Lock Down Your WordPress Site Before Attackers Find the Door
WordPress security hardening and malware prevention by a developer with 6+ years WordPress experience. I implement login protection, file integrity monitoring, WAF rules, and backups — proactive security, not just cleanup.
A Default WordPress Installation Is Configured for Convenience, Not Security
Out of the box, WordPress uses predictable paths like wp-login.php and /wp-admin/, default database table prefixes, and no rate limiting on login attempts. It allows file editing from within the dashboard. Plugins can be installed without review. These defaults make WordPress easy to set up — and easy for attackers to exploit at scale.
Automated scanners probe millions of WordPress sites every day looking for known plugin vulnerabilities, xmlrpc.php exploits, default admin usernames, and weak credentials. Brute force bots run tens of thousands of login attempts per hour against unprotected sites. Hardening closes the doors that default configuration leaves wide open.
The most dangerous vulnerabilities often come from plugins that are installed but no longer actively maintained. A single outdated plugin with a known CVE is all an automated scanner needs. Plugin auditing and timely updates are not optional — they are the front line of WordPress defense.
Systematic WordPress Hardening Across Every Attack Vector
Based in Davao City, Philippines, I implement a complete WordPress security hardening engagement — covering the file system, database, login layer, plugin ecosystem, and network perimeter. Each hardening measure is documented, verified, and explained so you understand what changed and why.
- File and directory permissions set to block unauthorized writes
- Two-factor authentication enforced for all admin accounts with brute force lockout
- Plugin and theme audit against known CVE databases — outdated and vulnerable plugins removed
- WAF rules blocking SQL injection, XSS, and WordPress-specific attack patterns
- xmlrpc.php locked down, admin URL changed, file editing disabled from dashboard
WordPress Security Hardening by Attack Surface Each item targets a specific attack vector that attackers actively exploit against WordPress sites.
Security Hardening Checklist
A 30-point security checklist applied to your WordPress installation — covering core configuration, file permissions, login settings, plugin status, SSL validity, exposed files, and server headers. Each item verified and documented.
Login Protection
Login attempt rate limiting configured to block brute force attacks. Admin username changed from the default. wp-login.php access restricted by IP or CAPTCHA. Login page URL optionally moved to a non-standard path.
File Permission Hardening
File and directory permissions set to WordPress security standards: 755 for directories, 644 for files, 400 for wp-config.php and .htaccess. PHP execution blocked in the uploads directory to prevent uploaded malware from running.
Database Security
WordPress database table prefix changed from the default wp_ to a randomized string. Database user privileges reviewed and trimmed to the minimum required. wp-config.php secured with restricted file permissions and moved above webroot where possible.
Plugin Audit
Every installed plugin and theme checked against the WPScan vulnerability database and WordPress.org repository. Plugins with known unpatched CVEs flagged for immediate removal or replacement. Abandoned plugins assessed and removed or substituted.
Two-Factor Authentication
TOTP two-factor authentication configured for all administrator and editor accounts using Google Authenticator or Authy. Backup codes generated. 2FA enforced at the user level so it cannot be disabled without admin credentials.
WordPress Security Packages Choose one-time hardening, ongoing monitoring, or emergency response — all at fixed, transparent rates.
One-time project
Ideal for: Sites that need a complete security baseline set up once, with no ongoing subscription.
- Full 30-point security audit
- Core WordPress hardening
- Login protection and rate limiting
- Two-factor authentication setup
- File permission lockdown
- Plugin and theme vulnerability audit
- Documented hardening report
per month
Ideal for: Sites that want continuous protection, monthly plugin updates, and incident response included.
- Everything in One-Time Hardening
- Daily automated malware scans
- File integrity monitoring with alerts
- Monthly plugin and theme update management
- Blacklist status monitoring
- Uptime monitoring with instant alerts
- Priority incident response (within 24 hours)
- Monthly security health report
One-time
Ideal for: Sites that have been compromised and need immediate investigation, cleanup, and hardening.
- Priority response within 2 to 4 hours
- Full malware and backdoor removal
- Database injection cleanup
- Root cause identification
- Post-cleanup WordPress hardening
- Google and Sucuri blacklist removal request
- 30-day post-cleanup monitoring
WordPress Hardening — Step by Step
Security Audit
Full scan of your WordPress installation: plugin versions checked against the CVE database, file permissions reviewed, user accounts audited, login configuration assessed, SSL status verified, and server response headers analyzed.
Plugin Cleanup
Vulnerable, outdated, and abandoned plugins identified. Alternatives recommended for any that must be removed. All remaining plugins updated to their latest secure versions before hardening proceeds.
Core and File Hardening
File permissions corrected, wp-config.php secured, file editing disabled from the admin dashboard, directory browsing blocked, PHP execution blocked in the uploads folder, and xmlrpc.php restricted to only the methods your site genuinely needs.
Login and Access Control
Two-factor authentication configured and enforced for all admin users. Login attempt limits applied. Admin username reviewed and changed if set to the default. Admin URL optionally relocated to a non-standard path.
WAF and Documentation
Web Application Firewall rules configured and verified. All changes documented in a full hardening report — what was changed, why it was changed, and what attack it prevents. You own this document regardless of future engagement.
Hardening That Goes Beyond Installing a Security Plugin Real WordPress security requires configuration changes at every layer — not just activating a plugin and hoping for the best.
Every Attack Surface Addressed
File system, database, login, plugin ecosystem, and network perimeter — not just the application layer that security plugins cover. Attackers probe every layer; hardening must match.
Two-Factor Authentication That Gets Used
Configuring 2FA that admins can disable because it feels inconvenient is worthless. I enforce TOTP 2FA at the user level with backup codes — admins cannot bypass it without proper credentials.
Plugin Audit With Real CVE Data
Every plugin is checked against the WPScan vulnerability database. Outdated plugins with known unpatched vulnerabilities are the leading cause of WordPress compromises — this step is non-negotiable.
PHP Execution Blocked in Uploads
Attackers who cannot exploit a vulnerability often try uploading a PHP file through a form or media uploader. Blocking PHP execution in the uploads directory eliminates this attack vector entirely.
xmlrpc.php Attack Prevention
The xmlrpc.php endpoint is a well-known target for credential stuffing and DDoS amplification attacks. I restrict it to only the methods your site actually requires — or disable it entirely if your site does not need it.
Documented, Not Just Done
Every hardening change is written up — what was changed, how to reverse it if needed, and what attack it prevents. When a future developer touches the site, they understand the security configuration.
WordPress Sites Secured Before and After Attack
"My website was receiving hundreds of failed login attempts every day. I could see it in the logs but did not know what to do. Johnbert set up login rate limiting, two-factor authentication, changed the admin URL, and configured Cloudflare rate limiting. The brute force attempts still happen but nothing gets through. Peace of mind I did not have before."
"After a previous hack, I wanted proper protection before rebuilding. Johnbert found four plugins with known vulnerabilities, fixed file permissions that had been set incorrectly during my original setup, and configured Wordfence properly. I have not had an incident since."
"I manage WordPress sites for eight clients and needed a consistent security baseline across all of them. Johnbert documented a hardening checklist for our agency and implemented it across every site. He also set up centralized monitoring so I receive one report covering all eight. Very thorough, very clear documentation."
WordPress Security Hardening — Frequently Asked Questions
Johnbert Oñez
AI Solutions Engineer & Full Stack Developer · 6+ yrs · 50+ projects
Based in Davao City, Philippines. Specialises in production AI systems, full-stack web applications, and WordPress. Remote-first, async-friendly, fixed-fee projects.
Explore Related Services
Got a project in mind?
Let's build it.
AI systems, SaaS platforms, WordPress solutions — whatever the scope, I bring craftsmanship and precision from day one.