WordPress Hardening: 5 Steps to Close Off Entry Points
Why is a default WordPress installation vulnerable to attacks?
WordPress’s default configuration is designed for maximum user convenience, not security. The URLs of key files are predictable (/wp-admin, /wp-login.php, xmlrpc.php), the readme.html file reveals the WordPress version, and the default username is admin. Every one of these details helps an attacker.
Hardening is the process of tightening the default configuration. The following 5 steps can be implemented without plugins or programming knowledge.
Step 1 — Restrict access to wp-login.php
The WordPress login page is the target of constant brute-force attacks — bots test thousands of password combinations per minute. The simplest protection is to restrict access to wp-login.php to known IP addresses only.
Add this to the .htaccess file:
<Files "wp-login.php">
Order Deny,Allow
Deny from All
Allow from YOUR_IP_ADDRESS
</Files>
If your IP is dynamic, an alternative is to change the login page address to a custom one, e.g. /admin-entry — plugins such as WPS Hide Login do this in 2 minutes.
Step 2 — Disable XML-RPC
XML-RPC is a WordPress API originally created for mobile clients and pingbacks. Today it is mainly an attack vector — it allows hundreds of passwords to be tested in a single HTTP request (a brute-force amplification attack).
If you do not use Jetpack and do not publish through external applications, disable XML-RPC in .htaccess:
<Files "xmlrpc.php">
Order Deny,Allow
Deny from All
</Files>
Step 3 — Secure wp-config.php
The wp-config.php file contains your database login credentials — it is the most important file on your server. Do two things:
- Move it one level above
public_html — WordPress will find it automatically, but the web server will not serve it directly.
- Block access using .htaccess:
<Files "wp-config.php">
Order Deny,Allow
Deny from All
</Files>
Step 4 — Disable file editing through the admin panel
By default, WordPress allows you to edit theme and plugin PHP files through the admin panel (Appearance → Theme File Editor). If an attacker takes over an admin account, they can inject malicious code without FTP access. Disable this feature in wp-config.php:
define('DISALLOW_FILE_EDIT', true);
Step 5 — Set appropriate file permissions
Incorrect permissions are one reason hackers can write files to your server. The correct values are:
- Directories: 755 (or 750)
- PHP files: 644
- wp-config.php: 440 or 400
.htaccess files: 444
You can set permissions in bulk over SSH:
find public_html -type d -exec chmod 755 {} \;
find public_html -type f -name "*.php" -exec chmod 644 {} \;
chmod 440 public_html/wp-config.php
What next?
These 5 steps make an attack significantly more difficult, but they do not replace a strong password, up-to-date plugins, and regular backups. WordPress security is a process, not a one-time action.
If you want to delegate monitoring and regular updates — check out our website care and monitoring plans. We take care of your website’s security in the background so you can focus on your business.