WordPress

WordPress Security Guide

By the Domain India teamPublished 5 min read
Knowledge base article
Contents (4 sections)

Most hacked WordPress sites fall to the same few things: an outdated plugin or theme, a weak or reused password, or too many administrator accounts. Fix those and you have stopped most attacks. This page is the short checklist; our full guides go deeper on each step.

Key takeaways

Keep WordPress core, plugins and themes updated, and delete what you don't use. Use unique passwords and turn on two-factor authentication for every administrator. Install one security plugin, turn off the dashboard file editor, force HTTPS, and keep your own backup copy off the server. On Domain India cPanel hosting, a server-side firewall and automatic malware cleanup already run for every account.

The full guides

For the complete hardening steps (wp-config.php, .htaccess, headers, database users), read the complete WordPress hardening guide. To choose and set up a plugin, see WordPress security plugins. If your site is already hacked, go straight to the hacked website checklist.

1. The essential checklist

  1. Update everything.
    Update WordPress core under Dashboard › Updates, and your plugins and themes. Delete plugins and themes you don't use; deactivated ones can still be attacked.
  2. Use strong, unique passwords
    from a password manager for WordPress, your hosting account and your email, and never use "admin" as a username.
  3. Turn on two-factor authentication
    for every administrator and editor, with an authenticator app.
  4. Install one security plugin,
    such as Wordfence, Solid Security or All-In-One Security, for login limits and alerts. Two security plugins together usually conflict.
  5. Turn off the file editor.
    Add define( 'DISALLOW_FILE_EDIT', true ); to wp-config.php, so a stolen admin login can't be used to paste code into a theme or plugin.
  6. Use HTTPS.
    Free SSL is included with your hosting; once the certificate is issued, set both addresses under Settings › General to https.
  7. Keep your own backups
    with a plugin that stores copies off the server, and test a restore now and then.

2. Habits that matter more than any plugin

  • Remove extra administrators. Every admin account is another password that can leak.
  • Never install nulled or pirated plugins and themes. They are a common way malware gets onto sites.
  • Block XML-RPC if you don't use it. Jetpack and some mobile apps need it; otherwise block it from your security plugin.
  • Hiding the login URL is optional. A plugin such as WPS Hide Login cuts noise from bots, but it is no substitute for 2FA and strong passwords.

The causes behind most hacks are explained in why and how WordPress websites get hacked.

3. What Domain India hosting already does

Web application firewall
On cPanel and DirectAdmin, ModSecurity runs Imunify360's full ruleset, so many attacks are blocked before they reach WordPress.
Automatic malware cleanup
On cPanel, Imunify360 removes malicious code it detects and keeps the original file for 14 days. You aren't emailed when it does, so keep your plugin's alerts on.
Account isolation
CloudLinux CageFS keeps each hosting account separate from the others on cPanel and DirectAdmin.
Weekly backups
JetBackup takes weekly backups on cPanel and DirectAdmin (Sunday, five copies), which you can restore yourself.
Server protection is not a clean-up service

The server scanner does not update your plugins or remove every backdoor. If your site is hacked, follow the hacked website checklist and restore a clean backup. See backup and restore with JetBackup.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

Prices on the cards exclude 18% GST.

Frequently asked questions

How do I secure my WordPress site?

Keep core, plugins and themes updated, delete what you don't use, use unique passwords with two-factor authentication, install one security plugin, turn off the file editor in wp-config.php, use HTTPS and keep your own off-server backups.

Which WordPress security plugin should I use?

One all-in-one plugin such as Wordfence, Solid Security or All-In-One Security is enough for most sites. Running two security plugins together often causes conflicts and lockouts.

What does DISALLOW_FILE_EDIT do?

It removes the theme and plugin file editor from the WordPress dashboard, so someone who steals an administrator login can't use it to paste malicious code into your files.

Does Domain India scan my site for malware?

On cPanel hosting, Imunify360 scans files and automatically removes malicious code it detects, keeping the original for 14 days. It does not update your plugins or remove every backdoor, so keep your own security habits.

How often is my WordPress site backed up?

On cPanel and DirectAdmin hosting, JetBackup takes weekly backups on Sundays and keeps five copies. Keep your own off-server backup as well.

Ready to lock down your site? Work through the checklist today, then the hardening guide. For help with your account, open a support ticket or use our 24/7 live chat.

Host WordPress with server-side protection

A web application firewall, automatic malware cleanup, account isolation and weekly backups on cPanel hosting.

See cPanel plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app