How-to · Intermediate · an hour of setup
How to Secure WordPress
Shut the doors that WordPress attacks actually come through — a practical, jargon-free walkthrough with the classic mistake flagged before you make it.
Straight answer first
The job: shut the doors that WordPress attacks actually come through. Time to allow: an hour of setup. Skill needed: intermediate.
Below you get the exact steps, the classic snag, and a tip from the support desk. Where our platform handles a step for you, the guide says so rather than making you do the robot's work.
Written by the Hosting Seller staff · Checked 1 August 2026
Intermediate
Skill needed
5
Stages to finish
Free
Help included
Tested
On our own kit
This guide assumes no expertise at all — just a hosting account, a browser and hour of setup of attention. Every instruction works on our platform exactly as written, and carries over to any standard cPanel host.
One promise before you start: nothing in this guide is irreversible. Where a step could bite, we say so and give you the undo.
The route, start to finish
From start to finish, you will make updates non-negotiable, reinforce the front door, hand out the smallest keys, clear out what you don't use and check the safety net works.
No stage needs code or a terminal unless the guide says so outright, and where it does, the exact commands are printed. The full step-by-step sits below; the sections around it give the context that makes it stick.
The classic snag
Buying a security plugin and then ignoring the update notices it keeps raising. The plugin is the smoke alarm. Out-of-date plugins and themes are the fire, and an alarm on its own has never put one out.
It is worth learning because it is not some rare edge case — it is the single most common reason this task turns into a support ticket. Knowing it up front turns the whole job from risky into routine.
The shortcut, straight from the support desk
Restore a backup once, on purpose, while nothing is wrong. A backup you have never restored is a hope rather than a plan, and twenty minutes of rehearsal removes the panic from whatever happens later.
Small habits like this are the real difference between people who find hosting easy and people who find it stressful. The tools are identical; the working method is not.
What runs by itself here
Several steps in this guide exist only because hosting historically made you do them. On our plans SSL issues itself, backups run daily without being asked, and one-click installers replace the manual setup entirely. What is left is the part that is genuinely yours.
And when a step misbehaves anyway, support answers at any hour with the actual fix, not a knowledge-base link and a shrug. Half our best guides began life as a pattern in the ticket queue.

Why the job is simpler on our plans
Tutorials age badly when they are written against imaginary hosting. These are written against ours: the same panel, the same installer and the same defaults you will meet.
SSL comes free with every plan and reissues itself before it lapses, so nobody has to diary the padlock.
- Step by step, tested exactly as printed
- The snag flagged before you reach it
- The dull steps are already automated
- People on hand at any hour if you stall
Why Hosting Seller
On every plan, as standard
Scoped honestly
Shut the doors that WordPress attacks actually come through is a intermediate-level task — this guide budgets an hour of setup and says which steps the platform absorbs.
5 steps, no filler
Each stage is a few minutes of steady clicking, with the fiddly parts marked as fiddly.
Help on the counter
Stuck on step three at midnight? Support answers at any hour, mid-guide included.
The snag, named early
The classic mistake for this exact job is flagged before step one, so an hour of setup stays an hour of setup.
Works exactly as written
Every step tested on the platform we run — no 'your host may differ' hand-waving anywhere.
No jargon toll
Terms are explained where they appear or linked to the glossary — nothing assumes you already know.
First Steps
From choosing to live
- 1
Make updates non-negotiable
Turn auto-updates on for core and set yourself a weekly slot for plugins and themes. Known holes in out-of-date components account for the overwhelming majority of compromised WordPress sites.
- 2
Reinforce the front door
A username that is not admin, a generated password, two-factor authentication and a limit on failed login attempts. Credential attacks run day and night against every WordPress site there is.
- 3
Hand out the smallest keys
Editors do not need administrator rights and contributors do not need to publish. Every unnecessary admin account is another set of keys that can be lost, guessed or shared with somebody who leaves.
- 4
Clear out what you don't use
Delete deactivated plugins, unused themes and dormant user accounts. Code sitting there unused is attack surface offering nothing back in return.
- 5
Check the safety net works
Confirm backups are running and can actually be restored, and that server-level protection such as the firewall and malware scanning is switched on. Perfect prevention is not a plan; being able to recover is.
In the Box
Packed with every plan
- cPanel, the panel the rest of the trade already knows
- WordPress Toolkit, with updates applied for you
- The renewal price printed on the tag matches the order price
- A free SSL certificate on every plan, reissued before it lapses
- Staging copies so changes get tested before they go live
- PHP versions picked per site from the panel
- Site migration done for you by our staff, at no charge
- A domain free for year one when you order annually
- Upgrades apply to the account in place, with no move between plans
- A 99.9% uptime commitment, watched by monitoring day and night
Across the Counter
The questions we get asked most
How do WordPress sites really get broken into?
Almost always through a known hole in an out-of-date plugin or theme, or through a password that was weak, reused or stolen. Exotic zero-days barely feature. Updates plus login hardening close the doors attackers actually walk through.
With server-level protection in place, is a security plugin still needed?
Server-level tooling such as our Imunify360 tier stops attacks before WordPress even loads. A light plugin still adds useful login hardening and an activity log worth reading. Run both, but let the server layer do the heavy lifting.
What uptime do you commit to, and who is watching?
We commit to 99.9% uptime and watch it continuously. That figure is an operational target rather than a poster line, and the alerting behind it usually has an engineer on a problem before the first customer notices anything is wrong.
Who actually runs the company?
Hosting Seller is a trading name of Bohzo Ltd, a company registered in England and Wales — a real business with a public record and terms published under English law. Looking that up is worth doing about any host before you hand over your domain.
Can I test changes somewhere safe first?
Yes — plans with staging let you clone the live site, work on the copy, then push it across when you are satisfied. It is the difference between hoping an update behaves and knowing that it does before any customer meets it.
How do I pay, and does it bill again on its own?
Orders go through a secure checkout by credit or debit card, and the renewal is taken at the same price you first paid. Every invoice sits in the client area for you to read, and switching auto-renewal off is a toggle in your account rather than a phone call.
Are backups included, and can I put one back myself?
A backup is taken daily on every plan, and the restore is yours to run from the panel in minutes — files, databases or both, at three in the morning without waiting on a ticket. Keeping your own copy offsite as well is never a bad habit, and nothing here stops you.
Read next
How to Create a Professional Email Signature
Build a signature that renders everywhere and does its selling quietly — beginner level, about 30 minutes.
How to Secure a New VPS
The first hour of hardening that heads off almost every compromise — advanced level, about one hour.
VPS Hosting
KVM virtual servers with root access, DDoS filtering and one flat price.
Web Hosting
cPanel hosting on NVMe disks, with SSL, migration and year-one domain included.
Packing up and moving host? Take our checklist.
A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.
Your site is worth better hosting.
From a first website to a rack of servers, moving up is a change to your account rather than a migration.
See the plans