cPanelOps · Hosting guides for site operators
cPanelOpsv2.2.0
Plain-English cPanel help from the team behind FirstResponderHost
26 guides live
CpanelOps / PageOps

Home › Guides

Security

WordPress security basics on cPanel hosting: a ten-step checklist

Most hacked WordPress sites were not targeted. They were found by a script looking for one of a few common weaknesses. Close those and you are ahead of nearly everyone.

WordPress itself is not the weak point. The overwhelming majority of break-ins come through an outdated plugin, a guessed password, or a leftover file. Automated scanners test every site they can find for those three things, all day. This checklist closes them. Most steps take a minute.

1. Turn on automatic updates

Under Dashboard > Updates, make sure automatic updates are enabled for WordPress itself. On the Plugins screen, enable auto-updates for each plugin. The risk of an update breaking something is real but small, and far smaller than the risk of running a plugin with a published hole. A weekly backup covers the first risk.

2. Delete what you do not use

A deactivated plugin or theme still has its files on the server, and those files can still be attacked. Delete every plugin you are not using and every theme except the active one and one default theme as a fallback.

3. Replace abandoned plugins

On each plugin's page in the directory, look at "Last updated". A plugin untouched for two years or more will not get a fix when a problem is found. Find a maintained alternative.

4. Fix the logins

  • No account named admin. Create a new administrator with a different name, sign in as it, and delete the old one, assigning its posts to the new user.
  • A long, unique password for every administrator and editor, kept in a password manager.
  • Two-step sign-in for administrators, with one of the established plugins for it.
  • Remove users who no longer need access, and lower roles that are higher than the job needs.

5. Limit sign-in attempts

By default WordPress allows unlimited password guesses. A login-limiting plugin, or the equivalent feature in a security plugin, blocks an address after a handful of failures. Many hosts also apply this at the server; ask yours.

6. Switch off the built-in file editor

The dashboard includes an editor for theme and plugin code. Anyone who gets into an administrator account can use it to plant malicious code in seconds. Add this line to wp-config.php:

define('DISALLOW_FILE_EDIT', true);

7. Lock down wp-config.php

This file holds the database password. Set its permissions to 600 in File Manager so only your account can read it. See the permissions guide for how.

8. Stop PHP running in the uploads folder

The uploads folder should contain images and documents, never code. A common attack uploads a PHP file disguised as an image and then runs it. Create a file named .htaccess inside wp-content/uploads containing:

<FilesMatch "\.php$">
  Require all denied
</FilesMatch>

Uploaded files are still served normally; only PHP files in that folder are refused.

9. Turn off XML-RPC if you do not use it

xmlrpc.php is an older way for outside apps to talk to WordPress, and a favorite target for password guessing. If you do not use the WordPress mobile app or a plugin that depends on it, block it in the main .htaccess:

<Files "xmlrpc.php">
  Require all denied
</Files>

If something stops working afterwards, remove the block; that feature needed it.

10. Back up, off the server

Every other step lowers the odds. A recent backup stored somewhere other than the hosting account is what turns a break-in from a disaster into an afternoon's work. The backup guide covers how to make one and how to prove it restores.

Things that matter less than they sound

  • Hiding the login address. It reduces noise in your logs. It does not stop an attack through a vulnerable plugin, which never touches the login page.
  • Changing the database table prefix. Negligible benefit on an existing site, and easy to break something doing it.
  • Installing several security plugins. They overlap and slow the site. One, properly configured, is enough.

A monthly five-minute check

  1. Updates screen: nothing waiting.
  2. Users screen: no accounts you do not recognize.
  3. Plugins screen: nothing inactive, nothing abandoned.
  4. Latest backup: exists, and is recent.

Common questions

Do I need a paid security plugin?

Not to cover the basics above. The free tiers of the established plugins handle login limiting and file-change alerts. Paid tiers add faster firewall rule updates and cleanup services, which are worth considering for a site that earns money.

Is my host responsible for security?

The host secures the server. What you install on your account, and the passwords you choose, are yours. Most hosts will help after a break-in, but few will clean a site for free.

How would I know if I had been hacked?

Signs include unfamiliar admin users, pages redirecting to other sites, a warning from the browser or from Google, files modified on dates you did nothing, and a sudden jump in outgoing email. If you see any of them, follow the first-hour guide.

Spotted a mistake, or a step that has changed?

cPanel's screens differ a little between versions and hosts. Tell us at info@firstresponderhost.com and we will correct the guide.

More guides