WordPress maintenance and security: how to keep your site safe

Short answer: a secure WordPress site needs four things. Updates to WordPress, plugins, theme and PHP. Backups stored in more than one place. A protected login with strong passwords and two-factor authentication. And someone who checks every week. Most hacks do not happen through WordPress itself, but through plugins that have not been updated.
Why WordPress needs maintenance
WordPress powers about 40 percent of all websites (W3Techs), which makes it a popular target. Security company Patchstack counted 11,334 new vulnerabilities in 2025, a 42 percent rise on the year before. 91 percent were in plugins and 9 percent in themes, while only six concerned WordPress core, all of low severity (Patchstack).
Two more figures from the same report show why speed matters. 46 percent of the vulnerabilities had no fix when they became public. And the most exploited were used in mass attacks within five hours, as a median (Patchstack).
The UK picture is no better. In the government's Cyber Security Breaches Survey, 43 percent of UK businesses reported a breach or attack in the last 12 months, rising to 65 percent of medium-sized firms (GOV.UK).
Updates
WordPress
Minor WordPress versions, which often contain security fixes, install automatically. Since version 5.6, new installations also get major versions automatically, while older installations keep their previous behaviour (WordPress Developer). Check what applies to your site.
Plugins and themes
Plugins and themes do not update automatically by default (WordPress Developer). This is where most problems start. You can switch on automatic updates per plugin, but on an important site it is safer to update in a controlled way and test afterwards.
The UK's National Cyber Security Centre gives the same advice for all small organisations: keeping software and apps up to date is the best protection, and automatic updates should be switched on where possible (NCSC). If you want Cyber Essentials certification, critical and high-risk security fixes must be applied within 14 days of release (NCSC).
PHP
WordPress recommends PHP 8.3 or later (WordPress.org). PHP 8.1 and older no longer get security updates, and 8.2 stops getting them on 31 December 2026 (PHP.net). You change version in your hosting control panel, but test first that your theme and plugins work.
Backups
A backup must include both the database and the files. WordPress recommends weekly backups for sites with little activity, daily for active sites and always before an update, keeping three to five copies in different places (WordPress Developer).
A good rule of thumb is 3-2-1: three copies, on two types of storage, one of them away from your hosting. A backup that only sits on the same server as the site does not help if that server is hit. Test a restore once a year too, or you will not know whether it works.
Protect the login
- Two-factor authentication. The Two Factor plugin from WordPress.org supports codes from an app, email and backup codes, and has more than 100,000 active installations (WordPress.org).
- Strong, unique passwords for all administrators, stored in a password manager.
- Fewer administrators. Give editors the Editor role, not Administrator.
- Application passwords for integrations. They are meant for connections to other systems and cannot be used to log in to the admin area (WordPress Developer).
- Remove old accounts for former staff and suppliers.
More protections that make a difference
WordPress's own hardening guide recommends, among other things (WordPress Developer):
- Turn off the file editor in the admin area, so a hijacked account cannot change the code.
- Use SFTP instead of FTP, with correct file permissions.
- Give the database user only the permissions it needs.
- Monitor and log, so you see if anything changes.
Also remove plugins and themes you do not use. Every plugin is code that can contain a vulnerability, even when deactivated. Do not rely blindly on your host's protection: in Patchstack's tests, hosting providers' own protections stopped only 26 percent of attacks (Patchstack).
Checklist: week, month, year
| How often | What |
|---|---|
| Daily | Automatic backup of database and files, uptime monitoring |
| Weekly | Update plugins and theme, check that forms and checkout work |
| Monthly | Review user accounts, remove unused plugins, check load times |
| Quarterly | Check the PHP version and that backups can be restored |
| Yearly | Review the whole site: theme, plugins, content and whether the technology still holds up |
If your site is hacked
- Take the site offline or show a maintenance page.
- Change all passwords: WordPress, hosting, database and SFTP.
- Restore from a clean backup taken before the breach.
- Update everything and remove the plugin that let the attacker in.
- Check in Google Search Console that Google has not flagged the site.
If the breach may have exposed personal data, such as customer or form data, and a risk to people is likely, you must report it to the ICO as soon as possible and, where feasible, within 72 hours (ICO).
What does WordPress maintenance cost?
There is no neutral price list. UK providers' own figures suggest maintenance ranges from around £30 to more than £1,000 a month, with around £50 a month typical for small and medium-sized sites (Website Helper). Compare what is included: how often updates are done, where backups are stored, whether testing after updates is included and how quickly someone responds when something breaks.
Doing it yourself works well for a small site with few plugins, if you really do it every week. For help choosing the right platform in the first place, read What is a CMS? and Wix vs WordPress.
Frequently asked questions
How often should you update WordPress?
Check for updates every week. Minor WordPress versions often install automatically, but plugins and themes do not update automatically by default, and that is where most vulnerabilities are.
Is WordPress secure?
Yes, if it is maintained. WordPress core has very few serious vulnerabilities. In 2025, 91 percent of new vulnerabilities were in plugins and 9 percent in themes, so the risk mainly comes from plugins that are not updated.
How often should you back up WordPress?
WordPress recommends weekly for sites with little activity, daily for active sites and always before an update. Keep several copies in different places, at least one away from your hosting.
What should I do if my WordPress site is hacked?
Take the site offline, change all passwords, restore a clean backup, update everything and remove the plugin that let the attacker in. If personal data may be affected and a risk is likely, report it to the ICO within 72 hours where feasible.
How much does WordPress maintenance cost in the UK?
UK providers' own figures range from around £30 to over £1,000 a month, with around £50 a month typical for small and medium-sized sites. Compare what is included, not just the price.
Sources
- Upgrading WordPress, WordPress Developer Resources
- Hardening WordPress, WordPress Developer Resources
- WordPress Backups, WordPress Developer Resources
- Application Passwords, WordPress Developer Resources
- Requirements, WordPress.org
- Two Factor, WordPress.org
- State of WordPress Security in 2026, Patchstack
- Protecting your devices, National Cyber Security Centre
- Cyber Essentials: Requirements for IT infrastructure, National Cyber Security Centre
- Cyber Security Breaches Survey 2025/2026, GOV.UK
- Personal data breaches, ICO
- Supported versions, PHP.net
- , W3Techs








