Most compromised sites we see share the same handful of causes. Avoiding them prevents the majority of problems.
- Keep WordPress, plugins and themes updated. Outdated plugins are the most common way in.
- Remove what you do not use. A deactivated plugin still sits on the server and can still be exploited - delete it.
- Use strong, unique passwords for WordPress admin, cPanel and your database.
- Avoid pirated themes and plugins. They very often contain backdoors, and that is usually the point of them.
- Limit admin accounts. Give people the lowest role that lets them do their job.
- Keep your own backups so you can roll back quickly.
If keeping on top of this is not something you want to manage, our WordPress Maintenance plans cover it for you.
