WordPress is fundamentally secure. But just like every other content management system, it has vulnerabilities that are closed through regular updates. That's why update-readiness is absolutely mandatory for WordPress websites.
Most attack vectors aren't in WordPress itself but in insecure WordPress plugins or themes. Often it's free solutions used without much thought that create security risks. A few years ago we also "won" a client whose professional WordPress theme had quietly stopped being maintained and, through severe vulnerabilities, gave hackers access to her online shop.
In that case we had to carry out an emergency redesign on a different theme and WordPress editor, because the old setup couldn't be saved (the content could). So a careful review of WordPress extensions is strongly advisable – and standard practice for us. Automatic updates help close vulnerabilities as soon as they become known.
Various base settings and a firewall can secure WordPress further. There are big differences here too: most firewall plugins such as Wordfence run at application level, meaning only inside the WordPress system. That can be sufficient for low-traffic sites that have never been attacked, but it's resource-hungry and slows the server down, because every single request has to be processed by PHP and the WordPress database before the firewall can decide whether access is allowed.
That costs valuable milliseconds and CPU load. Cloud-level firewalls, by contrast, filter traffic before it even reaches your own server. The most popular and best options here are Sucuri and Cloudflare.
The former is set up relatively quickly; the Cloudflare setup is more complex. Any questions? We advise on security topics, clean up hacked websites and harden WordPress installations.
Our background: we've been building WordPress websites, our own plugins and themes for 15 years. Our clients also include several IT security companies that regularly challenge us with the highest security requirements.
Related questions
- Do you still need a classic CMS today, or is a no-code/builder-based website enough?
- How long does a website relaunch take - and what determines the duration in practice?
- How does relaunch consulting work in practice?
- Can you implement a relaunch yourself - or when is external consulting or an agency worthwhile?