jpg?resize=1024%2C529&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall-Configuration.jpg?resize=768%2C397&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall-Configuration.jpg?resize=696%2C360&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall-Configuration.jpg?resize=1068%2C552&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall-Configuration.jpg?resize=813%2C420&amp;ssl=1 813w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Ninja-Firewall-Configuration.jpg?resize=218%2C114&amp;ssl=1 218w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<h2><b>Disable file editing on the WordPress dashboard<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">By default, file editing is enabled on all WordPress dashboards. Having this enabled on your WordPress dashboard is risky. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">If a hacker has gained access to your WordPress dashboard, they can easily insert malicious scripts into your website without you noticing it, causing you to lose control of your website.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Your file editor can be accessed by going to <\/span><b>Plugins<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Plugin Editor<\/b><span style=\"font-weight: 400;\">, or by going to <\/span><b>Appearance<\/b><span style=\"font-weight: 400;\"> &gt; <\/span><b>Editor<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-20772 size-full\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Disable-File-Editing.jpg?resize=696%2C360&#038;ssl=1\" alt=\"\" width=\"696\" height=\"360\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Disable-File-Editing.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Disable-File-Editing.jpg?resize=300%2C155&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Disable-File-Editing.jpg?resize=1024%2C529&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Disable-File-Editing.jpg?resize=768%2C397&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Disable-File-Editing.jpg?resize=696%2C360&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Disable-File-Editing.jpg?resize=1068%2C552&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Disable-File-Editing.jpg?resize=813%2C420&amp;ssl=1 813w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/Website-Security-Disable-File-Editing.jpg?resize=218%2C114&amp;ssl=1 218w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">To disable file editing on the WordPress dashboard, all you have to do is add the following line of code to your wp-config.php.<\/span><\/p>\n<pre><span style=\"font-weight: 400;\">define('DISALLOW_FILE_EDIT', true);\r\n<\/span><\/pre>\n<h2><b>Setup WAF Protection<\/b><\/h2>\n<p><b>WAF Protection<\/b><span style=\"font-weight: 400;\"> or <\/span><b>Web Application Firewall Protection<\/b><span style=\"font-weight: 400;\"> is a must to keep your website protected. WAF helps to filter, monitor, and block HTTP traffic to and from a web service. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you wish to set up WAF protection for your WordPress website, solution providers such as <\/span><a href=\"https:\/\/sucuri.net\/\" target=\"_blank\" rel=\"noopener\" data-schema-attribute=\"\"><b>Sucuri<\/b><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/www.cloudflare.com\/en-gb\/\" target=\"_blank\" rel=\"noopener\" data-schema-attribute=\"\"><b>Cloudflare<\/b><\/a><span style=\"font-weight: 400;\"> are a good choice for you.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you prefer to use a free WordPress plugin or do not want to change your name servers, <\/span><a href=\"https:\/\/wordpress.org\/plugins\/ninjafirewall\/\" target=\"_blank\" rel=\"noopener\" data-schema-attribute=\"\"><b>NinjaFirewall (WP Edition)<\/b><\/a><span style=\"font-weight: 400;\"> is a good choice for you too.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Thanks for spending your time reading the entire article about the latest WordPress website security tips I hope this article will provide some useful insights for you to improve your website security.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you are looking for a new WordPress hosting provider, check out our <\/span><a href=\"https:\/\/www.exabytes.sg\/web-hosting\/wordpress-hosting?utm_source=website&amp;utm_medium=blog&amp;utm_campaign=wph\"><span style=\"font-weight: 400;\">WordPress Hosting plans<\/span><\/a><span style=\"font-weight: 400;\"> for more information.\u00a0<\/span><\/p>\n<p>For more information about <a href=\"https:\/\/www.exabytes.sg\/web-security\/sucuri-website-security\">Sucuri Website Security<\/a> and <a href=\"https:\/\/www.exabytes.sg\/web-security\/cloudflare-web-performance-booster\">Cloudflare Global Network &amp; CDN Solution<\/a>, contact us now!<\/p>\n<p><a href=\"https:\/\/www.exabytes.sg\/contact\"><span class=\"td_btn td_btn_md td_default_btn\">Contact Us<\/span><\/a><\/p>\n<p>Related articles:<\/p>\n<p><a href=\"https:\/\/www.exabytes.sg\/blog\/cloudflare-cdn-for-wordpress\/\">Cloudflare CDN for WordPress: What You Can Expect From This CDN<\/a><\/p>\n<p><a href=\"https:\/\/www.exabytes.sg\/blog\/how-to-setup-wordpress-sucuri-firewall\/\">How to Set up Sucuri Firewall (WAF) on Your WordPress Site<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With 30,000 new websites hacked every day on average, the chances of our website being hacked are high if we are not following all the website security practices provided by industry experts. In this article, we have compiled all the WordPress website security tips that you should be implementing to keep your website protected from [&hellip;]<\/p>\n","protected":false},"author":17,"featured_media":28244,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[293],"tags":[288,255],"class_list":{"0":"post-20763","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security-backup","8":"tag-wordpress-hosting","9":"tag-wordpress-security"},"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2021\/08\/essential-wordpress-security.jpg?fit=1200%2C628&ssl=1","jetpack_shortlink":"https:\/\/wp.me\/pbHhPQ-5oT","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/posts\/20763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/comments?post=20763"}],"version-history":[{"count":12,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/posts\/20763\/revisions"}],"predecessor-version":[{"id":28245,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/posts\/20763\/revisions\/28245"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/media\/28244"}],"wp:attachment":[{"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/media?parent=20763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/categories?post=20763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/tags?post=20763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}