Welcome to Mastering WordPress Security Uncovered. WordPress powers over 40% of the internet, making it the most targeted CMS on the planet. Out-of-the-box WordPress security is insufficient against automated botnets and zero-day vulnerabilities in plugins. True security requires defense in depth, starting at the server level.
1. Isolating the Execution Environment
Never run WordPress as the oot user or under a shared Apache/NGINX user (like www-data) if hosting multiple sites. Use PHP-FPM configured with distinct resource pools. Each site must run under its own restricted Linux user account. This ensures that if one WordPress site is compromised via a vulnerable plugin, the attacker cannot access the files or databases of neighboring sites on the same server.
2. Enforcing Strict File Permissions
Most WordPress hacks involve uploading a malicious PHP backdoor into the wp-content/uploads directory. This is preventable. Set directory permissions to 755 and file permissions to 644. Crucially, configure NGINX or Apache to absolutely forbid the execution of PHP scripts inside the wp-content/uploads folder. Even if an attacker uploads a backdoor, the web server will refuse to execute it.
3. Blocking Brute Force at the Edge
The xmlrpc.php file and wp-login.php page are constantly hammered by botnets attempting password guessing. Do not rely on PHP-based security plugins to block these; invoking PHP and connecting to the database to log a failed attempt wastes massive server resources. Block xmlrpc.php entirely at the NGINX or WAF level, and rate-limit or IP-whitelist access to wp-login.php using Cloudflare or Fail2Ban.
4. Database Prefixing and Salting
The default database prefix wp_ makes automated SQL injection attacks trivial, as attackers know exactly what tables to target. Always change this prefix during installation. Furthermore, ensure the unique authentication keys and salts in wp-config.php are generated securely. These hashes make it mathematically impossible for an attacker to crack stolen session cookies.
Conclusion
WordPress security is not achieved by installing bloated security plugins. It is achieved through strict file permissions, process isolation, blocking malicious traffic at the edge, and adhering to the principle of least privilege.