Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
setup-wordpress-with-security-best-practice — Comprehensive guide for hardening WordPress installations: covers admin user changes, HTTPS enforcement, plugin security, file permissions, and server configuration for static corporate sites. | Kitploit
Tools/GitHubGitHub/password123456/setup-wordpress-with-security-best-practice
Configuration AuditingWeb SecurityLearning & Education
GitHubpassword123456/setup-wordpress-with-security-best-practice

setup-wordpress-with-security-best-practice

Comprehensive guide for hardening WordPress installations: covers admin user changes, HTTPS enforcement, plugin security, file permissions, and server configuration for static corporate sites.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
294102 years agoReviewed by Kitploit
Share

Setup WordPress With Security Best Practice

Hits

This document is written with the aim of being suitable for web applications developed using WordPress that do not interact with users. It is primarily intended for corporate brand pages, various static views, recruitment pages, and similar sites.

For websites where users register and freely use the site, such as open communities, some items in this document may not be applicable. Please keep this in mind as you read.

This document does not include all of the content necessary for securing WordPress.

However, it includes general and detailed information to a level that allows for security risk assessments and vulnerability responses based on the guide.

If you find this helpful, please the "star"🌟 to support further improvements.


Table of Contents

  • 1. Ensure that the Default WordPress Admin Username has been Changed
  • 2. Ensure User Roles and Permissions in WordPress are Properly Managed
  • 3. Ensure User Registration is Disabled
  • 4. Ensure the Plugin File Editor is Disabled
  • 5. Ensure Unused, Unnecessary Plugins are Deactivated
  • 6. Ensure WordPress is Configured to Use HTTPS Only, Including the WordPress Admin
  • 7. Ensure IP Access Restrictions (ACL) are Applied
    • 7.1. Ensure that IP access restrictions are applied to the WordPress admin.
    • 7.2. Restrict IP Access or Disable JSON REST API Feature
    • 7.3. Disable XML-RPC API Feature
    • 7.4. Disable WP-Cron or Restrict Feature
  • 8. System Configuration for Secure WordPress.
    • 8.1. Ensure Use of Non-End-of-Life (EOL) WordPress and PHP Versions
    • 8.2. Ensure Only Necessary PHP Extensions for WordPress are Enabled
    • 8.3. Ensure Security of Plugins with File Upload Features
    • 8.4. Ensure PHP Functions and Settings are Properly Configured
    • 8.5. Ensure the Web Server Runs As a Non-Root User - Unique, Unprivileged User and Group for the Server Application
    • 8.6. Ensure PHP-FPM Runs As a Non-Root User - Unique, Unprivileged User and Group for the Server Application
    • 8.7. Ensure Secure Configuration of the WordPress Home Directory
    • 8.8. Ensure PHP Execution is Disabled in Writable Directories
    • 8.9. Ensure Web Server Only Responds to Domain-Based Host Headers
    • 8.10. Completed WebServer Configuration
  • 9. Ensure WordPress Security Updates
  • 10. Ensure Regular Security Vulnerability Checks for WordPress

1. Ensure that the Default WordPress Admin Username has been Changed

When you install WordPress, the default admin username is "admin" unless you change it during the setup process. The "admin" account name is widely known, so it should be changed to a different name. If you continue to use "admin" as your admin username, an attacker could attempt a brute-force attack using "admin" to gain access to your WordPress site.

If an attacker gains access to the WordPress admin account, they will have full control over the website. The default WordPress admin username should be changed to a different name.

Audit:

  • Verify that if the default WordPress admin username is still set to "admin".

Remediation:

  • If username is "admin", change it to a less predictable username immediately.
  1. Login into your WordPress admin dashboard using admin account.
  2. "Users" area from your dashboard panel, and click on "Add New User".
  3. Fill in the form and choose "administrator" in the "Role" drop down menu (remember to use a strong web password and also use the provided password strength indicator to confirm that your new password is strong enough).
  4. When finished, click on the "Add New User" button.
  5. Log in again using your new WordPress admin username.
  6. Navigate to the "Users" area again.
  7. In the users list select the previous “admin” username and select "Delete" from the drop-down menu.
  8. When deleting the old admin, you will be asked about the articles posted under the previous "admin" username.
    • Select the option "attribute all posts and links to:" and select your new administrator.
    • When all set, click "Confirm Deletion".

Note:

  • Always use different "display name" from the username. If the actual username is used as display name of the content author, a hacker will easily identify username and target the account

2. Ensure User Roles and Permissions in WordPress are Properly Managed

By default, WordPress has five user roles - "Administrators", "Editors", "Authors", "Contributors", "Subscribers"

These roles allow you to control what tasks users can perform on your website by assigning appropriate permissions. If user roles and permissions are not properly managed, users might gain unnecessary access to critical functionalities, posing a significant security risk.

Audit:

  • Verify that WordPress user roles and permissions are adjusted to fit the needs of your website.
  • Review all user roles to ensure they are aligned with the current operational policies of your website.

Remediation:

  • Assign and manage user roles according to the needs of your website.
  • Generally, WordPress should be operated with one Administrator, one Editor, one Author.
  • Remove unnecessary admin accounts or reduce permissions where needed.
  • Regularly review users and their roles to ensure they are up-to-date with any changes.
Download Tool