WordPress Security Hardening: A Practical Checklist
How WordPress sites actually get compromised, and the hardening that prevents it — updates, accounts, 2FA, file permissions, backups and server-level controls.
Read article7 guides on wordpress security
Hardening, backups, malware cleanup, user management and the boring hygiene that actually prevents WordPress sites from being compromised.
How WordPress sites actually get compromised, and the hardening that prevents it — updates, accounts, 2FA, file permissions, backups and server-level controls.
Read articleGetting HTTPS right on WordPress, fixing mixed content, and which security headers are worth setting — including how to deploy a CSP without breaking the site.
Read articlePlugins are how most WordPress sites get compromised. How to assess one before installing it, what to monitor afterwards, and when to remove it.
Read articleWhat the built-in roles can actually do, why Administrator is handed out too freely, how to create custom roles, and how to audit who has access to what.
Read articleWhat to do when a WordPress site is compromised: contain it, find the entry point, clean properly, get delisted, and stop it happening again.
Read articleHow WordPress logins are actually attacked, and the controls that stop it — two-factor authentication, rate limiting, password policy and account hygiene.
Read articleWhat to back up, how often, where to keep it, and how to test a restore — because a backup you have never restored is a hypothesis, not a backup.
Read articleI build custom WordPress websites, WooCommerce stores, REST APIs and headless builds. See my recent projects or my services in Mumbai.