Security Baseline for a New WordPress Site

Wide demo banner

Written by

in

Baseline Controls

  • Use unique administrator accounts and strong authentication.
  • Apply updates deliberately and verify backups.
  • Restrict write access to required paths.
  • Protect login, XML-RPC, REST, and administrative endpoints according to actual use.
  • Use HTTPS everywhere.
  • Log authentication, privilege changes, plugin changes, and file modifications.

This is generalized test content and not a complete security standard.