10 Basic Tips to Keep Your WordPress Blog Secure
90% of the serious bloggers out there are using WordPress as their blogging platform. When it’s crowded, robbers will be there obviously; here we call them hackers. Of course WordPress is most secured than any other platform. But still remember that hackers are smart & intelligent than programmers. So, be cautious & observe every moment in your online presence…

# 1 Keep Up to Date
First thing you have to Do is, just keep your WordPress & Plugin collection up to date. You will see notification in your admin panel time to time or just install Auto upgrade plugin, which will do the task for you just in 5 clicks. It will take care about the back up too.
Be up to date with your WordPress plugins too. Just go to your plugins section in your dashboard and click on the auto upgrade to up to date with the plugins. Keeping all the things up to date will be the top most & basic important thing to secure your online presence.
# 2 Beware of Free Themes & Plugins
It’s been found that WordPress blogs are being hacked very often in recent days. Only the main reason behind this is downloading free themes & plugins from unauthorized sites. WordPress became very popular with its awesome API and amount of themes & plugins available for free.
Hackers taking advantage of the same. Think twice before downloading a theme or plugin and download always from authorized site or author sites. Here is a detailed article on this: Downloading Themes from 3rd Party sites? Be careful..!
# 3 Limit Plugins Usage
Don’t use too many plugins on your blog. It’s not only for security Reasons, it will improves your blogs load speed and performance. Limit your plugins collection to 15 at max. Trying each and every new plugin is not at all safe for your blog.
Assess the functionality of the plugin and count the benefits you get from that plugin. By doing this you can judge whether to have it or not.
# 4 Users & Passwords
This is the point where most of the hackers sitting to gain your access. Keep your usernames and passwords strong & unpredictable. Here are some precautions to be noted:
- Don’t use blog name as username
- Don’t use author names as usernames
- Don’t use author@123 or something like this as passwords
- Don’t save your passwords in mails or browsers
- Use very strong passwords i.e combination of at least 3 group of characters
- Keep changing your passwords at least monthly
# 5 login LockDown
Limit login attempts to your blog i.e preset 3 or 4 login attempts, exceeding which will lead to the IP blockage. You can do this by installing a simple plugin called Login LockDown, which will block the spam bots from gaining access with combination of login credentials.
This is the must have plugin for a WordPress blog. You can set the Maximum try outs a 3 and later you can change or unblock a specific IP. Here is the complete guide about Login LockDown
# 6 Hide Directories
To know whether you need to take this measure, try this experiment. If your blog is located at, say, http://www.yourblog.com/, type http://www.yourblog.com/wp-content/plugins/ in your browser. If you see a listing of all the plugins you’ve installed in your blog, this section applies to you.
Showing your list of plugins to public is nothing but showing loop holes to your blog. By seeing your list of plugins, hackers can find loop holes to hack your blog. Here is how you can hide them by using .htaccess
# 7 Hide/Remove WordPress Version
Right click on your blog page and go to view page source and try to find your version number there (Simply Ctrl + F and try to find 2.7. ). If you succeed here, just read below, it’s for you.
Each WordPress version has its known vulnerabilities. It’s a good practice to hide as much unwanted information as possible to the outside world. If you show your WordPress version out, bad dogs may try to hack your blog with that version loop holes.
Here are 2 simple ways to hide your version number:
- No version plugin is a simple plugin that will replace the version number with blanks, so anyone doing a view “page source” from the browser on your site will not be able to see your WordPress version.
- This is a simple hack: Just open your functions.php and paste the following code somewhere there.
remove_action(‘wp_head’, ‘wp_generator’);
# 8 Do Regular Scan
Scan your WordPress installation for security vulnerabilities. WP Security Scan is a simple plugin, which will scan your complete WordPress installation and suggests you the corrective actions to safe guard.
# 9 Protect Comments from Spam attack
Smart spam bots will try to Comment on your blog with unsolicited links to other resources. Which may contain iframes or malwares. Using a simple plugin like Block-Spam-By-Math will do the task for you.
# 10 Auto Backup Always
Backup Backup Backup always. It’s very important to have backups daily or at least weekly. Either you should take it manually or you should use a simple plugin called WP Database Backup, which will do auto backup as per your settings. It will send you a DB backup zip File to your email either daily or weekly or monthly as per your settings.
Hope you found it useful in securing your loving blog. Is your blog secure now? Share with us! Happy Blogging!!
Related posts:































very good tips for securing WordPress, thanks friend
Thanks for your comments dude..
Point 2 is the most problematic one. Many people are unaware of such things.
Yes true… Even though they are aware..Simply will forget when they see good theme
Good tips, create good passwords, instead of ” o ” use ” 0 “.
Use combination of Upper/Lower cases, special character, digits in the password.
That’s true…Recommend not to use passwords containing author names and blog names
Thanks for your Comment Anish.
good tips on securing WordPress blog
thanks for sharing
Great you found it useful. Thanks for the Comment dude…
hey great post, this is our first priority to take care our blog,
Yes should be everybody’s first priority.
Hi Lax
Nice info about securing WordPress blog. Thanx for sharing it over here.
Thanks for your comments dude…Keep rocking
Another good idea is to use a plugin that locks down your blog and notices you when someone tries to login 10 times with wrong password.
Thats the 5th point in the post. Login Lockdown is a plugin which can Do that task for you
I’m sorry Lax. I went through the points twice just to make sure you didn’t add it. I guess I have to blame the clock.
No probs…
Recently Hackers have targeted Self-Hosted Blogs to a large extent, So it is better to follow proper measure to stay secure.
Very good tips!
Yes they are targeting WP blogs specially by taking advantage of themes and plugins.
This post is really cool! Awesome tips
Thanks!
Great you found it useful.. Thanks for your comments dude..
Nice tips, although I thought changing the admin username is a MUST as it’s admin by default which is obvious to hackers.
Yes user names shouldn’t be like those standard Admin and all.
Don’t even keep author names or blog names
to keep the blog secure we should not say the plugin names which we are using to others
Yes that what we mentioned above to hide them. Thanks for your first comments here dude…
These tips should be followed by every one. For me most important thing is taking backups. I Do it daily.
Yes everyone should follow these basic secure tips. Thanks for your comments dude..
i dont knew what happend to my blog its not loading showing many errors. it think some one hacked it