A checklist you can use today
Check your WordPress site's security.
Start with the things you can verify: updates, administrator access, public files, and the result after a fix. Keep a record of what you checked and when.
Based on the WordPress hardening guide. Reviewed September 28, 2026.
Start with updates and access.
- Update WordPress, plugins, and themes. Check the dashboard for available updates. Remove plugins and themes you no longer use. Make a backup before a major change and confirm it can be restored.
- Review administrator accounts. Remove access that nobody needs. Use unique passwords and turn on two-factor authentication for administrators through a released, well-maintained tool.
- Check login protection. Review failed-login controls and recovery steps. Don't turn on a rule that could lock out your only administrator without a way back in.
- Limit dashboard file editing. WordPress documents `DISALLOW_FILE_EDIT` as one layer that can reduce damage after an account compromise. It doesn't replace updates or access controls.
Look for files the web should not serve.
Old database exports, archive backups, debug logs, and configuration copies sometimes end up under a public WordPress directory. A file's presence is a reason to investigate; its public reachability is a separate question.
Use your host's file manager or a trusted security tool to identify candidates. Don't paste a suspected private file into a chatbot, and don't share a public link to it. If a file is exposed, remove it from the public directory or block access through your host, then verify the same path from an independent route.
A CDN can cache a file after it is removed at the origin. A login page, redirect, or generic “not found” page can also confuse simple scanners. Record the HTTP result and retest after each change.
What a passing check means: the tested path was not confirmed exposed from that test route at that time. It does not cover every hostname, old cache, or unknown file.
Treat scanner output as evidence.
WordPress core checksums can show when a supported core file differs from the official copy. A mismatch needs investigation. Matching checksums do not prove there is no malicious file elsewhere, including in uploads or custom code.
For vulnerability alerts, check the installed version, the advisory's affected range, and whether a patched version exists. If a feed is stale or a premium plugin is not covered, “unknown” is the honest result.
Write down the issue, what you changed, and the result of the next check. If a tool claims to fix something automatically, review the exact change and its rollback first.
About Amazing Security.
Amazing Security is a free WordPress plugin we're building around this evidence-first workflow. Planned areas include hardening checks, vulnerability and file findings, independent public-file verification, and an optional MCP connection for AI assistants.
It's in development and has no download yet. If your site needs protection now, use a released security plugin and follow your host's incident process. You can read our dated Wordfence Free comparison to see what a current option provides.