Synthetic Industry

Troubleshooting guide · updated 2026-10-11

WordPress hardening: what each common measure does, what it cannot do, and a safe order

WordPress's own hardening guide calls its measures risk reduction, not elimination. Learn what each does, which caveats apply, and an order that protects you from breaking the site.

Start with what hardening is

WordPress publishes a hardening guide, and it describes its own measures as risk reduction, not risk elimination. That is the right way to read every checklist, including ours. Hardening makes the common attacks harder and leaves a record of what was done. It does not make a site unhackable, it does not replace backups, and it does not clean a site that is already compromised.

What the common measures do, and their caveats

Updates: old versions do not get security patches, so keep core, plugins and themes current and delete the ones you do not use. DISALLOW_FILE_EDIT removes the dashboard's theme and plugin code editor, a common first tool for an attacker who has one login, but WordPress says it does not stop malicious file uploads. File permissions should let the web server write only where it must; the guide gives example values of 755 for directories and 644 for files, and notes that automatic updates reset to those values. Passwords and two-step authentication protect the logins that everything else depends on, and SFTP keeps file-transfer credentials from travelling in the clear.

Some popular measures have limits. Changing the database table prefix blocks only some attacks. Renaming an administrator account is obscurity, which the guide itself calls unsound as a main strategy. Protecting the admin folder with server-level authentication adds a layer but can break features such as admin-ajax.php. Moving the configuration file is disputed among practitioners. Revoking database privileges is described as not recommended, because updates and plugins may need them.

  • Worth doing for most sites: updates, removing unused plugins, editor off, sensible permissions, strong logins with two-step.
  • Use with care: admin-folder protection, moving files, database privilege changes.
  • Low value alone: renaming the admin user, changing the table prefix.

A safe order

Hardening is a change to a live site, so protect it first. Confirm a backup you could actually restore. Update everything on a copy and test. Remove the plugins and themes you do not use after the owner approves the list. Review the administrator list with the owner, one account at a time. Switch off the dashboard code editor. Check and correct permissions against the host's recommendation. Turn on two-step sign-in for every administrator; the guide does not say how, and in practice this normally means a plugin or your host's login protection. After each risky step, load the agreed pages, submit a form and log in; undo any step that breaks them.

  • Backup, then updates on a copy, then removals, then users.
  • Editor and permissions next, then two-step sign-in.
  • Test after each change.

When not to harden

If the site shows pages you did not create, odd redirects, unknown administrators or unfamiliar files, or the host has flagged it, do not harden over the top. Hardening assumes a clean starting point. A compromised site should be restored or cleaned first, and then hardened. WordPress's guidance for a hacked site starts with documenting what you saw and resetting every password.

How the paid outcome is accepted

The fixed-price job for this is a published test price of £195, not yet tested with buyers, payable after sign-off. It works through a written ten-item checklist on one single-site WordPress installation. Each item is marked applied, declined or not possible, with a reason. The dashboard editor is confirmed switched off, every administrator is confirmed by you as a current person, and ten pages, one form and one log-in pass before and after. It is not an audit, penetration test or compliance advice, and it makes no claim that the site cannot be attacked.

Sources and limits

  • WordPress: Hardening WordPress Checked 2026-10-11.
    • The guide frames its measures as risk reduction, not risk elimination.
    • Keep core and plugins updated and delete unused plugins; DISALLOW_FILE_EDIT removes the dashboard code editor but does not stop malicious uploads; file permissions should limit write access, and automatic updates can reset permissions to 0644 and 0755.
    • Use strong passwords with two-step authentication and SFTP instead of FTP; protecting wp-admin with server authentication can break admin-ajax.php; changing the table prefix blocks only some attacks.
  • WordPress support: FAQ My site was hacked Checked 2026-10-11.
    • Guidance for a hacked site starts with documenting what you saw and resetting every password.