WordPress Security Checklist

Use this free WordPress Security Checklist to ensure that your WordPress site remains protected and secure at all times.

WordPress Security ChecklistThis tutorial is part of our tutorial series on WordPress Security. In this tutorial, we provide a WordPress Security Checklist that will help ensure your WordPress site is protected and secure.


WordPress Security Checklist

Important Info

*** Important – Read Me ***

Many of the tasks listed in the checklist below can be completed by non-technical users simply by following the tutorials in our WordPress Security training module. Some of these tasks, however, should only be carroed out by more technically advanced users. If you don’t understand what to do or don’t feel confident performing one or more tasks, please ask a professional and experienced WordPress service provider for assistance.


Always backup your WordPress site (database and files) before making any changes to files. Even small mistakes can have disastrous consequences if you are not careful.

Please note that we have no control over the software and services mentioned in this checklist and that under no circumstances will we be held responsible for any losses or damages incurred either directly or indirectly as a result of following the recommendations below.

We also provide a printable version of this checklist at the end of this tutorial. We recommend printing out this checklist and using it as a reference to ensure the continued security of your WordPress site.

Basic Website Security Checklist

WordPress Security Setup Checklist

  • Protect your site against spam (Install an antispam plugin, e.g. Akismet or Bad Behavior)
  • Perform a full security scan of your WordPress files (Install a security scan plugin, e.g. Acunetix WP Security).
  • Secure your WP database (change database table prefix).
  • Option 1: Install a brute-force attack prevention plugin (e.g. Login Lockdown, Limit Login Attempts), or
  • Option 2: Install a comprehensive security plugin (e.g. BulletProof Security, SecureScanPro, etc.)
  • Secure your wp-admin folder.
  • Protect your uploads folder.
  • Secure your wp-config.php file.
  • Delete redundant WordPress core files (e.g. readme.html, install.php, etc.)
  • Set secure permissions for files and folders.
  • Protect server directories (e.g. add empty index.php files to directories)
  • Add a secure admin user.
  • Set correct permissions for users (User Roles and Capabilities)
  • Remove user registration capabilities (if not required)
  • Set up an Intrusion Detection System (Install a file monitoring plugin, e.g. File Monitor Plus)
  • Add Antivirus protection (Install an antivirus plugin, e.g. Antivirus for WordPress)
  • Add Firewall protection (Install a firewall plugin like WordPress Firewall 2, Block Bad Queries, etc …)
  • Enable data logging and archiving.
  • Secure PHP.
  • Set up hosting monitoring (e.g. Sucuri, etc…)

WordPress Security Maintenance Checklist

Schedule the tasks below to be performed on a regular basis:

Critical Website Information Checklist

Have this information handy and keep it in a safe place!

Download a printable copy of this free WordPress Security checklist below.

Hopefully, you have gone through the above checklist and implemented measures that will help ensure your WordPress site is protected and secure.

WordPress Security Checklist


"I was absolutely amazed at the scope and breadth of these tutorials! The most in-depth training I have ever received on any subject!" - Myke O'Neill, DailyGreenPost.com


Recommended Video Courses For WordPress Users

How To Use FTPHow To Use FTP

This video course shows you how to use FTP (File Transfer Protocol) to transfer and upload files between your hard drive and your server using a free FTP program called Filezilla.

More info: How To Use FTP

Recommended Video Courses For WordPress Users

How To Back Up & Restore WordPress SitesHow To Back Up & Restore WordPress Sites

Learn how to safely and automatically backup your WordPress files and database and how to easily restore your WordPress site if something were to happen.

More info: How To Back Up & Restore WordPress Sites

Recommended Video Courses For WordPress Users

Using Password ManagersUsing Password Managers

Password Managers provide an easy and secure way to keep track of all your passwords. This video course shows you how to use two FREE powerful password management tools.

More info: Using Password Managers

Recommended Video Courses For WordPress Users

How To Use Amazon S3How To Use Amazon S3

Learn how to set up and use Amazon S3 to upload, store, manage, and protect your site’s images, large media files, downloadable files, stream videos and more.

More info: How To Use Amazon S3

Recommended Video Courses For WordPress Users

How To Use cPanelHow To Use cPanel

cPanel is a powerful and simple-to-use web hosting management software application that gives website owners the ability to quickly and easily manage their servers and websites using a simple and intuitive dashboard.

This video course will teach you how to use the main features of cPanel to manage your web hosting.

More info: How To Use cPanel

Recommended Video Courses For WordPress Users

How To Set Up WordPress On LocalhostHow To Set Up WordPress On Localhost

Learn how to install, set up, and locally host a fully functioning WordPress site on your computer.

More info: How To Set Up WordPress On Localhost

Recommended Video Courses For WordPress Users

WordPress SecurityWordPress Security

Learn how to keep your WordPress site or blog secure and protected from malware, hackers and brute-force attacks.

More info: WordPress Security

Author: Martin Aranovitch

Martin Aranovitch is the owner of WPCompendium.org and the author of The WordPress User Manual. WPCompendium.org provides hundreds of FREE tutorials that show you how to use WordPress to grow your business online with no coding skills required! Get our FREE "101+ WordPress Tips, Tricks & Hacks For Non-Techies" e-course with loads of useful WordPress tips!

Originally published as WordPress Security Checklist.