HS Article

WordPress Security Checklist: 6 Things to Check Every Month

Most WordPress sites don’t get hacked because of some advanced attack. They get hacked because an outdated plugin sat unpatched for months, or a backup that nobody checked turned out to be broken the day it was needed. A short monthly check can catch many of the common problems before they become serious, and it takes less time than people expect.

Here’s a practical checklist to help reduce your risk of getting hacked, one you can get through in about 15 minutes (plus an occasional restore test), not a 30-item audit that gets skipped because it’s overwhelming. A short list you finish every month prevents far more problems than a long one you abandon after the first try.

Quick Monthly Checklist

  1. Update WordPress core, themes, and plugins, and delete anything unused
  2. Check WordPress Site Health
  3. Review your admin users for anything unfamiliar
  4. Run a full scan with your security plugin
  5. Confirm your latest backup completed successfully
  6. Check login activity for repeated failed attempts

1. Update WordPress Core, Themes, and Plugins

Outdated plugins are consistently one of the most common ways WordPress sites get compromised. A plugin that hasn’t been updated in a year isn’t just missing new features; it’s likely missing security patches for vulnerabilities that are already public knowledge.

Go to Dashboard > Updates and update everything shown there. If you’re nervous about an update breaking something, test it on a staging copy of your site first, or at minimum take a backup immediately before updating.

While you’re there, delete any plugins and themes you’re not using. Deactivated plugins still sit on your server, and a vulnerable file can sometimes be requested directly even when the plugin is inactive, so deactivating is not enough. If you come across a plugin you don’t remember installing, or one its developer no longer maintains, take a second look; an abandoned plugin is a long-term risk even if it works fine today.

It’s also worth turning on auto-updates for minor and security releases of WordPress core, and for plugins you trust. It’s one of the easiest security wins available.

2. Check WordPress Site Health

WordPress has a built-in tool for exactly this, under Tools > Site Health. It checks for things like outdated PHP versions, missing security recommendations, and configuration issues, and it’s often overlooked simply because people don’t know it’s there.

Spend two minutes on the Status tab. Anything listed under “Critical issues” is worth addressing that same month, not whenever you get around to it. “Recommended improvements” can wait for a quieter moment, but don’t ignore them entirely. Site Health is a useful first check, but it isn’t a substitute for a dedicated security scan.

Read: Site Performance

3. Review Your Admin Users

Go to Users and look at who actually has administrator access. This is easy to leave unchecked for years: an old freelancer who no longer works on the site, a client’s former employee, a test account you created once and never removed. Remove or downgrade anyone who doesn’t need admin rights.

While you’re here, make sure every admin account uses a strong, unique password, and enable two-factor authentication on them if you haven’t already. Admin accounts are the keys to the whole site.

If you see an admin account you don’t recognize at all, that’s a different situation. Treat it as a possible sign of compromise, not routine cleanup. Change your WordPress and hosting passwords immediately, log out all users (Users > Your Profile > “Log Out Everywhere Else” for your own account, or via your security plugin for everyone), run a security scan, and check for other unfamiliar admins and recently modified files. If the compromise is confirmed, restore from a known-clean backup or contact your host or a security professional.

4. Run a Full Security Scan

A dedicated security plugin, like Wordfence or Sucuri, can scan for malware, unexpected file changes, and known vulnerabilities. Most of these plugins can run scans automatically on a schedule, but it’s worth actually opening the results once a month rather than letting them pile up unread in an email you don’t check.

If a scan flags something, don’t dismiss it without looking closer. False positives happen, but so do real infections, and the only way to tell the difference is to investigate the specific file or change the scan is pointing to. Pay particular attention to recently modified files you didn’t touch yourself.

5. Confirm Your Backups Actually Work

This is the step most people skip, and it’s arguably the most important one. Having a backup running isn’t the same as having a backup you can rely on. Backups can silently fail, run against an empty database, or save to a storage location that’s since been disconnected, and you often don’t find out until the exact moment you need one.

Every month, look at your backup logs and confirm that the latest backup completed successfully. Every few months, go a step further and test-restore it, ideally to a staging site, to confirm it genuinely works. A backup you’ve never tested is a guess, not a safety net.

6. Check Login Activity for Brute Force Attempts

Most security plugins log failed login attempts. A handful of failed logins here and there is normal background noise on the internet, but a concentrated spike from the same IP address, or hundreds of attempts in a short window, is a sign your login page is being actively targeted.

If you see this, add a login attempt limiter if you don’t already have one, and make sure two-factor authentication is switched on for admin accounts.

Plugin: Math CAPTCHA Plugin | Login Protection Plugin

What to Do If Something Looks Wrong

If any of these checks turn up something genuinely suspicious (an admin account you didn’t create, a scan flagging unfamiliar files, or a site that suddenly behaves differently with no update or change on your end), don’t wait for next month’s check. Change your WordPress, database, and hosting passwords right away, and run a full malware scan before you do anything else on the site.

Read: Error Establishing a Database Connection in WordPress

Frequently Asked Questions

How often should I run a WordPress security check?

Monthly is a reasonable minimum for most sites. If your site handles sensitive data, payments, or high traffic, weekly is worth considering, particularly for updates and backup verification.

Do I need a security plugin if my host already offers security features?

It depends on what your host actually covers. Many hosts handle server-level protection, but a dedicated plugin like Wordfence or Sucuri adds WordPress-specific scanning, such as checking for changes to core files and known plugin vulnerabilities, which most hosting-level security doesn't cover.

Is updating plugins immediately always safe?

Not always. Occasionally an update introduces a conflict with your specific theme or another plugin. That's why taking a backup first, and testing on staging if you have it available, is worth the extra few minutes before updating a live site.

What's the single most important item on this checklist?

If you only have time for one thing, make it backups. A reliable, tested backup makes recovery after a compromise much faster and safer. A site with no working backup can mean losing everything.

5 1 vote
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
wordpress white screen of death error

WordPress White Screen of Death: How to Fix a Blank White Page

If you open your WordPress site and see nothing...

Read More
how to fix database connection error wordpress

Error Establishing a Database Connection in WordPress: How to Fix It (Complete Guide)

If your site is showing “Error establishing a database...

Read More
Wordpress contact form not sending email

WordPress Contact Form Not Working? SMTP Fix That Works

Your form doesn’t always submit cleanly either, sometimes it...

Read More
Best math captcha plugin

Free Math CAPTCHA Plugin for WordPress Forms (No API Key Needed)

Quick Answer: If your WordPress contact form keeps getting...

Read More
fix missing alt text in wordpress

How to Fix Missing Alt Text in WordPress (Step-by-Step)

If you have ever run an SEO audit or...

Read More
Choose a Color Palette for Your Website

How to Choose a Color Palette for Your Website

Quick answer: Start with one color that matches the...

Read More
Core Web Vitals: Why Your Rankings Might Have Dropped

Core Web Vitals in 2026: What Actually Changed and Why Your Rankings Might Have Dropped

If your traffic has dipped this year and you...

Read More
reading time calculator

How Long Should a Blog Post Be? Word Count Guide by Content Type

Every writer hits this question eventually. You finish a...

Read More
How to install wordpress on localhost using XAMPP

How to Install WordPress on Localhost Using XAMPP: A Step by Step Guide

If you’re building or testing a WordPress site, you...

Read More
Best Gradient tool

10 Best CSS Gradient Tools in 2026 (Generators, Galleries & Mesh Gradients Compared)

Searching for the best css gradient tools usually turns...

Read More

About

HSArticle logo

HS Article is a free resource for Designers & Developers. Explore free tools, free plugins, WordPress fixes, Instagram ideas, and interactive quizzes - all in one place.