Securing WordPress: what we do and what you do

The security of a WordPress site has two layers. The server layer is our responsibility: network, operating system, web server, PHP, backups and SSL. The WordPress layer is yours: core, theme, plugins, passwords and users. Most hacked sites we see did not get in through the server, but through a plugin that had not been updated for months or a password that was easy to guess.

Below is exactly what lies on which side, followed by five steps you carry out in an hour that remove the bulk of the risk. At the bottom you can read what to do if things go wrong anyway.

Who does what

Security that you attribute to the other party gets done by nobody. So here it is in black and white: what we do at platform level and what stays on your side.

What WWW4 does at platform level

This comes with every hosting plan and requires no setting, plugin or add-on from you.

  • DDoS protection at network level, so your site stays reachable during an overload attack
  • Daily backup of files and database, kept for 14 days
  • Free SSL certificate, renewed automatically, so traffic and logins are encrypted
  • Maintenance and security updates of the operating system, web server and the PHP versions we offer
  • Isolation between sites on the same server, so a neighbour's problem does not become yours

What you do at WordPress level

This lives in your installation and we cannot do it for you without intervening in your site.

  • Update WordPress core, theme and plugins, after a backup
  • Delete plugins and themes that are no longer maintained, rather than just deactivating them
  • Strong, unique passwords and two-factor authentication for every user who can log in
  • Restrict user roles: only whoever manages the site is an administrator, the rest are editors or authors
  • No account with the username 'admin'; that is the first one tried
  • Limit login attempts, so a password cannot be guessed endlessly
  • No cracked (nulled) themes or premium plugins from dubious sources; they often contain a backdoor
  • Remove old users: former employees, previous web developer, test accounts

What we deliberately do not promise: that a site cannot be hacked. Anyone who claims that does not know WordPress. What we can say is that a site that is up to date, carries no dead plugins and has decent logins is no longer an interesting target for the automated scans that sweep the internet every day.

About DDoS protection About backup & restore About SSL

Securing WordPress in an hour

Five steps, in this order. Anyone who does them once and then repeats a quarter of an hour monthly covers the bulk of the risk.

1

Take a backup and update everything

First make or check a backup. Then update WordPress core, your theme and all your plugins, and check the most important pages and forms after the update. If something breaks, roll back that one plugin and you know what is due for replacement. Outdated plugins are the most common cause of a hacked site.

2

Clean up what you do not use

Delete deactivated plugins and themes completely; deactivated is not gone, the code is still on the server and remains an entry point. For every remaining plugin, check when it was last updated. Silent for over a year? Look for an alternative. Also delete themes or plugins that do not come from the maker themselves.

3

Strengthen logins

Give every user a long, unique password and enable two-factor authentication. If there is an account with the username 'admin', create a new administrator with a different name, log in with it and delete the old account, assigning its content to the new user.

4

Review users and roles

Go through the user list. Who no longer works here, which test accounts or accounts from a previous web developer are still there? Delete them. Downgrade anyone who does not need to be an administrator to editor or author; someone who only writes articles does not need to be able to install plugins.

5

Limit login attempts and check the backup

Limit the number of login attempts, so a password cannot be guessed endlessly. Finally, check that you know how to request a restore and that the daily backup covers your complete site. A backup you do not know how to restore is an assumption, not a safety net.

Guide: updating WordPress safely

When things do go wrong

You recognise a hacked site by unknown administrators, pages or files you did not create, redirects to strange sites, a warning from the browser or from Google, or mail leaving from your domain without you sending it. Then do not keep working on the site and change your passwords first: WordPress, control panel, FTP and database.

The fastest way back is usually a restore from the backup from before the break-in, followed by immediately updating whatever the entry point was. Backups are kept for 14 days; the sooner you report it, the greater the chance that a clean version still exists. Then comes the clean-up work, which is set out step by step in the knowledge base.

What you report to us: your domain name, what you see and since when, and above all when the site was still in order. The latter decides which backup we restore. We restore the backup and look through the server logs with you; cleaning up and updating your WordPress installation stays on your side or with your web developer.

Guide: recovering a hacked website Contact support

Further reading

How we secure the platform itself is on the overarching security page. What is included specifically for WordPress in the hosting, on the hosting page.

Security at WWW4 WordPress hosting Jaan Performance Engine

Frequently asked questions about WordPress security

Both parties, each for one layer. WWW4 secures and maintains the server: network, operating system, web server, PHP, SSL and backups. Your WordPress installation itself, with theme, plugins, passwords and users, remains your responsibility. Your content lives in there too, and that is where most break-ins come in.
Through an outdated plugin or an outdated theme with a known vulnerability, through a weak or reused password, or through a cracked theme that already contained a backdoor at installation. These are automated scans sweeping the whole internet; they are not looking for a specific site but for a known weak spot. An up-to-date site with strong logins is not a target for those scans.
That is your choice; we do not supply one and do not prescribe one. The measures that deliver the most need no plugin: updating, cleaning up, strong passwords with two-factor authentication, restricted user roles. If you do choose a plugin, for example to limit login attempts, keep it just as up to date as the rest.
Do not keep working on the site and first change all your passwords: WordPress, control panel, FTP and database. Contact us with your domain name, what you see and when the site was still in order. We restore a backup from before the break-in; updating and cleaning up the installation afterwards is done by you or your web developer.
Fourteen days, of both files and database, with a new backup every day. So a break-in you notice within that period can be rolled back to a clean version. If you only notice it later, cleaning up is the only way. Reporting quickly pays off.
No. We update the server side: operating system, web server and the PHP versions we offer. A blind automatic update of WordPress, theme or plugins can break a site, and your content lives in there. So that stays with you, and the advice is: monthly, after a backup, with a check of the most important pages afterwards.
Yes. Automated attacks make no distinction between a large webshop and a small business site; they try the same leaked passwords everywhere. Two-factor authentication makes a guessed or leaked password worthless on its own. It costs every user five minutes once to set up.
Because it is the first username every automated attack tries. With a different username an attacker has to guess two things instead of one. Create a new administrator with a different name, log in with it and delete the old account, assigning its content to the new user.
Call us
Send an email