Skip to main content
.com domains from $2.99 — WHOIS privacy at no extra charge

How-to · Intermediate · an hour of setup

How to Secure WordPress

Shut the doors that WordPress attacks actually come through — a practical, jargon-free walkthrough with the classic mistake flagged before you make it.

Straight answer first

The job: shut the doors that WordPress attacks actually come through. Time to allow: an hour of setup. Skill needed: intermediate.

Below you get the exact steps, the classic snag, and a tip from the support desk. Where our platform handles a step for you, the guide says so rather than making you do the robot's work.

Written by the Hosting Seller staff · Checked 1 August 2026

Intermediate

Skill needed

5

Stages to finish

Free

Help included

Tested

On our own kit

This guide assumes no expertise at all — just a hosting account, a browser and hour of setup of attention. Every instruction works on our platform exactly as written, and carries over to any standard cPanel host.

One promise before you start: nothing in this guide is irreversible. Where a step could bite, we say so and give you the undo.

The route, start to finish

From start to finish, you will make updates non-negotiable, reinforce the front door, hand out the smallest keys, clear out what you don't use and check the safety net works.

No stage needs code or a terminal unless the guide says so outright, and where it does, the exact commands are printed. The full step-by-step sits below; the sections around it give the context that makes it stick.

The classic snag

Buying a security plugin and then ignoring the update notices it keeps raising. The plugin is the smoke alarm. Out-of-date plugins and themes are the fire, and an alarm on its own has never put one out.

It is worth learning because it is not some rare edge case — it is the single most common reason this task turns into a support ticket. Knowing it up front turns the whole job from risky into routine.

The shortcut, straight from the support desk

Restore a backup once, on purpose, while nothing is wrong. A backup you have never restored is a hope rather than a plan, and twenty minutes of rehearsal removes the panic from whatever happens later.

Small habits like this are the real difference between people who find hosting easy and people who find it stressful. The tools are identical; the working method is not.

What runs by itself here

Several steps in this guide exist only because hosting historically made you do them. On our plans SSL issues itself, backups run daily without being asked, and one-click installers replace the manual setup entirely. What is left is the part that is genuinely yours.

And when a step misbehaves anyway, support answers at any hour with the actual fix, not a knowledge-base link and a shrug. Half our best guides began life as a pattern in the ticket queue.

A shield icon standing in for site security and DDoS filtering

Why the job is simpler on our plans

Tutorials age badly when they are written against imaginary hosting. These are written against ours: the same panel, the same installer and the same defaults you will meet.

SSL comes free with every plan and reissues itself before it lapses, so nobody has to diary the padlock.

  • Step by step, tested exactly as printed
  • The snag flagged before you reach it
  • The dull steps are already automated
  • People on hand at any hour if you stall

Why Hosting Seller

On every plan, as standard

Scoped honestly

Shut the doors that WordPress attacks actually come through is a intermediate-level task — this guide budgets an hour of setup and says which steps the platform absorbs.

5 steps, no filler

Each stage is a few minutes of steady clicking, with the fiddly parts marked as fiddly.

Help on the counter

Stuck on step three at midnight? Support answers at any hour, mid-guide included.

The snag, named early

The classic mistake for this exact job is flagged before step one, so an hour of setup stays an hour of setup.

Works exactly as written

Every step tested on the platform we run — no 'your host may differ' hand-waving anywhere.

No jargon toll

Terms are explained where they appear or linked to the glossary — nothing assumes you already know.

First Steps

From choosing to live

  1. 1

    Make updates non-negotiable

    Turn auto-updates on for core and set yourself a weekly slot for plugins and themes. Known holes in out-of-date components account for the overwhelming majority of compromised WordPress sites.

  2. 2

    Reinforce the front door

    A username that is not admin, a generated password, two-factor authentication and a limit on failed login attempts. Credential attacks run day and night against every WordPress site there is.

  3. 3

    Hand out the smallest keys

    Editors do not need administrator rights and contributors do not need to publish. Every unnecessary admin account is another set of keys that can be lost, guessed or shared with somebody who leaves.

  4. 4

    Clear out what you don't use

    Delete deactivated plugins, unused themes and dormant user accounts. Code sitting there unused is attack surface offering nothing back in return.

  5. 5

    Check the safety net works

    Confirm backups are running and can actually be restored, and that server-level protection such as the firewall and malware scanning is switched on. Perfect prevention is not a plan; being able to recover is.

In the Box

Packed with every plan

  • cPanel, the panel the rest of the trade already knows
  • WordPress Toolkit, with updates applied for you
  • The renewal price printed on the tag matches the order price
  • A free SSL certificate on every plan, reissued before it lapses
  • Staging copies so changes get tested before they go live
  • PHP versions picked per site from the panel
  • Site migration done for you by our staff, at no charge
  • A domain free for year one when you order annually
  • Upgrades apply to the account in place, with no move between plans
  • A 99.9% uptime commitment, watched by monitoring day and night

Across the Counter

The questions we get asked most

How do WordPress sites really get broken into?

Almost always through a known hole in an out-of-date plugin or theme, or through a password that was weak, reused or stolen. Exotic zero-days barely feature. Updates plus login hardening close the doors attackers actually walk through.

With server-level protection in place, is a security plugin still needed?

Server-level tooling such as our Imunify360 tier stops attacks before WordPress even loads. A light plugin still adds useful login hardening and an activity log worth reading. Run both, but let the server layer do the heavy lifting.

What uptime do you commit to, and who is watching?

We commit to 99.9% uptime and watch it continuously. That figure is an operational target rather than a poster line, and the alerting behind it usually has an engineer on a problem before the first customer notices anything is wrong.

Who actually runs the company?

Hosting Seller is a trading name of Bohzo Ltd, a company registered in England and Wales — a real business with a public record and terms published under English law. Looking that up is worth doing about any host before you hand over your domain.

Can I test changes somewhere safe first?

Yes — plans with staging let you clone the live site, work on the copy, then push it across when you are satisfied. It is the difference between hoping an update behaves and knowing that it does before any customer meets it.

How do I pay, and does it bill again on its own?

Orders go through a secure checkout by credit or debit card, and the renewal is taken at the same price you first paid. Every invoice sits in the client area for you to read, and switching auto-renewal off is a toggle in your account rather than a phone call.

Are backups included, and can I put one back myself?

A backup is taken daily on every plan, and the restore is yours to run from the panel in minutes — files, databases or both, at three in the morning without waiting on a ticket. Keeping your own copy offsite as well is never a bad habit, and nothing here stops you.

Packing up and moving host? Take our checklist.

A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.

One email carrying the checklist, then the odd note on running a site well. Step off the list whenever you like — our privacy policy spells out the rest.

Your site is worth better hosting.

From a first website to a rack of servers, moving up is a change to your account rather than a migration.

See the plans