• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

Spectrum Group Online

Decisions Made with Data.

  • Services
    • Digital Marketing
    • SEO
    • Google Analytics
    • Pay Per Click
    • WordPress Websites
  • Pricing
  • About
    • Our Difference
    • Who We Are
    • Client Testimonials
    • Case Studies
    • Certifications
    • Contact Us
  • Resources
    • Blog
    • eBooks
    • Tools We Use
  • Free Strategy Call
  • Services
    • Digital Marketing
    • SEO
    • Google Analytics
    • Pay Per Click
    • WordPress Websites
  • Pricing
  • About
    • Our Difference
    • Who We Are
    • Client Testimonials
    • Case Studies
    • Certifications
    • Contact Us
  • Resources
    • Blog
    • eBooks
    • Tools We Use
  • Free Strategy Call

WordPress Security Best Practices

January 31, 2017 //  by Massimo Paolini//  Leave a Comment

Updated January 12, 2023

Reading Time: 2 minutes

Hardening Your WP Installation

WordPress security has come a long way since its inception back in 2003. Built on a foundation that’s free and open source, it’s content management system structure can make it a target for nefarious hackers especially if you don’t know what you’re doing. As part of every new website project, I make changes to the basic WordPress installation to keep the bad guys out and the good stuff in. If you’re a newbie to website management, here are several critical WordPress security principles to follow:

2025 Business Website Checklist

Name(Required)
Privacy(Required)
Stay Informed
This field is for validation purposes and should be left unchanged.

Learn More

In this Free eBook:

  • Learn website requirements
  • Configure technical settings
  • Improve user-experience
  • Do optimization & Tracking

Change the Table Prefix

There is a default prefix that’s part of WordPress’ standard installation. If it’s a default, then you know it’s not a secret and therefore presents a WordPress security risk. I routinely change the table prefix; we recommend modifying the standard prefix of “wp_.”

Change Default Admin Account Login Info

If you have “admin” as your administrator username, then you’re hanging this sign on your website: “feel free to break in and mess stuff up.” We counsel our clients to use strong passwords that include numbers and special characters. Worried that you’ll forget this complicated password and get continually locked out? Then consider using a password vault like LastPass.

Keep WordPress Version Secret

My philosophy is to keep a website’s core up-to-date. Meaning, keep the WordPress code and plugins current with the latest possible versions. However, I keep the WordPress version hidden. Note: there are lots of plugins that let you do this simply.

Add 2-Step Authentication

Adding 2-step authentication provides yet another layer of protection. When logging into WordPress you enter the username and password; the user name can be guessed by simply looking at authorship on blog posts. Users often use easy-to-remember passwords that are easily cracked by brute force software. Requiring a security code makes it that much harder to break into your website. There are two 2-step plugins I recommend: Google Authenticator and Clef. Note: you only need one.

Use VaultPress’s Protect & Sucuri

Part of JetPack, VaultPress performs comprehensive security scans.  For a nominal annual fee you get brute force attack protection, uptime monitoring, and priority support. Sucuri provides two paid services: cleaning up of a hacked site as well as protection for DDoS (Distributed Denial of Service) attacks, vulnerability exploit attempts and more brute force defense.

Automated Backups

When it comes to data, it pays to backup. One of my favorite plugins is WP-DBManager. As your database (which includes content, settings, etc) is the backbone of your website, I also recommend using a cloud backup service such as VaultPress.  Using a belt and suspenders may be a fashion faux pas, but if you’ve ever had to restore a website after a catastrophic event, you’ll appreciate this redundant approach.

Use Plugins that Use Coding Best Practices

If you have commissioned a coder to develop a custom WordPress theme or plugin, make sure they follow WordPress Coding Standards.  If their response is “huh?” when asked, then look for another developer. By not following the Codex’s best practices, you are putting WordPress security at risk.

What other practices do you use to keep your website safe?

Category: Web Design// Author: Massimo Paolini

About Massimo Paolini

Massimo is Co-CEO and Chief Data Scientist. On the web since the 90’s and a Google Partner since 2014, his expertise includes technical SEO, search marketing, marketing analytics/analysis, and online advertising. Massimo has an innate ability to sift through a sea of data, uncovering insights that formulate results-oriented strategies. He has taught Digital Marketing, Google Ads and SEO at UC Berkeley Extension since 2014—and presented at international search marketing conferences like SMXL in Milan.

Previous Post: « Preparing Your PPC For A Website Migration
Next Post: Build an Online Personal Brand »

Reader Interactions

Comments

  1. Buford Chase

    March 19, 2013 at 10:31 pm

    An impressive share! I’ve just forwarded this onto a coworker who had been doing a little homework on this. And he actually bought me lunch because I found it for him… lol. So let me reword this…. Thank YOU for the meal!! But yeah, thanx for spending time to discuss this issue here on your site.

    Reply
    • Alyson Harrold

      March 21, 2013 at 12:29 pm

      Glad we could help. Hope it was a good lunch 😉

      Reply
  2. kristy_barba

    October 14, 2018 at 1:47 am

    Hey There. I came across your blog using search. That is a really well crafted
    article. I’ll be sure to bookmark it and get back to learning much more of
    your
    useful information. Thanks a lot for the post.
    I’ll be back 🙂

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Categories

  • Case Studies
  • News & Events
  • PPC
  • Sales
  • SEO
    • Content
    • Links
    • Local SEO
    • Schema
  • Social Media
  • Web Analytics
  • Web Design

Most Relevant

4 Tools for Effective SEO Link Building

10 Tips to Create Great Customer Testimonials

Basics of SEO

How to Interview a Website Designer or Developer

Blog Marketing: 10 Sources for Inspiration

Footer

Spectrum Group Online

About Us
Certifications
Contact Us

[email protected]
(408) 675-0330
San Jose, CA 95129

Founded by Massimo Paolini and Alyson Harrold in 2011

Stay On Top Of Your Game

Digital Marketing never stands still. Keep up with the latest online marketing trends, sign up for our monthly newsletter. We promise no SPAM and no sales pitches.

Privacy*
Privacy
This field is for validation purposes and should be left unchanged.

Twitter LinkedIn Facebook Instagram YouTube

Copyright © 2025 Spectrum Group Online, LLC | All rights reserved | Privacy Policy | Site Map

Tell us about yourself.

Step 1 of 3

33%
Which option best describes you?(Required)
How many full-time employees does your company have?(Required)
What is your company's annual revenue?(Required)
This field is for validation purposes and should be left unchanged.