August 23, 2019 |

WordPress Security Basics to Keep Your Site Safe

Stay in the Loop

Get practical marketing insights, branding tips, and growth strategies delivered straight to your inbox.

Subscribe

“Companies spend millions of dollars on firewalls, encryption, and secure access devices and it’s money wasted because none of these measures address the weakest link in the security chain: the people who use, administer, operate and account for computer systems that contain protected information. ”
Kevin Mitnick, Security researcher, notable hacker


Security is a myth, which is why it’s important to keep up with it. Sounds stupid when put that way, doesn’t it? Hear me out. If someone wants to break into your stuff bad enough, they’ll find a way. Whether it’s an unpublished or zero-day exploit in some code on the website, or by social engineering a hack through someone in your organization – they’ll find a way in.


However, for most malicious intenders, they’re just looking for a quick way in so they can spam their knockoff male enhancement scams. If you make your website sufficiently difficult to compromise, they’ll move on to the next target. There’s hundreds of millions of websites out there, 75 million of those are WordPress – lots of targets that aren’t just your site.


The steps to better security


Step 1: keep backups of your website


Regular website backups offer multiple benefits. Backups:


  • provide a restore point in case part of the WordPress update process goes awry;
  • allow for snapshots of the website to be stored in zipped up, compressed files at remote locations;
  • help mitigate the effects of a hacked website by serving as a restore point.


UpdraftPlus WordPress Backup Plugin is a decent solution if your hosting company doesn’t already offer automated, daily backups. The premium version of the plugin will take automatic backups of the site and upload them to remote locations, such as an Amazon AWS, Google Drive, Dropbox, or a Rackspace storage account.


Step 2: practice some basic security


Practice strong password management


This one’s pretty simple: make strong passwords and change them periodically. There’s websites like 
Secure Password Generator that can make cryptic looking passwords for you, so you don’t have to mash your keyboard to make one up. There’s online password managers like LastPass that’ll store the passwords for each site in case you’re using a web browser that doesn’t already do that.


Be vigilant with WordPress and plugin updates


Periodically log in to your WordPress dashboard (if you don’t already) and apply whatever pending updates there are. We recommend the following steps for that:


  1. Log in to the dashboard and see if there are any “updates” in the Dashboard -> Home -> Updates section.
  2. If so, first take a backup of the website such as with the UpdraftPlus plugin mentioned earlier.
    - If there’s no updates, go enjoy something else.
  3. Then apply the updates by clicking the appropriate buttons on the updates page in the dashboard. That’s it.


Bonus Step: add extra security through hosting or extra plugins


If you host at a company like WP Engine, they have some sweet extra security built in to their infrastructure, and you shouldn’t need any extra security plugins installed. If your current hosting provider doesn’t have WordPress-specific security baked in to their service, you can install additional security plugins to help harden your website against attacks. Wordfence is a popular security plugin with a wealth of free options, and even more premium options to help keep your website protected against malicious activity such as brute-force password attempts, plus additional security options including file scans and some basic firewall utilities.


Want help with any or all of that?


Since we work in the field of web development, a lot of what this post covers is knowledge we take for granted, along with all the nomenclature used. If you have any questions about it or just want someone else to take these items off your plate, we’re happy to help. For instance, we’ve had many clients who try out the WordPress update process and think “shit, what if something breaks?” And that’s okay. I think the same thing whenever I update stuff, too, and I’ve been doing it for years. There’s no wrong in asking for help, and that’s what we’re here to do – help you focus on your business.

Thoughtful strategy. Practical execution.

Clear thinking, honest perspectives, and experience shaped by years of doing the work. No shortcuts, no borrowed opinions, just lessons learned by showing up, solving problems, and following ideas all the way through.

Four hikers with backpacks walking along a rocky mountain ridge under a blue sky
May 8, 2026
We are each our own greatest inhibitor. People don’t want to do new things if they think they’re going to be bad at them or people are going to laugh at them. You have to be willing to subject yourself to failure, to be bad, to fall on your head and do it again, and try stuff that you’ve never done in order to be the best you can be. ~ Laird Hamilton Yesterday: Hit Range Balls/Hike – Casa del Critters, 1:15 Today: Run – GGCSP, ~2 hours Tomorrow: Ride – Somewhere singlespeedy, ~2 hours Yesterday, Rach and I took a nice stroll in the woods around our house. The songbirds were going crazy-nuts and surprisingly, we only saw one other person walking his dog. I love where we live – close proximity to fun trails and the ability to get away from it all in just a short walk from our house. During lunch yesterday, I went to the driving range to get a few cuts in before playing a round of golf with my dad next week. I don’t get to play very often so need to brush up on my skills (or lack thereof) whenever I can. I am looking forward to playing with my pops and hope to break 100. I shot a 102 the last time I played so I am within striking distance of the sub-triple-digit score. We’ll see how things go. I usually do okay for most of the round and then fall apart on a couple of holes pushing my score way up. Dad shoots in the low 80s usually (I think). I am not sure I will ever play enough to be that good but it is fun to get out on the course now and again. I also went to see Dr. Paul yesterday for my ankle problem (which seems to have been resolved) and my knee (which is still a bit swollen but has decreased in size markedly over the past several days). The knee stems from my unscheduled nose-dive back in May (see this post for details). The shot some pictures and believe that everything is a-ok so that was good news. I just need to select better places for splashdowns in the future. And today is Luke’s birthday. Age is one place where I will always beat him but visit his blog to congratulate him on trying to catch up. Until next time…
Runner silhouetted at sunset on a rocky trail, mid-stride between hills.
May 8, 2026
Progress comes from the intelligent use of experience. ~ Elbert Hubbard Yesterday: Run – Casa del Critters/Flume, 1 hour 15 minutes Today: Ride/Hike/Relax Tomorrow: Run/Hike – Pawnee/Buchanan Passes, 6 hours? Yesterday I ran around the house. Not literally, mind you, but in the neighborhood. It was a gorgeous evening – calm, cool. Perfect. The wildflowers are really starting to take off up here and I was treated with a bold display of color throughout my run. Tons of Columbine lined the trailside as I ran on old mining roads and singletrack trails. It is really fun to see how much differently I am able to handle familiar terrain. I used to have difficulties running this loop and would have to walk major sections. Last night, I ran the entire loop without trouble and was able to moderate my speed to maintain a steady cadence through the run. Good times. Contracting is staying steady. A bit of a drop-off this week given the holiday but I am still managing to put in a decent number of hours. I picked up another new project today and will need to get started immediately to ensure that it gets completed on time.  Tomorrow, we are going to head up Pawnee Pass and loop back around to Buchanan Pass in the northern Indian Peaks Wilderness. This should be a fun challenge as we’ll get up pretty high, have to navigate some snow (most likely) and will be out for quite awhile. I am looking forward to it for sure . Movie time: I forgot to mention Shopgirl, a Steve Martin vehicle, we watched the other night. I wasn’t quite sure what to expect but found this to be a charming film about loneliness. It was well acted and would recommend it for sure. The pacing is steady throughout and some might find it a little on the slow side but it was an engaging film that had a lot to say without being overly sappy.
Hands holding a tablet displaying a video player interface. The video is paused.
February 20, 2026
In case you hadn’t seen these (and also for my friends at Adventure Film ), here are a couple of must-see running movies from Joel Wolpert:  Geoff Roes: Slogging to the Top