Most hacked WordPress sites are outdated or use weak passwords. These measures protect your website effectively.
Recommended measures
- Automatic updates: Enable automatic updates for WordPress under Dashboard > Updates, and for plugins and themes under Plugins and Appearance > Themes.
- Few plugins: Deactivate and delete unused plugins and themes. Only use actively maintained extensions from trusted sources.
- Strong credentials: Do not use the username "admin", and use a long, unique password.
- Two-factor authentication: Enable 2FA with a plugin (e.g. "Two Factor") and an authenticator app.
- Backups: Your hosting is backed up automatically every day with JetBackup. In cPanel, use JetBackup to restore files or databases yourself. Before major updates, also create a backup, e.g. via Softaculous.
- Malware protection: Imunify360 monitors your account for malware and blocks attacks. You can see the results in cPanel under Imunify360.
- Current PHP version: In cPanel, choose a current version supported by your plugins under Select PHP Version.
- Performance: Use the LiteSpeed Cache plugin, which works seamlessly with the LiteSpeed web server.
Note: If Imunify360 reports an infection or your site behaves suspiciously, open a ticket in the Client Area under Support > Open Ticket.