· updated 2026-10-07
Most of the breaches we have investigated were possible because of a handful of basics. These settings close them.
Access control
- Two-factor authentication on every administrator account.
- A separate account per person — no shared “admin” logins.
- Editor rights for anyone who does not need administrator.
- Login attempt limiting at server level, not only through a plugin.
Files and configuration
define( 'DISALLOW_FILE_EDIT', true );— the admin file editor off.- PHP execution blocked in
wp-content/uploads. - File permissions 644, directories 755,
wp-config.php600. - XML-RPC disabled if you do not use it.
Maintenance
- Updates on a schedule, with a backup first and testing.
- Unused themes and plugins deleted, not just deactivated.
- Backups with verified restores.
- Log monitoring: new users, file changes, failed logins.
Point ten surprises people most often: a deactivated plugin is still files on the server, reachable directly. If it contains a vulnerability, deactivation does not protect you.
All of this is included in technical maintenance; you can start with the free security check.