The 2026 WordPress hardening checklist for UK businesses.
Ten practical steps to close the gaps attackers exploit most, without turning your website into a fragile collection of security plugins.
Most WordPress compromises do not begin with a sophisticated zero-day. They usually start with an overlooked update or an old administrator account. Hardening means closing these ordinary gaps.
Your baseline should be boring and complete.
The goal is not to install every security product you can find. You just need to reduce the ways an attacker can get in and make sure you can recover if they do.
The five controls to put in place first
- Keep WordPress core, themes, and plugins patched on a defined schedule.
- Remove inactive plugins and themes instead of simply deactivating them.
- Require unique passwords and multi-factor authentication for every administrator.
- Keep an off-site backup that you can restore and test regularly.
- Review administrator accounts, file permissions, and hosting access at least quarterly.
Updates are a security control, not housekeeping.
Create a simple patching rhythm. Review critical updates promptly and test material changes on a staging copy. Unused plugins deserve no place in production, so delete them.
Treat every administrator account as a key to your business.
Use named accounts, strong unique passwords, and multi-factor authentication. Remove access the moment a contractor or employee no longer needs it. Avoid shared logins since they make incident investigation almost impossible.
A backup is only real if it restores. Keep a separate, off-site copy and rehearse a restore before you need one. Ransomware and accidental deletion both become manageable when recovery is proven.
Give the site less to defend.
Review file permissions, disable features you do not use, and keep production separate from testing tools. Your host, forms, and third-party integrations all belong on the same security inventory.
Monitoring catches the small changes.
File-integrity checks and regular vulnerability scans are practical early-warning systems. Pair them with a clear incident contact.
What to do next
Start with the areas you can verify today like current updates and a tested backup. Then ask for an independent view of the gaps your team may not be equipped to see.
Keep reading
Security should feel manageable.
Explore practical guidance for your team, or let us identify the gaps in a free 30-minute assessment.