Website security is risk reduction, not a one-click product.
A secure WordPress or CMS deployment depends on several layers working together: HTTPS, updates, strong authentication, a web application firewall, safe file permissions, backups, DNS hygiene and server access controls.
This checklist focuses on the controls that matter most for ordinary websites and small-business infrastructure without pretending that one plugin, VPN or paid SSL certificate can secure the entire stack.
Prioritize layered controls: keep software updated, reduce unnecessary exposure, encrypt traffic, protect credentials, filter malicious requests, maintain recoverable backups and monitor the systems that matter.
Last verified: September 15, 2026.
1. The Website Security Checklist
| Security Layer | Main Risk Reduced | Recommended Action | Priority |
|---|---|---|---|
| HTTPS / TLS | Eavesdropping and traffic tampering | Use a valid certificate and enforce HTTPS | Critical |
| Updates | Known software vulnerabilities | Keep CMS core, plugins, themes and server packages current | Critical |
| Authentication | Credential stuffing and brute force | Strong unique passwords + MFA/2FA | Critical |
| WAF / edge filtering | Malicious application requests | Use Cloudflare WAF, ModSecurity or equivalent controls | High |
| Backups | Data loss, ransomware, bad updates | Automate offsite backups and test restores | Critical |
| Server access | Unauthorized administrative access | Limit SSH exposure, use keys/MFA where supported, restrict admin access | High |
| DNS and email authentication | Spoofing and domain abuse | Configure SPF, DKIM and DMARC where applicable | High |
| Monitoring | Delayed detection | Monitor uptime, logs, login activity and certificate expiry | High |
2. Enforce HTTPS and Modern TLS
HTTPS encrypts traffic between the browser and the website, reducing the risk of eavesdropping and tampering in transit.
For many ordinary websites, the simplest option is the free certificate already provided by the host or an automated Let's Encrypt deployment.
If you use Cloudflare, configure encryption between both legs of the connection. Cloudflare recommends Full (strict) where possible so the connection from Cloudflare to the origin is also encrypted and the origin certificate is validated.
If your needs go beyond basic automated HTTPS—for example wildcard coverage, several domains, OV/EV business validation or commercial certificate support—compare the options in our Best SSL Certificates guide.
3. Keep WordPress, Plugins and Themes Updated
WordPress' own security documentation emphasizes keeping WordPress itself and installed plugins and themes current.
Practical rules:
- Install updates from trusted sources.
- Remove unused plugins and themes instead of leaving them dormant indefinitely.
- Avoid abandoned or pirated software.
- Review changelogs before major production updates.
- Maintain a rollback-capable backup before significant changes.
4. Harden Authentication
Use strong unique passwords and enable MFA or 2FA wherever the platform supports it.
For WordPress and hosting accounts, protect at least:
- WordPress administrator accounts.
- Hosting control-panel accounts.
- Domain registrar accounts.
- Cloudflare accounts.
- Email accounts used for password resets.
- SSH or server-management accounts.
A compromised email or registrar account can be as damaging as a compromised WordPress password.
5. Use a Web Application Firewall
A WAF can filter suspicious web requests before they reach the application.
Common options include:
- Cloudflare WAF at the edge.
- ModSecurity rules at the server or hosting layer.
- Managed host-specific application filtering.
No WAF is a substitute for patching vulnerable software. Treat it as another layer, not the only defense.
6. Protect the Origin Server
If Cloudflare proxies your website, an exposed origin IP can allow direct requests that bypass some edge protections.
Where your architecture supports it, restrict origin access to trusted traffic sources and use properly validated origin HTTPS.
Cloudflare also documents Authenticated Origin Pulls as an additional control that helps verify requests reaching the origin came through Cloudflare.
7. Secure WordPress File Permissions
WordPress recommends limiting write access rather than making files broadly writable.
A common Linux baseline is:
# Directories
find /path/to/wordpress/ -type d -exec chmod 755 {} \;
# Files
find /path/to/wordpress/ -type f -exec chmod 644 {} \;
Actual ownership and permissions depend on your server model, PHP handler and hosting configuration. Do not apply permissions blindly to production systems.
8. Protect wp-config.php and Sensitive Files
wp-config.php contains database credentials and other sensitive configuration.
Restrict access using the mechanisms appropriate for your web server.
On Apache-compatible environments, one possible rule is:
<Files "wp-config.php">
Require all denied
</Files>
Test configuration changes carefully because server syntax varies.
9. Back Up Offsite and Test Restores
A backup that cannot be restored is not a reliable recovery plan.
For important production sites:
- Automate backups.
- Store at least one copy outside the primary hosting account.
- Retain multiple restore points.
- Test restores periodically.
- Document what is covered: files, database, email, DNS and application secrets.
Backup frequency should reflect how much data you can afford to lose.
10. Secure DNS and Email Authentication
Domain security is part of website security.
Protect registrar and DNS accounts with strong authentication, and configure SPF, DKIM and DMARC for domains that send email.
Also review DNS records after migrations so abandoned A, CNAME or MX records do not continue pointing to old infrastructure.
11. Secure Administrative Network Access
Do not treat public networks as inherently trusted.
For remote administrative work:
- Prefer encrypted protocols such as HTTPS and SSH.
- Avoid exposing database interfaces publicly when possible.
- Use a VPN when your network model or organization requires one.
- Restrict SSH by firewall, keys, MFA or access gateway where supported.
The important control is reducing exposure and protecting credentials—not purchasing a specific VPN brand by default.
12. Monitor Uptime, Logs and Certificate Expiry
Security failures are easier to contain when they are detected quickly.
Monitor:
- Unexpected administrator logins.
- Repeated failed authentication attempts.
- Application and web-server errors.
- File changes where appropriate.
- Certificate expiry.
- Uptime and external availability.
For a self-hosted availability workflow, Digital Bhatti's Uptime Kuma guide can be used to add independent uptime monitoring.
13. Website Security Priority Order
1. Patch core software, plugins and themes
2. Protect admin / registrar / email accounts with MFA
3. Enforce HTTPS end to end
4. Maintain tested offsite backups
5. Add WAF / edge filtering
6. Restrict server and origin exposure
7. Harden file permissions and sensitive configuration
8. Configure DNS and email authentication
9. Monitor uptime, logs and certificate expiry
This order is more useful than buying random security products without first closing basic operational gaps.
Frequently Asked Questions
Do I need a paid SSL certificate for website security?
Usually not. Many ordinary websites are well served by a valid automatically renewed free certificate. Paid certificates are more relevant when wildcard, multi-domain, OV/EV, commercial support or organizational policy requirements apply.
What is the most important WordPress security action?
There is no single control, but keeping WordPress core, plugins and themes updated is foundational. WordPress itself identifies current software as a key security practice.
Should I disable XML-RPC?
Only if your site does not depend on features that use it. Blocking XML-RPC indiscriminately can break integrations, so treat it as an application-specific hardening decision.
Does a WAF replace WordPress updates?
No. A WAF can filter malicious traffic, but vulnerable software should still be patched or removed.
How often should I back up my website?
Match backup frequency to the amount of data you can afford to lose. A frequently updated ecommerce site may need much more frequent database backups than a static brochure site.
Should I use a VPN to manage WordPress?
A VPN can be useful in some network models, but the core requirements are encrypted protocols, strong authentication and restricted administrative exposure. A VPN is one possible layer, not a universal requirement.
Abdul Shakoor
Founder of Digital Bhatti, focused on web hosting and infrastructure, WordPress performance, Linux VPS environments, web servers and technical SEO.
