Most hacked WordPress sites share the same handful of problems. Five things you should do for every WordPress install — none of them complicated.
WordPress is the most widely used publishing platform on the web, which makes it the most targeted. Attackers don't need sophisticated techniques when so many sites share the same predictable default configurations. The good news is that the majority of compromises exploit basic, fixable problems — and fixing them isn't complicated.
WordPress used to create a default administrator account with the username "admin" during installation. A large portion of WordPress installs in 2010 still have this default in place. Every brute-force attack tool starts with "admin" as the username because it works so often.
Create a new administrator account with a non-obvious username, then delete the original "admin" account, transferring its posts to the new one. If an attacker doesn't know your username, they have to guess two things instead of one — that alone stops many automated attacks.
"password", "wordpress", your domain name, your business name, your name followed by a year — all of these are in every credential list attackers use. A strong password for 2010 means: at least 10 characters, mixed case, numbers, at least one symbol. Write it down somewhere physical if you need to. The inconvenience of a complex password is nothing compared to the cost of a compromised site.
If you have multiple administrator accounts (for different team members), each one needs its own strong unique password. One weak account is all it takes.
Covered in detail in a separate post, but worth repeating: an outdated WordPress install is a known target. Security releases patch publicly disclosed vulnerabilities — once the patch is out, the vulnerability is documented and attackers begin exploiting unpatched sites immediately.
Plugins are just as important as core. A vulnerable plugin is an entry point to your entire site. Check for updates at least weekly. Delete plugins you're not actively using — an inactive plugin that never gets updated is still an attack surface.
By default, WordPress puts your exact version number in the HTML source of every page, in a meta generator tag. This makes it trivial for scanners to identify which sites are running vulnerable versions. Remove it by adding this to your theme's functions.php:
remove_action('wp_head', 'wp_generator');
This doesn't make you more secure on its own — a site running an old version is still vulnerable — but it removes a signal that flags you as a target before an attacker has even looked at the site.
WordPress allows unlimited login attempts by default. A brute-force attack can try thousands of username/password combinations without any friction. The Login Lockdown plugin (and similar tools) locks out an IP address after a configurable number of failed attempts.
Even a limit of five attempts with a 30-minute lockout period makes automated brute-force attacks effectively useless. It won't stop a determined attacker with a large pool of IP addresses, but it will stop the vast majority of automated attack tools in use.
None of these steps guarantee your site will never be compromised. But most WordPress sites that get hacked have at least one of these basics missing. Fixing all five takes under an hour and makes your site a much less attractive target than the millions of sites that haven't.
DownUnder WP applies server-level rate limiting on login attempts for every hosted site as standard — protecting your wp-admin before a request even reaches WordPress.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.