Skip to main content

Walkthrough · Intermediate · an hour of setup

How to Secure WordPress

How to shut the doors WordPress attackers actually use, without the guessing — the steps in order, the snag ahead of time, and the tip our support team repeats daily.

The short answer

The job: shut the doors WordPress attackers actually use. Time to set aside: an hour of setup. Skill needed: intermediate.

Below are the precise steps, the classic stumble, and one tip from the support desk. Wherever the platform already does a step for you, the guide says so rather than handing you a machine's chores.

By the Hosting & Domains team · Reviewed 18 August 2026

Intermediate

Experience required

5

Stages, start to finish

Free

Support included

Proven

On the platform itself

No prior knowledge assumed — a hosting account, a browser and hour of setup of attention is the whole entry requirement. Every instruction runs on our platform exactly as printed, and carries over to any standard cPanel host.

A promise before step one: nothing here is a one-way door. Any step with teeth is flagged, and the way back is printed beside it.

The route, mapped end to end

Over the whole job, you will treat updates as compulsory, harden the login, give the smallest role that works, remove what is not in use and prove the safety net works.

No part of this needs code or a terminal unless the guide says so plainly — and where it does, the exact commands are printed. The step-by-step is below, with the surrounding sections supplying the context that makes it hold.

The well-worn snag

Installing a security plugin and then waving away the update warnings it keeps raising. The plugin is the smoke alarm; out-of-date plugins and themes are the fire, and no alarm ever put one out.

It earns a section of its own because it is no obscure edge case — it is the single commonest reason this task reaches a support queue. Knowing it in advance turns the whole job from risky into routine.

The support desk's own short cut

Run one deliberate restore while everything is calm. An untested backup is a hope rather than a plan, and twenty minutes of practice takes the panic out of whatever happens later.

Habits this small are what separate the people who find hosting effortless from the people who find it draining. The same tools on both sides — a different way of working.

The parts that look after themselves here

Some steps in this guide exist only because hosting traditionally forced them on you. Here the SSL issues itself, the copy is taken daily without being asked, and one-click installers remove the manual setup. What is left is the part that was always genuinely yours.

Should a step still misfire, support answers at any hour with an actual fix rather than a knowledge-base link and a shrug. Half the guides on this site began as repeat patterns in our ticket queue.

The filtering that absorbs an attack well before it reaches the site

The hosting these steps were tested on

Every walkthrough in this library is run on the platform we actually operate — cPanel, LiteSpeed, NVMe, one-click installs — so the instructions match your screen rather than gesturing at it from a distance.

The rate you register at is the rate you renew at, so year two costs precisely what year one did — nothing lying in wait on the invoice.

  • Every step checked exactly as published
  • The snag named before it arrives
  • The dull steps taken out of your way
  • People reachable at any hour you stall

Why Hosting & Domains

Standard on every plan

Honest about how big it is

Shut the doors WordPress attackers actually use is a intermediate-level job — set aside an hour of setup, with the platform-absorbed steps marked.

5 steps, nothing padded

Each stage is a few minutes of steady clicking, and the fiddly moments are labelled fiddly.

Help that keeps your hours, not ours

Stuck on step three at midnight? Support answers at any hour, mid-walkthrough included.

The snag, flagged up front

The classic error for this particular task is named before step one, which is how an hour of setup stays an hour of setup.

Works exactly as printed

Every step is proven on the platform we run — none of the 'your host may vary' hedging.

Jargon never charges you

Every term is defined on the spot or linked to the jargon buster — nothing assumes prior knowledge.

Quick Start

Order placed to site online

  1. 1

    Treat updates as compulsory

    Let core update itself and set aside a weekly slot for plugins and themes. Known holes in out-of-date components account for the overwhelming majority of hacked WordPress installs.

  2. 2

    Harden the login

    A username that is not admin, a generated password, two-factor authentication, and a limit on failed attempts. Credential attacks run all day and all night against every WordPress site there is.

  3. 3

    Give the smallest role that works

    An editor does not need administrator; a contributor does not need publishing rights. Every spare admin account is another key waiting to be lost, guessed or walked out of the building.

  4. 4

    Remove what is not in use

    Delete deactivated plugins, spare themes and dormant user accounts. Idle code is attack surface that gives nothing back.

  5. 5

    Prove the safety net works

    Confirm the backups run and genuinely restore, and that the server-side defences, the firewall and the malware scanning, are switched on. Perfect prevention is not a plan; dependable recovery is.

Built In

Fitted to every plan

  • Upgrades applied in place, with no migration when you change plan
  • No set-up charge at any point, and no joining fee
  • Your existing site brought across by our engineers, at no charge
  • PHP versions set per site from the control panel
  • WordPress Toolkit, with the updates seen to for you
  • A renewal figure identical to the one you registered at
  • Free SSL on every plan, reissued before the old one lapses
  • Staging copies for trying a change before it goes live
  • SSH, Git and Composer on the developer plans
  • NVMe SSD storage on every tier, not only the dear ones

Frequently Asked

The questions that come up most

How do WordPress sites actually get hacked?

Almost always through a known flaw in an out-of-date plugin or theme, or a password that was weak, reused or leaked. Genuine zero-days barely register. Patching plus a hardened login closes the routes attackers really take.

Do I need a security plugin when the server already protects me?

Server-side defences such as our Imunify360 layer stop attacks before WordPress even runs. A light plugin still adds login hardening and an activity log worth reading. Keep both, and let the server tier do the heavy work.

What is the uptime commitment, and what happens in a month that misses it?

99.9% — and if a month falls below that through a fault on our side, our terms entitle you to a pro-rated credit; ask and we apply it. Calling it a target rather than a contractual SLA is a deliberate choice. Hardware and network faults surface through platform monitoring, usually before the first customer notices.

Who stands behind Hosting & Domains?

Hosting & Domains is a trading name of UK Health Care Support Ltd, registered in England and Wales — a real company with a public filing and terms governed by English law. Running that check on any host before you hand over a domain is time well spent.

Keep reading

  • How to Secure a New VPS

    Close the obvious doors in the first hour, before anything is listening in earnest — intermediate level, about an hour.

  • How to Migrate Email to a New Host

    Relocate mailboxes to a new host with full history preserved and zero losses — intermediate level, about 1–2 hours, or one support ticket.

  • Best Squarespace vs WordPress

    A shortlist with the working shown: what to check, and the single trap most buyers fall into.

  • Web Hosting

    cPanel hosting on NVMe drives — SSL, the migration and year one of the name all included.

  • Reseller Hosting

    White-label WHM hosting — your brand in front, monthly billing behind.

Changing hosts? Run through our checklist first.

A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.

What arrives is the checklist, and then the occasional note on keeping a site quick. Leave whenever you like; the privacy policy covers the rest.

Register it, then build on it.

Free SSL, a free migration, renewals billed at the original rate, and people on support around the clock. That is the whole of it.

View Web Hosting plans