WordPress Security: Best Practices to Keep Your Site Safe in 2025-2026
Most hacked WordPress sites were not beaten by a genius. They were neglected: an update deferred for a season, a backup nobody ever restored, a plugin installed in 2019 and untouched since. Hardening gets the glory — firewalls, locked-down config files — but safety mostly comes from maintenance: small, boring, scheduled work. Here is the rhythm we recommend to every client site we touch.
The weekly fifteen minutes
WordPress core can auto-update for security releases; plugins need a human decision, because an update can break custom code. The clean habit is wp-cli with fifteen spare minutes:
wp core update
wp plugin update --all
wp theme update --all
wp db export backups/db-$(date +%F).sql
The export line runs first in practice, guaranteeing a rollback that does not depend on your host's mood. Click through the admin and two public pages afterwards, and you are done for the week. PHP matters on the same clock: be on 8.3 or newer, since PHP 7.4 stopped receiving security fixes in late 2022 and plenty of hosts still quietly allow it.
Plugin hygiene as a quarterly audit
Twice a year, sit down with the plugin list. Deactivated plugins still ship their vulnerabilities to scanners, so removal — not deactivation — is the hygienic move. Question every survivor: when was its last update, does the developer still exist, does the site actually use it? New plugins come from the official directory or the developer you paid — nowhere in between — and a nulled premium theme is an unlocked door that eventually someone tries.
Backups on a schedule, restores on a drill
Daily off-site backups with UpdraftPlus or BlogVault to S3, Backblaze or even Drive, retaining at least two weeks so a slow-burning hack cannot overwrite your clean restore point. Then the part everyone skips: once a quarter, restore one backup to a staging site and click around. A backup nobody has restored is a rumour about your data, not a plan.
Watch it while you sleep
UptimeRobot pings the site free every few minutes and tells you when it falls over. Wordfence or Solid Security sends file-change alerts the moment a core file is touched — how you learn about an intrusion in hours instead of months. Subscribe to the Patchstack or Wordfence Intelligence advisories so a newly disclosed plugin hole reaches you before it reaches a bot.
Passwords as routine, not heroics
A password manager for every admin account, two-factor on every login that matters, and the part people forget: credentials rotated the day a developer or agency stops working on the site. Access you forgot you granted is access you cannot audit.
Archivists in Gaza digitize and duplicate everything they can, because what is not backed up can be erased — there, a backup is an act of memory, not merely maintenance. That reframed how seriously I take the boring part of this job.
Travel documents live on the same clock: passports expiring quietly, visa windows opening and closing, NICOP renewals nobody memorises. We run a small expiry-check service for our travellers at HTG Travels — the same discipline as the checklist above, applied to the folder that carries your name. Renew before you need to; it is the cheapest travel insurance there is.




