All posts
November 2010·5 min read

5 WordPress security basics every site owner should know

Most hacked WordPress sites share the same handful of problems. Five things you should do for every WordPress install — none of them complicated.

Most WordPress compromises are preventable

WordPress is the most widely used publishing platform on the web, which makes it the most targeted. Attackers don't need sophisticated techniques when so many sites share the same predictable default configurations. The good news is that the majority of compromises exploit basic, fixable problems — and fixing them isn't complicated.

1. Don't use "admin" as your username

WordPress used to create a default administrator account with the username "admin" during installation. A large portion of WordPress installs in 2010 still have this default in place. Every brute-force attack tool starts with "admin" as the username because it works so often.

Create a new administrator account with a non-obvious username, then delete the original "admin" account, transferring its posts to the new one. If an attacker doesn't know your username, they have to guess two things instead of one — that alone stops many automated attacks.

2. Use a strong, unique password

"password", "wordpress", your domain name, your business name, your name followed by a year — all of these are in every credential list attackers use. A strong password for 2010 means: at least 10 characters, mixed case, numbers, at least one symbol. Write it down somewhere physical if you need to. The inconvenience of a complex password is nothing compared to the cost of a compromised site.

If you have multiple administrator accounts (for different team members), each one needs its own strong unique password. One weak account is all it takes.

3. Keep WordPress core and plugins updated

Covered in detail in a separate post, but worth repeating: an outdated WordPress install is a known target. Security releases patch publicly disclosed vulnerabilities — once the patch is out, the vulnerability is documented and attackers begin exploiting unpatched sites immediately.

Plugins are just as important as core. A vulnerable plugin is an entry point to your entire site. Check for updates at least weekly. Delete plugins you're not actively using — an inactive plugin that never gets updated is still an attack surface.

4. Remove your WordPress version number from public view

By default, WordPress puts your exact version number in the HTML source of every page, in a meta generator tag. This makes it trivial for scanners to identify which sites are running vulnerable versions. Remove it by adding this to your theme's functions.php:

remove_action('wp_head', 'wp_generator');

This doesn't make you more secure on its own — a site running an old version is still vulnerable — but it removes a signal that flags you as a target before an attacker has even looked at the site.

5. Limit login attempts

WordPress allows unlimited login attempts by default. A brute-force attack can try thousands of username/password combinations without any friction. The Login Lockdown plugin (and similar tools) locks out an IP address after a configurable number of failed attempts.

Even a limit of five attempts with a 30-minute lockout period makes automated brute-force attacks effectively useless. It won't stop a determined attacker with a large pool of IP addresses, but it will stop the vast majority of automated attack tools in use.

Security is a baseline, not a destination

None of these steps guarantee your site will never be compromised. But most WordPress sites that get hacked have at least one of these basics missing. Fixing all five takes under an hour and makes your site a much less attractive target than the millions of sites that haven't.


DownUnder WP applies server-level rate limiting on login attempts for every hosted site as standard — protecting your wp-admin before a request even reaches WordPress.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.