← All articles

WordPress maintenance that actually prevents incidents

·2 min read·By Adrian

Also available in ES, RO

WordPress powers a large share of business websites, and it is attacked constantly — not because it is insecure by design, but because its scale makes automated attacks worthwhile.

The good news: nearly every compromise we investigate was preventable with routine maintenance.

Where the risk is

Rarely in WordPress itself, which is patched quickly. Almost always in:

  • Plugins that have not been updated in months
  • Plugins abandoned by their authors and never removed
  • Themes bought once and never updated since
  • Administrator accounts with weak passwords and no second factor
  • An outdated PHP version the host stopped supporting

A maintenance routine worth paying for

Weekly. Apply core, plugin and theme updates on a staging copy, check the site still works, then apply to production. Automatic updates on a live site without checking is how a plugin update takes down a shop on a Friday.

Monthly. Review the plugin list and remove anything unused. Check for abandoned plugins. Confirm backups restore. Review administrator accounts.

Quarterly. Check the PHP version against what is still supported. Review file permissions. Look at the error logs properly.

Reduce what you have to maintain

The single most effective measure is having fewer plugins. Each one is code you did not write, running with full access to your database. Twenty plugins is twenty ongoing dependencies; eight is a manageable estate.

Be particularly wary of plugins doing something a few lines in the theme could do.

The non-negotiables

  • Multi-factor authentication on every administrator account
  • No account named admin
  • Automatic updates for security releases at minimum
  • Off-site backups, tested, not only the host's snapshots
  • A web application firewall in front of the site
  • File editing disabled from the dashboard

That last setting means a stolen administrator password does not immediately become the ability to run arbitrary code.

If it is already compromised

Do not just delete the visible damage. Restore from a known-good backup, patch what let them in, rotate every credential, and only then bring it back. Cleaning symptoms while leaving the entry point is why sites get reinfected within days.

We maintain sites under WordPress themes and maintenance.

← Blog