MB Bluejuice
Security

WordPress hardening: 12 settings worth doing today

Concrete steps without extra plugins that genuinely reduce the chance of a breach.

· updated 2026-10-07

Most of the breaches we have investigated were possible because of a handful of basics. These settings close them.

Access control

  1. Two-factor authentication on every administrator account.
  2. A separate account per person — no shared “admin” logins.
  3. Editor rights for anyone who does not need administrator.
  4. Login attempt limiting at server level, not only through a plugin.

Files and configuration

  1. define( 'DISALLOW_FILE_EDIT', true ); — the admin file editor off.
  2. PHP execution blocked in wp-content/uploads.
  3. File permissions 644, directories 755, wp-config.php 600.
  4. XML-RPC disabled if you do not use it.

Maintenance

  1. Updates on a schedule, with a backup first and testing.
  2. Unused themes and plugins deleted, not just deactivated.
  3. Backups with verified restores.
  4. Log monitoring: new users, file changes, failed logins.

Point ten surprises people most often: a deactivated plugin is still files on the server, reachable directly. If it contains a vulnerability, deactivation does not protect you.

All of this is included in technical maintenance; you can start with the free security check.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.