For several years now, WordPress has been used to build millions of websites. Many of them store private information. Often it is the payment data of e-commerce customers. You therefore have to secure WordPress at all costs.
WordPress is used by so many people that you might imagine the CMS is invulnerable to hacking. Reality tells another story.
In fact, this is regularly contradicted, but do not panic, it is perfectly normal.
All software has flaws, and WordPress is no exception. When a WP site is hacked, the culprit is usually not the CMS. It is more often the webmaster who runs the site. In truth, clients ignore the recommendations for securing their WordPress site.
Cybercrime
Experts expect more attacks on WP sites, because many have not updated to WP 6.0 since May 2025.
As a WordPress web design agency in Switzerland, we often hear “I am only a small SME”. Yet whether small or large, in Lausanne, Fribourg or Geneva, no one is spared!
For this kind of hacking, attackers cast a wide net with automated bot attacks. Which raises the real question: how do you prevent hacking and secure a WordPress site?

Our four WordPress security tips to protect your site in 2025
1. Protect your admin page
Your admin page is the first thing to secure against cyberattacks. You therefore have to make it hard to reach. Here are 4 essential actions for avoiding unpleasant surprises:
-
WP users know how to reach the admin page. All it takes is typing /wp-login.php or /wp-admin. And indeed, any bot will add that link to your URL. You then become vulnerable. To start protecting your site, change the link to your admin page. Several plugins exist to secure WordPress.
-
Use an “anti-brute force” system that will lock your site after several failed login attempts. This protection prevents forced attacks. When someone tries to get in with an incorrect password, the page locks. You then receive an alert by email or SMS. Plenty of dedicated plugins exist to strengthen your WordPress site.
-
Set up two-factor authentication on the admin page. As the administrator, you choose the method. It can be a password with a secret code, special characters or a code sent to your phone. This last option ensures that only the person holding the phone can access the site.
-
Update your passwords regularly. Mix upper case, lower case, numbers and special characters. What is more, a long enough password (10 characters minimum) will be almost impossible to crack by brute force.

2. Use secure hosting for WordPress
To secure a WordPress site, you need to go beyond simply blocking access. Your site must also be protected at web server level. That is where your host comes in. Take the time to look for a reliable host such as Infomaniak or Cloudways.
Ideally, your server should have a firewall and intrusion detection systems. These tools protect your site from the moment WordPress is installed and throughout its development. On that note, Cloudflare, even in its free version, also provides effective protection by filtering traffic directly.
With cloud hosting, the provider must ensure that the software on its servers protects your site while remaining compatible with the latest versions of WordPress.
3. Use WP with the latest updates
To secure a WordPress site properly, you need to keep it regularly maintained by updating every version.
Just as you change your car’s oil or mow your lawn, maintain your WordPress site. The WordPress core, plugins and themes all need frequent updates.
A report by WP White Security revealed that
“Close to 50% of WordPress vulnerabilities come from plugins or themes that are not updated or patched. Vulnerabilities spread fast in the open source world and the people looking to exploit them know where to start.”
According to Malcare Security, the figure would be higher still, at around 80%. That is why WordPress has to be updated very often. Each new version fixes bugs and vulnerabilities. WordPress identifies its vulnerabilities and adds protections with every update.
Whether or not you like the latest WordPress features (yes, I am talking about you, Gutenberg), updates are nevertheless no longer optional if you want to secure your WordPress site.

4. Do not host several WordPress sites on the same server Imagine having 4 sites on your server account. Three get regular updates thanks to their heavy traffic. Do not forget to update the last one, though, to keep WordPress secure.
A malicious bot can discover the flaws of outdated sites and access the backend of your server. It could then download a script to take control of your hosting and hack all your data.
No panic if you use shared hosting. Good hosts generally run small server clusters. That means few sites per server.
That way, when an attack occurs, it affects only a small number of sites. As a result, this considerably reduces the risk of your WordPress site being compromised.
And finally…
Here are a few additional tips you can apply in 2025 to secure WordPress:
- Choose quality WordPress themes that their creators update regularly. Above all, always check the history before selecting a free WordPress theme.
- Avoid using “administrator” as a username. Unfortunately, many WordPress webmasters go for “admin”. Obviously, this makes the login easy to guess on their WordPress site.
- Disable file editing and modification directly from the WordPress dashboard.




