August 23, 2019 |

WordPress Security Basics to Keep Your Site Safe

Stay in the Loop

Get practical marketing insights, branding tips, and growth strategies delivered straight to your inbox.

Subscribe

“Companies spend millions of dollars on firewalls, encryption, and secure access devices and it’s money wasted because none of these measures address the weakest link in the security chain: the people who use, administer, operate and account for computer systems that contain protected information. ”
Kevin Mitnick, Security researcher, notable hacker


Security is a myth, which is why it’s important to keep up with it. Sounds stupid when put that way, doesn’t it? Hear me out. If someone wants to break into your stuff bad enough, they’ll find a way. Whether it’s an unpublished or zero-day exploit in some code on the website, or by social engineering a hack through someone in your organization – they’ll find a way in.


However, for most malicious intenders, they’re just looking for a quick way in so they can spam their knockoff male enhancement scams. If you make your website sufficiently difficult to compromise, they’ll move on to the next target. There’s hundreds of millions of websites out there, 75 million of those are WordPress – lots of targets that aren’t just your site.


The steps to better security


Step 1: keep backups of your website


Regular website backups offer multiple benefits. Backups:


  • provide a restore point in case part of the WordPress update process goes awry;
  • allow for snapshots of the website to be stored in zipped up, compressed files at remote locations;
  • help mitigate the effects of a hacked website by serving as a restore point.


UpdraftPlus WordPress Backup Plugin is a decent solution if your hosting company doesn’t already offer automated, daily backups. The premium version of the plugin will take automatic backups of the site and upload them to remote locations, such as an Amazon AWS, Google Drive, Dropbox, or a Rackspace storage account.


Step 2: practice some basic security


Practice strong password management


This one’s pretty simple: make strong passwords and change them periodically. There’s websites like 
Secure Password Generator that can make cryptic looking passwords for you, so you don’t have to mash your keyboard to make one up. There’s online password managers like LastPass that’ll store the passwords for each site in case you’re using a web browser that doesn’t already do that.


Be vigilant with WordPress and plugin updates


Periodically log in to your WordPress dashboard (if you don’t already) and apply whatever pending updates there are. We recommend the following steps for that:


  1. Log in to the dashboard and see if there are any “updates” in the Dashboard -> Home -> Updates section.
  2. If so, first take a backup of the website such as with the UpdraftPlus plugin mentioned earlier.
    - If there’s no updates, go enjoy something else.
  3. Then apply the updates by clicking the appropriate buttons on the updates page in the dashboard. That’s it.


Bonus Step: add extra security through hosting or extra plugins


If you host at a company like WP Engine, they have some sweet extra security built in to their infrastructure, and you shouldn’t need any extra security plugins installed. If your current hosting provider doesn’t have WordPress-specific security baked in to their service, you can install additional security plugins to help harden your website against attacks. Wordfence is a popular security plugin with a wealth of free options, and even more premium options to help keep your website protected against malicious activity such as brute-force password attempts, plus additional security options including file scans and some basic firewall utilities.


Want help with any or all of that?


Since we work in the field of web development, a lot of what this post covers is knowledge we take for granted, along with all the nomenclature used. If you have any questions about it or just want someone else to take these items off your plate, we’re happy to help. For instance, we’ve had many clients who try out the WordPress update process and think “shit, what if something breaks?” And that’s okay. I think the same thing whenever I update stuff, too, and I’ve been doing it for years. There’s no wrong in asking for help, and that’s what we’re here to do – help you focus on your business.

Thoughtful strategy. Practical execution.

Clear thinking, honest perspectives, and experience shaped by years of doing the work. No shortcuts, no borrowed opinions, just lessons learned by showing up, solving problems, and following ideas all the way through.

Hands holding a tablet displaying a video player interface. The video is paused.
February 20, 2026
In case you hadn’t seen these (and also for my friends at Adventure Film ), here are a couple of must-see running movies from Joel Wolpert:  Geoff Roes: Slogging to the Top
Runner in blue and red gear sprints across grassy terrain, mountains in background, cloudy sky.
October 27, 2015
Guess who’s back. Back again. ~ Eminem  Still working out some kinks in the site but hoping to be more active and on the regular up in this joint. Quick catch up: 2013: NYC was a bust. I experienced a heel problem which led to a hamstring problem and I shut down my quest for an NYC finish. At least for now. The remainder of 2013 was spent trying to get uninjured. 2014: Injuries persisted in 2014. When the heel/hammy started feeling ready to run again, I broke my ankle bouldering. Literally came off the wall a foot and a half off the ground and popped my ankle. Whee. So more recovery and I pretty much switched to riding mountain bikes for the year. 2015: Back at it in 2015. Running pretty well. A bit off my game from day’s past but still having fun. Even entered a few races which didn’t go well. Just trying to figure things out and stay happy/healthy. More to come, I promise. ~stubert.
Person fixing a flat tire on a mountain bike outdoors; green helmet, tan shirt, shorts.
August 24, 2013
I hurt myself today . ~ N.I.N. Ah the Tabata. Some people hate them, others love them. In the moment, they can be the bane of my existence but after rocking out a few sets, I really tend to notice the benefits. For the uninitiated, a Tabata can be applied to virtually any exercise type (cycling; swimming; push-ups; chess, I assume) but since I am a runner, I tend to knock these out while running. Go figure. Here’s the formula: Go as hard as you can for 20 seconds Rest for 10 seconds Repeat 8 times Feel free to do multiple sets Four minutes (per set) of activity doesn’t sound like much, but if done correctly, these can really help boost your fitness. I tend to replace strides with one Tabata on Fridays and will work in multiple sets as part of my Tuesday interval training. Just keep good form, really work the 20s and you’ll reap the benefits. ~stubert.