Most hacked WordPress sites fall to the same few things: an outdated plugin or theme, a weak or reused password, or too many administrator accounts. Fix those and you have stopped most attacks. This page is the short checklist; our full guides go deeper on each step.
Keep WordPress core, plugins and themes updated, and delete what you don't use. Use unique passwords and turn on two-factor authentication for every administrator. Install one security plugin, turn off the dashboard file editor, force HTTPS, and keep your own backup copy off the server. On Domain India cPanel hosting, a server-side firewall and automatic malware cleanup already run for every account.
For the complete hardening steps (wp-config.php, .htaccess, headers, database users), read the complete WordPress hardening guide. To choose and set up a plugin, see WordPress security plugins. If your site is already hacked, go straight to the hacked website checklist.
1. The essential checklist
- Update everything.Update WordPress core under Dashboard › Updates, and your plugins and themes. Delete plugins and themes you don't use; deactivated ones can still be attacked.
- Use strong, unique passwordsfrom a password manager for WordPress, your hosting account and your email, and never use "admin" as a username.
- Turn on two-factor authenticationfor every administrator and editor, with an authenticator app.
- Install one security plugin,such as Wordfence, Solid Security or All-In-One Security, for login limits and alerts. Two security plugins together usually conflict.
- Turn off the file editor.Add
define( 'DISALLOW_FILE_EDIT', true );towp-config.php, so a stolen admin login can't be used to paste code into a theme or plugin. - Use HTTPS.Free SSL is included with your hosting; once the certificate is issued, set both addresses under Settings › General to https.
- Keep your own backupswith a plugin that stores copies off the server, and test a restore now and then.
2. Habits that matter more than any plugin
- Remove extra administrators. Every admin account is another password that can leak.
- Never install nulled or pirated plugins and themes. They are a common way malware gets onto sites.
- Block XML-RPC if you don't use it. Jetpack and some mobile apps need it; otherwise block it from your security plugin.
- Hiding the login URL is optional. A plugin such as WPS Hide Login cuts noise from bots, but it is no substitute for 2FA and strong passwords.
The causes behind most hacks are explained in why and how WordPress websites get hacked.
3. What Domain India hosting already does
The server scanner does not update your plugins or remove every backdoor. If your site is hacked, follow the hacked website checklist and restore a clean backup. See backup and restore with JetBackup.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
Prices on the cards exclude 18% GST.
Frequently asked questions
How do I secure my WordPress site?
Keep core, plugins and themes updated, delete what you don't use, use unique passwords with two-factor authentication, install one security plugin, turn off the file editor in wp-config.php, use HTTPS and keep your own off-server backups.
Which WordPress security plugin should I use?
One all-in-one plugin such as Wordfence, Solid Security or All-In-One Security is enough for most sites. Running two security plugins together often causes conflicts and lockouts.
What does DISALLOW_FILE_EDIT do?
It removes the theme and plugin file editor from the WordPress dashboard, so someone who steals an administrator login can't use it to paste malicious code into your files.
Does Domain India scan my site for malware?
On cPanel hosting, Imunify360 scans files and automatically removes malicious code it detects, keeping the original for 14 days. It does not update your plugins or remove every backdoor, so keep your own security habits.
How often is my WordPress site backed up?
On cPanel and DirectAdmin hosting, JetBackup takes weekly backups on Sundays and keeps five copies. Keep your own off-server backup as well.
Ready to lock down your site? Work through the checklist today, then the hardening guide. For help with your account, open a support ticket or use our 24/7 live chat.
A web application firewall, automatic malware cleanup, account isolation and weekly backups on cPanel hosting.
See cPanel plans