Fellside Studio

How do I keep my WordPress website secure?

The problem with WordPress Security

WordPress is a fantastic platform for building and editing websites. It is built and maintained by a community of developers and can be extended with free themes and plugins. These are all fantastic benefits, but they also create additional opportunities for things to go wrong if a website isn't properly maintained.

Because WordPress can be extended in so many ways, there are also more potential points of failure. A vulnerable plugin, an outdated theme, or poor security practices can all introduce risks.

Security Plugins

A security plugin is a great place to start. Plugins like Wordfence and Sucuri can be installed and will continually monitor your website. They can flag things like your site's core files being modified, critical vulnerabilities, and block attackers from trying to force their way into your website.

Wordfence is free to install and gives a really good base layer of protection, with a firewall that is regularly updated to block newly discovered threats, helping protect websites from known attacks before they become a problem.

Updates to WordPress, Themes, and Plugins

To a hacker, there’s nothing better than an out of date WordPress site. WordPress updates contain critical security patches, closing potential vulnerabilities down so that hackers can’t exploit them.

If your website hasn’t been updated, then there could be any number of unpatched vulnerabilities that attackers could make use of. Making sure your website is up to date is one of the simplest ways to ensure your website has a basic level of security. This is one of the key reasons regular website maintenance is so important.

Backups

Whilst they don’t offer any security protection, having a website backup will make sure that if disaster does strike, you have a clean copy of your website that you can revert to quickly.

For WordPress, there are plenty of free plugins that can handle this automatically with one of the most well-known being UpdraftPlus. We’d recommend setting a scheduled backup for at least once per month as a minimum, and if you’re making updates more often than that then simply increase the frequency.

You’ll be glad of a backup if you ever run into any critical issues on your site. And remember, these issues can also be caused by a failed update, or a dodgy plugin. It’s not always intentional.

Make sure you have a strong password

We’d think in 2026 that this one goes without saying, but we do unfortunately still see passwords along the lines of MyBusinessName2026, or even worse we recently saw a password that was the businesses’ phone number.

If I were an attacker, your business name would be in the 1st 10 passwords I would be trying, right after letmein and password123. And remember attackers aren’t sitting manually typing these in, there are bots that will constantly attempt to brute force their way into your website, with multiple attempts per second.

Strong passwords are hard to remember, but there are tools like 1password, and even the built-in Google Password Manager in Chrome that will remember passwords for you.

Need help creating a strong password? Sites like Correct Battery Horse Staple can generate a strong password for you.

So, with a site to generate a password, and your browser remembering what you set it to, there’s really no excuse for having a weak password!

Enable Multi-Factor Authentication

We’re sorry, we know it’s a pain but adding MFA (Multi Factor Authentication) is one of the best ways to ensure only you can login to your website.

We know it's an extra step every time you log in, but MFA is one of the most effective ways to secure your website. Most MFA solutions use an authentication app on your phone to generate a time-sensitive code that only you can access.

For WordPress, plugins like WP 2FA are free to install and configure, and will give that additional layer of security.

Secure Web Hosting

This is a big one, and unfortunately it’s not always something you can control.

Hosting providers generally keep things up to date, but new versions of key software like Apache, PHP, and MySQL are released frequently that include security patches.

Similar to WordPress it’s again important to ensure that these services are maintained to give a good base layer of security.

For this reason, it’s always worth checking what your website host does for security, what versions of key software they run, and in the same vein choosing the cheapest provider may well mean you’re actively choosing an outdated, and sometimes insecure platform.

Security is an Ongoing Process

Website security isn't something you do once and forget about. New vulnerabilities are discovered every day, plugins are updated regularly, and attack methods continue to evolve. By keeping your website updated, using strong passwords, enabling MFA, maintaining backups, and choosing reliable hosting, you'll already be ahead of many small business websites.

The Alternative

If you'd rather focus on running your business than worrying about WordPress security, we're here to help.

We can carry out an initial security audit, identify any vulnerabilities, ensure your website is fully updated, and provide ongoing maintenance to keep everything secure and running smoothly.

Whether you need a one-off review or ongoing website maintenance, get in touch and we'll be happy to help.

Have a Project in Mind?

Let's build a website that complements your business, and helps generate leads.

Request a Quote