Written by Noah Britton on 07/06/2018

Websites are hacked by autonomous machines these days… not by humans hacking individual sites. These machines (aka bots) search the internet for vulnerable websites day and night.

We get calls every month from people whose websites got hacked and I have some very specific things for you to do if you own a WordPress website.

Backup your website daily

1. Backup your website daily. Don’t assume your web hosting does this for you (many do not or if they do they charge you to access it and it only goes back 30 days).

Update your WordPress themes

2. Update your WordPress themes, plugins, and core software once a week. This is the #1 reason for hacked WordPress websites and it’s simple to do. You just need to have diligence when doing it. Check out our Care Plans, as we do not recommend a DIY approach.

Never use admin as a username

3. Never use admin as a username. That is what WordPress comes with out of the box and it should be changed immediately. Create a new administrative level user and delete admin.

Use a super secure password

4. Use a super secure password and store it in a program like Lastpass.com so that you don’t have to remember it. A password should be so secure that it’s impossible to memorize. Think lots of special characters and uppercase/lowercase combos.

Don't use the default wp-admin URL for your dashboard

5. Don’t use the default wp-admin URL for your dashboard. Use WPS-Hide Login plugin to do just that!


6. Install Wordfence there are way too many options to talk about here it audits your website security, lets you do virus checks, and even lets you block whole countries from viewing your website.

Dont give out your login info

7. Don’t give out your login info. Instead, create a separate administrative login for trusted developers to use. That way you can turn it off.

Noah Britton

Noah Britton is the founder of Thrive with 18 years of experience in the web industry and 10 years with WordPress.